Saudi Arabia may be abusing global phone tracking system to spy on dissidents

Saudi TelecomThe government of Saudi Arabia may be exploiting a decades-old tracking system embedded in the global mobile telecommu- nications network in order to spy on its citizens as they travel abroad, a report suggests. The report was published on Sunday in the British broadsheet The Guardian, based on documents provided by an anonymous whistle-blower.

The alleged documents may implicate Saudi Arabia’s three largest cellular telecommuni- cations service providers, said The Guardian, namely Mobily, Zain and Saudi Telecom. The anonymous whistle-blower told the paper that these companies were “weaponizing mobile technologies”, allegedly under the direction of Saudi Arabia’s ruling monarchy, which is notorious for suppressing political dissent within and outside the oil kingdom.

The alleged method of surveillance relies on SS7, a decades-old feature of the global cellular telecommunications system, which allows cellular providers to provide service to mobile phone users as they travel internationally. The SS7 system allows a mobile phone registered in a specific country to be used from a different country, and its user to be charged for the service. But to do so with accuracy, the SS7 system enables the service provider to track the owner of the device being charged for the phone call. This is done through what is known in cellular telecommunications parlance as a Provide Subscriber Location, or PSL, request.

According to The Guardian, Saudi cellular telecommunications providers have been making “excessive use” of PSLs in recent years. This indicates possible attempts to track the physical movements of Saudi cell mobile phone users who are traveling to the United States, and possibly other countries. The paper said that millions of PSLs were filed by Saudi Arabia in a one-month period in November of 2019. There is no telling how long this alleged surveillance operation has been going on, and in how many countries.

The paper also said that Ron Wyden, a Democratic senator from the US state of Oregon, who is a member of the Senate’s powerful Committee on Intelligence, has written to the Federal Communications Commission (FCC) about the privacy vulnerabilities of the SS7 system. However, the FCC has taken no action on the matter.

Author: Ian Allen | Date: 30 March 2020 | Permalink

Google removes Iranian government’s COVID-19 app amidst claims of espionage

Iran Ministry of Health and Medical EducationAn Android application developed by the Iranian government to assist in coordinating the country’s response to the COVID-19 epidemic has been removed by Google amidst accusations that it may be used to track Iranian dissidents. The application, named AC19, was released several days ago by Iran’s Ministry of Health and Medical Education. Its release was announced through a text message sent by the Iranian government to every mobile telephone subscriber in the country. The text message urged citizens to download the application through a dedicated website or third-party app stores, including the Google Play Store. Millions have since done so.

The purpose of AC19 is to help coordinate the nationwide response to COVID-19, known as coronavirus, in a country that is experiencing one of the world’s most prolific outbreaks of the disease. App users can register using their unique phone number and determine whether their flu-like symptoms resemble those of COVID-19. The app’s developers argue that it can help keep people from flooding local hospitals throughout the country, which are already overwhelmed.

But some users have raised concerns that the app also requests access to the real-time geolocation data of users, which it then stores in remote databases. As technology news website ZDNet reports, some have accused the government in Tehran of using the AC19 app in order to track the movements of citizens. An expert consulted by ZDNet to examine the app’s technical details said that it did not appear to contain unusually intrusive features or functions.

However, the company used to develop the app, called Smart Land Strategy, has previously built apps that, according to ZDNet, were used by the Iranian intelligence services and were subsequently removed from the Google Play Store. Some Iranians claim that, given the connection between AC19 and Smart Land Strategy, it is possible that the new app may be used in the future by the Iranian government to spy on citizens, despite the fact that it may be presently useful in efforts to contain the COVID-19 epidemic.

The app continues to be available through Iranian government websites and app sites other than Google’s.

Author: Ian Allen | Date: 10 March 2020 | Permalink

WhatsApp sues Israeli firm for enabling spy attacks on 1,400 users worldwide

NSO GroupThe Facebook-owned company WhatsApp has filed a lawsuit against a leading Israeli technology firm, accusing it of enabling governments around the world to spy on 1,400 high-profile users, including politicians and diplomats. The Reuters news agency said it spoke to “people familiar” with the investigation into the spy scandal, which it says was launched “earlier this year”.

What is interesting about the case, says Reuters, is that a “significant” proportion of the hundreds of WhatsApp users who were targeted by governments worldwide are “high profile” officials. The victims reportedly serve in various government agencies, including the armed forces, of at least 20 countries on five continents. They allegedly include politicians, diplomats, military officers, academics, journalists, lawyers and human-rights activists in countries such as the United States, India, Mexico, Bahrain, the United Arab Emirates and Pakistan.

WhatsApp alleges that the spy activities against these individuals were enabled by NSO Group, an Israeli software development company that specializes in surveillance technologies. The Facebook-owned company alleges that NSO Group specifically developed a hacking platform that allows its users to exploit flaws in WhatsApp’s servers in order to gain access to the telephone devices of targeted individuals. At least 1,400 of WhatsApp’s users had their telephones compromised between April 29 and May 10, 2019, says WhatsApp.

NSO Group, whose clientele consists exclusively of government agencies worldwide, denies any wrongdoing. The company claims that its products are designed to “help governments catch terrorists and criminals”, says Reuters. But WhatsApp and Citizen Lab, a research initiative based at the University of Toronto, which worked with WhatsApp on the NGO Group case, claim that at least 100 of the 1,400 victims were news journalists, political activists and the lawyers who defend them. There was no overlap between ongoing criminal or terrorism investigations and those targeted by NSO Group’s software, they claim.

