Meta Disrupts 8 Spyware Firms, 3 Fake News Networks

Meta has identified and interrupted six spyware networks linked to eight companies in Italy, Spain, and the United Arab Emirates, as well as three fake news operations from China, Myanmar, and Ukraine.
It outlines how fake news operations - particularly those originating in Russia - have taken a hit in recent years, but commercial surveillance is thriving, using fake social media accounts to collect intel about targets and lure them into downloading powerful cross-platform spying tools.
Eight Spyware Firms on Meta Platforms There are a few key characteristics of today's spyware ecosystem that Meta observed in its report.
Firstly, these pseudo-legal vendors are typically concealed by layered corporate ownership structures.
There's Cy4Gate, for example - an Italian spy-for-hire company owned by a defense contractor called ELT Group.
Cy4Gate has been observed scraping information about targets via fake social media accounts with AI-generated profile photos.
Previously, it operated a WhatsApp phishing site, which goaded victims to download a Trojanized version of the app for iOS, capable of collecting photos, emails, SMS, screenshots, and much more.
Besides being owned by ELT Group, Cy4Gate itself owns another firm called RCS Labs.
RCS likes to impersonate activists, journalists, and young women in Azerbaijan, Kazakhstan, and Mongolia - the same demographics they typically target - in order to trick victims into sharing their contact information, or clicking on lure documents or malicious links which track their IP addresses and profile their devices.
Because the industry is flourishing, spyware customers who are also attackers often use more than one tool as part of their attack chain.
Meta observed one customer of IPS Intelligence - another Italian firm which used fake accounts to target victims in three continents, across most major social media platforms - engaging in social engineering activities, tracing victims' IP addresses, and priming Android devices for further tampering, all independent of IPS. The last, perhaps most obvious trend observed by Meta is surveillance companies' tendency to use social platforms as a testbed for their exploits.
Spanish firms Variston IT and Mollitiam Industries, the Italian Negg Group and TrueL IT, and the misleadingly named, UAE-based Protect Electronic Systems all used social media accounts to test the delivery of their spyware.
Negg, for example, experimented by using some of its accounts to perform data exfiltration and transmit its cross-platform spyware against its other accounts.
Negg typically deploys its tooling against targets in Italy and Malaysia.
The first was from China and targeted US audiences by posing as anti-war activists and members of American military families.
This threat actor targeted users across Meta platforms, Medium, and YouTube, but it was snuffed out before gaining significant traction.
Another CIB from Myanmar targeted local Myanmar citizens by posing as members of ethnic minorities on Meta platforms and beyond, including Telegram, X, and YouTube.
This activity, after some investigation, was tied back to individuals in Myanmar's military.
Finally, Meta removed a cluster operating in Ukraine, targeting individuals in Ukraine and Kazakhstan.
Reputable opinion-makers represent an attractive target and should exercise caution before amplifying information from unverified sources, particularly ahead of major elections.


This Cyber News was published on www.darkreading.com. Publication date: Tue, 20 Feb 2024 21:50:30 +0000


