Tag

Citizen Lab

All articles tagged with #citizen lab

spyware-mobile-security1 year ago

FSB Deploys Spyware to Track Anti-War Russian Techie

The Russian Federal Security Service (FSB) allegedly implanted spyware on the Android device of Kirill Parubets, a Russian programmer accused of supporting Ukraine. The spyware, discovered through a joint investigation by First Department and Citizen Lab, was hidden in a trojanized version of the Cube Call Recorder app and allowed extensive surveillance capabilities. The case highlights the risks of device compromise when in the custody of hostile security services. The spyware shares similarities with Monokle, suggesting a possible codebase reuse.

world-news1 year ago

Russian Programmer Outsmarts FSB's Spyware and Escapes

Russian programmer Kirill Parubets outsmarted the FSB by identifying spyware on his phone after it was confiscated during his detention for allegedly sending money to Ukraine. Parubets, who was threatened with life imprisonment if he didn't cooperate with the FSB, managed to flee Russia with his wife before being fully recruited. His phone was found to have a trojanized app linked to the Monokle spyware family, highlighting the risks of device compromise by security services. Citizen Lab advises those in similar situations to seek expert analysis of their devices.

cybersecurity2 years ago

Egyptian Opposition Presidential Candidate Falls Victim to Spyware Attack

Egyptian opposition presidential candidate Ahmed Altantawy has been targeted with spyware multiple times, with security researchers suspecting the Egyptian government's involvement. The hacking attempts aimed to surveil Altantawy and potentially find compromising material to discredit him. Researchers from Citizen Lab and Google's Threat Analysis Group discovered the malware and prompted Apple to release security updates. The attacks involved network injection and malicious links in text and WhatsApp messages. Altantawy's phone was likely targeted due to his political candidacy and opposition role against President Abdel Fattah el-Sisi's regime.

cybersecurity2 years ago

Egyptian Presidential Hopeful Targeted with Predator Spyware: Researchers Uncover New Apple Zero-Days

Ahmed Eltantawy, a prominent Egyptian opposition politician and presidential hopeful, was targeted with a zero-day attack in an attempt to infect his iPhone with Predator spyware. The attack, which prompted Apple to release a security update, was discovered by Google and the University of Toronto's Citizen Lab. The lab has "high confidence" that the Egyptian government was responsible for the hacking attempt. Predator spyware, developed by Cytrox, can steal passwords, log keystrokes, and record calls. Eltantawy, an outspoken critic of the Egyptian government, had been receiving suspicious messages since May. The attack involved the use of PacketLogic, a product by Sandvine, a Canadian networking equipment company. The incident highlights the risks posed by commercial surveillance vendors and their impact on online user safety.

technology2 years ago

"Urgent Alert: Ongoing Attacks Targeting Apple Devices—Stay Protected!"

Users of iPhones, iPads, Apple Watch, and Macs are being urged to update their devices immediately due to a sophisticated spyware attack uncovered by Citizen Lab and Google's Threat Analysis Group. The attack targeted an Egyptian pro-democracy politician using SMS and WhatsApp messages, infecting his phone with spyware through a malicious website. Apple has released emergency security updates addressing three critical vulnerabilities, urging users to update to iOS 17.0.1 or iOS 17.0.2 as soon as possible. The vulnerabilities, including a kernel vulnerability and certificate validation issue, have already been exploited. Lockdown Mode is recommended for users at risk.

cybersecurity2 years ago

"Urgent Apple Security Update: Pegasus Hack Targets Washington DC Group"

A Washington DC-based organization with international offices was targeted in an apparent Pegasus hack, according to researchers at Citizen Lab. The individual's device was found to have been infected with powerful hacking software made by NSO Group, raising concerns about the proliferation of spyware that can infect Apple devices. The attack utilized a "zero-click exploit," allowing the software to infect the user's mobile device through a previously unknown security flaw. NSO Group claims to sell its spyware only to government clients for use in fighting crime and terrorism, but there have been documented cases of misuse. The Biden administration has placed NSO on a blacklist, and the company is facing lawsuits from Apple and WhatsApp.

cybersecurity2 years ago

"White House Implements Ban on Spyware After 50 US Officials Targeted"

At least 50 US government employees have been targeted with commercial spyware that hacks smartphones to spy on their owners, according to the White House. President Joe Biden will sign an executive order aimed at curtailing spyware abuse by setting guidelines for the companies that produce it. The order gives the White House the power to ban a company’s software across all federal agencies if it is found to have used spyware to target activists, curb political dissent or spy on Americans. Spyware companies have been repeatedly deployed against journalists, political candidates, researchers and activists around the world, leading to widespread condemnation from human rights advocates.