Iran spied on ISIS supporters through fake phone wallpaper app, say researchers
September 14, 2018 1 Comment
Supporters of the Islamic State, most of them Persian speakers, were spied on by the government of Iran after they downloaded a fake smartphone application with wallpaper images, according to an online security firm. Iran is a major adversary of the radical Sunni group Islamic State. The latter considers Shiism (Iran’s state religion) as an abomination. Not surprisingly, therefore, the Islamic State, which is also known as the Islamic State of Iraq and Syria (ISIS), relies largely on supporters from the Arabic-speaking regions of the Levant. But according to estimates, Sunnis constitute about 10 percent of Iran’s population, and ISIS has found some fertile ground among Iran’s 8 million-strong Sunni minority. As a result, the government in Tehran is highly mistrustful of Iranian Sunnis, many of whom are ethnic Kurds, Baluchis, Azeris or Turkomans, and systematically spies on them.
According to the Israeli online security firm Check Point Software Technologies, one way in which Tehran has spied on Persian-speaking ISIS supporters is through fake smartphone applications. In an article published last week, the company said it had uncovered a state-sponsored surveillance operation that it had codenamed “Domestic Kitten”. The Check Point article said that the operation had gone on for more than two years, but had remained undetected “due to the artful deception of its attackers towards their targets”. The surveillance of targeted phones was carried out with the help of an application that featured pro-ISIS-themed wallpapers, which users could download on their devices. Yet another program linked to the same vendor was a fake version of the Firat News Agency mobile phone application. The Firat News Agency is a legitimate Iranian information service featuring news about Iran’s Kurdish minority. But both applications were in fact malware that gave a remote party full access to all text messages sent or received on the compromised phones. They also gave a remote party access to records of phone calls, Internet browser activity and bookmarks, and all files stored on the compromised phones. Additionally, the fake applications gave away the geo-location of compromised devices, and used their built-in cameras and microphones as surveillance devices.
Check Point said that the majority of compromised phones belonged to Persian-speaking members of Iran’s Kurdish and Turkoman minorities. The company stressed that it was not able to confirm the identity of the sponsoring party with absolute accuracy. However, the nature of the fake applications, the infrastructure of the surveillance operation, as well as the identities of those targeted, posed a strong possibility that “Domestic Kitten” was sponsored by the government of Iran, it concluded. Last July, the American cyber security firm Symantec said that it had uncovered a new cyber espionage group called “Leafminer”, which was allegedly sponsored by the Iranian state. The group had reportedly launched attacks on more than 800 agencies and organizations in in countries such as Israel, Egypt, Bahrain, Qatar, Kuwait, the United Arab Emirates, Afghanistan and Azerbaijan.
► Author: Ian Allen | Date: 14 September 2018 | Permalink
A Russian-made device caused the mystery ailments that affected more than two dozen American diplomats in Cuba and China, according to United States government officials who have been briefed on the matter. Since September of last year, Washington has recalled the majority of its personnel from its embassy in Havana and at least
A group of German radicals planned to assassinate Soviet Premier Mikhail Gorbachev in East Germany in 1989, thus triggering a Soviet military invasion of the country, according to a new book written by a former British spy. The
United States President Donald Trump authorized American officials to attend secret meetings held by Venezuelan military officers who conspired to launch a military coup against President Nicolás Maduro. The claim was made on Saturday by The New York Times, which
Sergei Skripal, the Russian double agent who was poisoned with a military-grade nerve agent in England earlier this year, worked with Spanish intelligence after his defection to the United Kingdom, according to sources. Skripal, a former military intelligence officer who spied for Britain in the early 2000s, had kept a low profile while living in the English town of Salisbury. He was resettled there in 2010 by the British Secret Intelligence Service (MI6), after he was released from a Russian prison. But he and his daughter Yulia made international headlines in March, after they were
Security agencies in Eastern Europe have voiced concern about the rise of far-right paramilitary groups whose members have access to heavy weaponry, including in some cases armored vehicles and tanks. The most recent warning came on Sunday, when the Czech daily newspaper Mlada Fronta Dnes published excerpts of a leaked security report on the subject. The report was authored by analysts in the Security Information Service (BIS), the country’s primary domestic intelligence agency. It detailed the recent activities of a group calling itself the National Home Guard, a far-right, anti-immigrant militia that
Police in Norway and Holland have opened formal investigations into the whereabouts of a Dutch cybersecurity expert and senior associate of WikiLeaks, who disappeared without trace on August 20. Arjen Kamphuis, a 47-year-old online privacy specialist, is known for his book Information Security for Journalists, which offers advice on investigative reporters working on national security and intelligence matters. Additionally, Kamphuis, who has Dutch citizenship, is a close associate of Julian Assange, founder of the international whistleblower website WikiLeaks.
Germany has dropped a criminal case against the second-in-command of Switzerland’s intelligence agency, who was accused by Berlin of authorizing an espionage operation against the German tax collection service. A year ago, Germany launched an
Advanced weapons that emit microwave radiation were most likely responsible for the ailments of American diplomats in Cuba and China, according to the scientist leading the investigations into the matter. In September of 2017, Washington recalled the majority of its personnel from its embassy in Havana and issued a
Eight senior officials of Malaysia’s external intelligence agency, including its former director, have been arrested, allegedly for stealing over $16 million from government coffers. The arrests represent a dramatic widening of the anti-corruption campaign that has gripped the Asian nation of 31 million since it was launched in May of this year. The campaign is led by a special task force within the Malaysian Anti-Corruption Commission (MACC). The task force was set up by Malaysia’s Prime Minister Mahathir Mohamad, with the aim of probing the so-called 1MDB scandal. The acronym refers to the 1Malaysia Development Berhad, a government-owned strategic development company spearheaded by Malaysia’s then Prime Minister, Dato Sri Najib Razak, with the aim of raising funds to match foreign direct investment in the country.