Cyber News related to Meta Disrupts 8 Spyware Firms, 3 Fake News Networks

Meta Disrupts 8 Spyware Firms, 3 Fake News Networks - Meta has identified and interrupted six spyware networks linked to eight companies in Italy, Spain, and the United Arab Emirates, as well as three fake news operations from China, Myanmar, and Ukraine. It outlines how fake news operations - ...
9 months ago Darkreading.com
Citizen Lab details ongoing battle against spyware vendors - Citizen Lab senior researcher Bill Marczak said that while the organization has achieved some important wins against spyware proliferation, the progress is inevitably hindered by vendors that continually adapt their technologies and practices. The ...
9 months ago Techtarget.com
Law Firms and Legal Departments Get Singled Out For Cyberattacks - Cyberattackers are doubling down on their attacks against law firms and corporate legal departments, moving beyond their historical activity of hacking and leaking secrets to targeting the sector with financial attacks, such as ransomware and ...
11 months ago Darkreading.com
Spyware isn't going anywhere, and neither are its tactics - The illegal use of spyware to target high-profile or at-risk individuals is a global problem, as highlighted by this article from The Register that Talos' Nick Biasini just contributed to. As we've written about, many Private Sector Offensive Actors ...
9 months ago Blog.talosintelligence.com
How Cybersecurity for Law Firms has Changed - The public nature of the legal system makes law firms particularly vulnerable to a growing number of cybersecurity risks. Law firms have unique access to highly confidential client information and as a result, face a growing number of federal, ...
10 months ago Securityboulevard.com
Intellexa and Cytrox: From fixer-upper to Intel Agency-grade spyware - Cisco Talos has a new, in-depth analysis of timelines, operating paradigms and procedures adopted by spyware vendor Intellexa. Talos' analysis revealed that rebooting an iOS or Android device may not always remove the Predator spyware produced by ...
10 months ago Blog.talosintelligence.com
Intellexa Spyware Adds Persistence with iOS or Android Device - In the shadowy realm of commercial spyware, the spotlight turns to the notorious Intellexa spyware and its Predator/Alien solution, as dissected by Cisco Talos in their comprehensive May 2023 report. This expose navigates the labyrinthine intricacies ...
10 months ago Gbhackers.com
US Uses Visa Restrictions in Struggle Against Spyware - The United States will impose visa restrictions on foreign individuals who have been involving the misuse of spyware, the latest effort by the Biden Administration to address the dangers of the commercial software that often is used by governments ...
9 months ago Securityboulevard.com
Is Your Organization Infected by Mobile Spyware? - The surge in mobile device usage within organizations has inevitably opened the floodgates to a new kind of cyber threat-mobile spyware. The growing dependence on mobile technology has made it imperative for organizations to recognize and mitigate ...
10 months ago Blog.checkpoint.com
ICE Signs $2 Million Contract With Spyware Maker Paragon Solutions | WIRED - Measures have included placing spyware vendors like NSO Group and Intellexa on the so-called Entity List to prevent any US companies from doing business with them; enacting a visa restriction policy against multiple individuals “who have been ...
1 month ago Wired.com
What is Spyware? How It Works and How to Protect Yourself Against It - Spyware is a type of malicious software that is designed to collect sensitive data from victims without their knowledge or consent. It is typically installed on computers without the user’s knowledge or consent, and collects sensitive information ...
1 year ago Heimdalsecurity.com
Kaspersky Details Method for Detecting Spyware in iOS - Researchers with cybersecurity firm Kaspersky are detailing a lightweight method for detecting the presence of spyware, including The NSO Group's notorious Pegasus software, in Apple iOS devices. The new method, which calls for looking for traces of ...
10 months ago Securityboulevard.com
US announces visa ban on those linked to commercial spyware - Secretary of State Antony J. Blinken announced today a new visa restriction policy that will enable the Department of State to ban those linked to commercial spyware from entering the United States. As part of this effort, the Biden Administration ...
9 months ago Bleepingcomputer.com
Meta Considers Facebook News Ban In Australia - Meta says it may ban news content from Facebook in Australia if forced to pay licensing fees under 2021 law. Facebook parent Meta Platforms said it is considering banning news from the social media service if it is forced to pay licensing fees. She ...
4 months ago Silicon.co.uk
Privacy at Stake: Meta's AI-Enabled Ray-Ban Garners' Mixed Reactions - There is a high chance that Meta is launching a new version of Ray-Ban glasses with embedded artificial intelligence assistant capabilities to revolutionize wearable technology. As a result of this innovation, users will have the ability to process ...
10 months ago Cysecurity.news
Law Firms are Raising the Bar on Cybersecurity - Corresponding with recent increases in threat actor activity in the legal industry, law firms are investing more time and attention in modernizing security operations. Both midsize and large law firms are increasingly engaging with cybersecurity ...
1 year ago Bluevoyant.com
U.S. rolls out visa restriction policy on people who misuse spyware to target journalists, activists - WASHINGTON - The Biden administration announced Monday it is rolling out a new policy that will allow it to impose visa restrictions on foreign individuals involved in the misuse of commercial spyware. The administration's policy will apply to people ...
9 months ago Pbs.org
Google says spyware vendors behind most zero-days it discovers - Commercial spyware vendors were behind 80% of the zero-day vulnerabilities Google's Threat Analysis Group discovered in 2023 and used to spy on devices worldwide. Zero-day vulnerabilities are security flaws the vendors of impacted software do not ...
9 months ago Bleepingcomputer.com
As Meta rolls out end-to-end encryption, police warn keeping children safe 'no longer possible' - The move will ensure that Meta's users are protected from abusive legal requests from non-democratic governments. Globally the company receives hundreds of thousands of government requests for user data annually, according to its transparency center ...
11 months ago Therecord.media
Palo Alto Networks and IBM to Jointly Provide AI-Powered Security Offerings - PRESS RELEASE. SANTA CLARA, Calif. and ARMONK, N.Y., May 15, 2024 /PRNewswire/ - Palo Alto Networks, the global cybersecurity leader, and IBM, a leading provider of hybrid cloud and AI, today announced a broad-reaching partnership to deliver ...
6 months ago Darkreading.com
Meta sues ex VP of Infrastructure for 'trade secret theft' The Register - Over the course of his 12-year employment at the Facebook giant, Dipinder Singh Khurana - also known as T.S. Khurana - rose to the rank of vice-president of infrastructure. He left the mega-corp in June 2023 to take a position as senior veep of ...
8 months ago Go.theregister.com
US to Roll Out Visa Restrictions on People Who Misuse Spyware to Target Journalists, Activists - The Biden administration announced Monday it is rolling out a new policy that will allow it to impose visa restrictions on foreign individuals involved in the misuse of commercial spyware. The administration's policy will apply to people who've been ...
9 months ago Securityweek.com
SentinelLabs uncovers new CapraRAT spyware targeting Android users - A new report released today by SentinelLabs, the research arm of listed cybersecurity company SentinelOne Inc., warns of a resurgence of CapraRAT spyware targeting mobile gamers and weapons enthusiasts through malicious Android applications. CapraRAT ...
4 months ago Siliconangle.com
New Android Spyware Employs Tactics to Deceive Malware Analyst - In the dynamic realm of mobile application security, cybercriminals employ ever more sophisticated forms of malware, with code obfuscation standing out as a deceptive technique. This method intentionally distorts code elements, rendering them ...
11 months ago Cybersecuritynews.com
A Comprehensive Look at the Financial Firms in European Union and Their Rules on Cloud-Based Services - Today's technology has opened up a world of possibilities for financial firms, especially with cloud-based services. Financial institutions are now able to access a great deal of information over the internet in an efficient and timely manner. ...
1 year ago Tripwire.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)