CYBER WARS
Booby-trapped messaging apps used for spying: researchers
by Staff Writers
San Francisco (AFP) Jan 18, 2018


An espionage campaign using malware-infected messaging apps has been stealing smartphone data from activists, soldiers, lawyers, journalists and others in more than 20 countries, researchers said in a report Thursday.

A report authored by digital rights group Electronic Frontier Foundation and mobile security firm Lookout detailed discovery of "a prolific actor" with nation-state capabilities "exploiting targets globally across multiple platforms."

Desktop computers were also targeted, but getting into data-rich mobile devices was a primary objective, according to the report.

With fake versions of secure messaging services like WhatsApp and Signal, the scheme has enabled attackers to take pictures, capture audio, pinpoint locations, and mine handsets for private data.

EFF and Lookout researchers dubbed the threat "Dark Caracal."

People in the US, Canada, Germany, Lebanon, and France have been hit by Dark Caracal, according to EFF director of cybersecurity Eva Galperin.

"This is a very large, global campaign, focused on mobile devices," Galperin said.

"Mobile is the future of spying, because phones are full of so much data about a person's day-to-day life."

Hundreds of gigabytes of data have been taken from thousands of victims in more than 21 countries, according to Lookout and the EFF.

There were indications that Dark Caracal might be an infrastructure hosting a number of widespread, global cyberespionage campaigns, some of which date back years, the report said.

Because the apps fool people into thinking they are legitimate, users give them access to cameras, microphones and data.

"All Dark Caracal needed was application permissions that users themselves granted when they downloaded the apps, not realizing that they contained malware," said EFF staff technologist Cooper Quintin.

"This research shows it's not difficult to create a strategy allowing people and governments spy to on targets around the world."

Researchers reported that they tracked Dark Caracal to a building in Beirut belonging to the Lebanese General Security Directorate.

Analysis showed that devices of military personnel, businesses, journalists, lawyers, educators, and medical professionals have been compromised, according to the report.

"Not only was Dark Caracal able to cast its net wide, it was also able to gain deep insight into each of the victim's lives," the report concluded.

Cyber security professionals consistently warn people to be wary when downloading software, avoiding programs shared through links or email and instead relying on trusted sources.

CYBER WARS
Former CIA agent's arrest follows US spying debacle in China
Washington (AFP) Jan 18, 2018
The third arrest in one year of a US official suspected of helping Chinese spies has bared the tense battle between the two superpowers' intelligence agencies. The arrest late Monday by US authorities of former Central Intelligence Agency agent Jerry Chun Shing Lee was reportedly linked to Beijing's brutal dismantling five years ago of the CIA's network of undercover operatives and informant ... read more

Related Links
Cyberwar - Internet Security News - Systems and Policy Issues

Comment using your Disqus, Facebook, Google or Twitter login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

CYBER WARS
Alabama's PeopleTec awarded $33M for missile defense

Japan broadcaster mistakenly flashes missile alert

Saudi Arabia intercepts new Yemen rebel missile attack

Hawaii 'missile alert' sparks anger, demands for answers

CYBER WARS
Israel says India to restart talks on missile sales

India likely to revive mega missile deal with Israel

State Department approves $133.3M missile sale to Japan

Navy awards Raytheon with $27M contract for SM-2 missiles

CYBER WARS
Boeing unveils UAV prototype for cargo, logistics use

Russia's army warns of 'terrorist' drones after attacks

Air Force to upgrade Reaper drone fleet as the Predator begins retirement

DARPA working on collaborative autonomy for UAVs and Drones

CYBER WARS
Map of ionospheric disturbances to help improve radio network systems

Military defense market faces new challenges to acquiring SatCom platforms

Harris contracted by Army for radios for security force assistance brigades

Joint Hellas-Sat-4 and SaudiGeoSat-1 satellite ready for environmental tests

CYBER WARS
UK army seeks recruits by offering emotional support

US troops stage #MeTooMilitary protest outside Pentagon

Too fat to march: Spanish Legion soldiers put on diet

Environmentally safe red glare rocket changes fireworks, soldier technology

CYBER WARS
Rolls-Royce deepens restructuring, may sell marine unit

Norway wealth fund bans 9 groups, including BAE Systems

N. Korea steps up tunnelling at nuclear test site: monitor

Airbus fined 104 mn euros over Taiwan missile affair

CYBER WARS
EU 'hearts still open' to Brexit reversal

FBI warned Kushner on Murdoch ex-wife: report

Japan says China sent nuclear-powered sub to disputed isles

Greek, Turkish patrol ships collide near disputed islets

CYBER WARS
Silver nanoparticles take spectroscopy to new dimension

Researchers find simpler way to deposit magnetic iron oxide onto gold nanorods

Discovery sets new world standard in nano generators

A 100-fold leap to GigaDalton DNA nanotech