The government of Afghanistan is facing one of its most serious crises since the end of the Taliban reign in 2001, as the country’s most senior security and intelligence officials tendered their resignations this week. The unprecedented move followed a dramatic escalation in attacks against Afghan government installations by Taliban and Islamic State forces, which have resulted in dozens of casualties throughout the Central Asian country. On Saturday, Mohammad Haneef Atmar, long time national security adviser to President Ashraf Ghani and one of the Afghanistan’s most recognizable and powerful political figures, tendered his
A delegation of senior American government officials met secretly with Syria’s spy chiefs in an effort to lay out the terms of a possible deal between Washington and Damascus, according to a Lebanese newspaper. Relations between the United States and Syria have been strained since the late 1950s, when Damascus blamed Washington for a failed coup and expelled America’s ambassador there. In 2012, the US shut down its embassy in the Syrian capital in response to the government’s violent suppression of protests. Since then, Washington has carried out missile strikes on Syrian soil at least twice, while openly supporting armed groups that are opposed to the government of President Bashar al-Assad.
Russia, the United States and Tajikistan have all denied that they were behind a series of mystery airstrikes that took place along the Tajik-Afghan border on Sunday, while the identity of the targets also remains unknown. The 800-mile border between Afghanistan and Tajikistan consists of mountainous terrain. Unlike the Afghan-Pakistani border, which is rife with skirmishes and firefights, the Afghan-Tajik border is usually peaceful and sparsely guarded. But on Sunday, August 26, local officials from both sides of the Afghan-Tajik border
Secret informants inside the Russian government, which the United States has relied on in recent years for tips about Moscow’s strategy and tactics, have gone silent in recent months, according to sources. Over many years, US intelligence agencies have built networks of Russian informants. These consist of officials placed in senior positions inside the Kremlin and other Russian government institutions, who can help shed light on Russia’s political maneuvers. These informants were crucial in enabling the US Intelligence Community to issue warnings of possible Russian meddling in the American presidential elections of November 2016. Since then, US spy agencies have largely relied on these informants to produce detailed assessments of Russian intelligence activities targeting the US, and propose 






Western spy agencies thwarted alleged Russian plot to hack Swiss chemical lab
September 17, 2018 by intelNews Leave a comment
The laboratory, located in the western Swiss city of Spiez, has been commissioned by the Netherlands-based Organization for the Prohibition of Chemical Weapons (OPCW) to carry out investigations related to the poisoning of Russian double agent Sergei Skripal and his daughter Yulia in March of this year. It has also carried out probes on the alleged use of chemical weapons by the Russian-backed government of President Bashar al-Assad in Syria. In the case of the Skripals, the laboratory said it was able to duplicate findings made earlier by a British laboratory.
Switzerland’s Federal Intelligence Service (NDB) reportedly confirmed the arrest and subsequent expulsion of the two Russians. The Swiss agency said it “cooperated actively with Dutch and British partners” and thus “contributed to preventing illegal actions against a sensitive Swiss infrastructure”. The office of the Public Prosecutor in the Swiss capital Bern said that the two Russians had been the subject of a criminal investigation that began as early as March 2017. They were allegedly suspected of hacking the computer network of the regional office of the World Anti-Doping Agency in Lausanne. The Spiez laboratory was a target of hacking attempts earlier this year, according to a laboratory spokesperson. “We defended ourselves against that. No data was lost”, the spokesperson stated.
On April 14, Russian Minister of Foreign Affairs Sergei Lavrov stated that he had obtained the confidential Spiez lab report about the Skripal case “from a confidential source”. That report confirmed earlier findings made by a British laboratory. But the OPCW, of which Russia is a member, states that its protocols do not involve dissemination of scientific reports to OPCW member states. Hence, the question is how Foreign Minister Lavrov got hold of the document.
As intelNews reported in March, in the aftermath of the Skripals’ poisoning the Dutch government expelled two employees of the Russian embassy in The Hague. In a letter [.pdf] sent to the Dutch parliament on March 26 —the day when a large number of countries announced punitive measures against Russia— Holland’s foreign and internal affairs ministers stated that they had decided to expel the two Russian diplomats “in close consultation with allies and partners”. The Russians were ordered to leave the Netherlands within two weeks. It is unknown whether the two expelled Russian diplomats are the same two who were apprehended in The Hague, since none have been publicly named.
A November 2017 parliamentary letter from Dutch minister of internal affairs Kajsa Ollongren, states[4] that Russian intelligence officers are “structurally present” in the Netherlands in various sectors of society to covertly collect intelligence. The letter added that, in addition to traditional human intelligence (HUMINT) methods, Russia deploys digital means to influence decision-making processes and public opinion in Holland.
► Author: Matthijs Koot | Date: 17 September 2018 | Permalink
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with computer hacking, diplomatic expulsions, GRU, MIVD (Netherlands), NDB (Switzerland), Netherlands, News, Switzerland