The names on the list of espionage victims are not known. But Reuters said that, depending on how high-profile the victims are, the WhatsApp-NSO Group spy scandal could have worldwide political and diplomatic consequences.

Author: Joseph Fitsanakis | Date: 01 November 2019 | Permalink

Israel planted surveillance devices targeting Trump, claims report

White HouseThe intelligence services of Israel planted surveillance devices around the White House in an attempt to spy on United States President Donald Trump and his senior advisors, according to a report published on Thursday. The report, authored by Politico’s Daniel Lippman, cited three former US officials with knowledge on the matter, “several of whom served in top intelligence and national security posts”, it said.

According to Politico, the Israelis planted International Mobile Subscriber Identity (IMSI) catchers —known in technical-surveillance lingo as “StingRays” after a leading hardware brand. StingRay devices are designed to simulate the activity of legitimate cell towers in order to trick cell phones into communicating with them. That allows StingRay users to monitor the physical whereabouts of targeted cell phones. Some of the more expensive Stingray models can intercept the actual content of telephone conversations and can even plant Trojans on the compromised phones of unsuspecting users.

Politico said that the StingRays found around the White House were of the highest technical sophistication, and were “likely intended” to spy on President Trump, his senior advisers and other close associates. Politico said it had no information on whether the attempt was successful. The spy devices were detected by the Department of Homeland Security (DHS) in 2017 and acknowledged by US government officials in 2018. Senior American intelligence officials allegedly told Politico that an exhaustive two-year investigation into the matter showed “with confidence [that] the Israelis were responsible” for the StingRays.

The investigation was led by the counterintelligence division of the Federal Bureau of Investigation with the help of the DHS and the Secret Service. The National Security Agency and the Central Intelligence Agency are also known to assist such counterintelligence investigations. The devices were disassembled and their technical specifications were carefully inspected to assess their history and origins. Investigators reportedly concluded that very few countries have the technical and financial capabilities to build and plant such devices in the US, and that Israel was the most likely culprit.

Politico also said that some intelligence officials are unhappy about the Trump administration’s lack of response to the alleged spying by Israel. According to the officials, the White House did not file a protest —either publicly or privately— with the Israeli government, and “there were no consequences for Israel’s behavior”.  On Thursday afternoon, the US president voiced skepticism when asked by reporters about the Politico report: “I really would find that hard to believe”, said Trump, adding that his “relationship with Israel has been great”. Meanwhile the office of the Israeli Prime Minister Benjamin Netanyahu dismissed the Politico report as “a blatant lie” and noted that Israel’s spy services had “a directive from the Israeli government not to engage in any intelligence operations in the US”.

Author: Joseph Fitsanakis | Date: 13 September 2019 | Permalink

Trump’s use of unsecured iPhone worries White House officials

Donald TrumpOfficials in the White House are concerned about President Donald Trump’s insistence on using an unsecured iPhone to communicate with friends and associates, despite warnings that foreign spies may be listening in. Prior to being elected president, Trump used an Android phone, made by Google, which the NSA advised him to abandon due to security concerns. That is when he switched to using iPhones. Since his election to the presidency, Trump has routinely used three iPhone cell phones. He uses one of them to access a limited list of authorized applications, including Twitter. He uses the second iPhone for phone calls, but cannot use it to send texts, take pictures, or download and install applications. Both of these iPhones have been vetted and secured by the National Security Agency (NSA).

But The New York Times said on Wednesday that, despite the advice of the NSA, the US president continues to use a third iPhone, which is his personal device. The newspaper cited “current and former American officials” who said that the president’s third iPhone has not been secured by the NSA, and is thus “no different from hundreds of millions of iPhones in use around the world”. Trump uses that third iPhone to call many of his old friends and associates. The president has been repeatedly warned, sources said, to abandon the use of his unsecured third iPhone. Moreover, US intelligence agencies have confirmed that Chinese, Russian, and possibly other spy agencies have been “routinely eavesdropping” on the US president’s calls made on his personal iPhone.

To some extent, Trump has heeded the advice of his intelligence agencies in recent months and has begun to rely on his secure White House landline to make important calls, thus avoiding cell phones altogether. But he refuses to give up use of his iPhones, despite repeated warnings by the NSA, sources told The Times. They added that “they can only hope [Trump] refrains from discussing classified information when he is on them”. The president’s use of unsecured phone devices adds to what sources described as “frustration” with his “casual approach” to communications security. In July of this year, Nada Bakos, a 20-year veteran of the Central Intelligence Agency, said in an editorial that President Trump’s “Twitter feed is a gold mine for every foreign intelligence agency”. The CIA veteran described Trump’s use of social media is too impulsive and potentially dangerous from a national-security perspective.

Author: Joseph Fitsanakis | Date: 25 October 2018 | Permalink

Iran spied on ISIS supporters through fake phone wallpaper app, say researchers

Cell Phone - IASupporters of the Islamic State, most of them Persian speakers, were spied on by the government of Iran after they downloaded a fake smartphone application with wallpaper images, according to an online security firm. Iran is a major adversary of the radical Sunni group Islamic State. The latter considers Shiism (Iran’s state religion) as an abomination. Not surprisingly, therefore, the Islamic State, which is also known as the Islamic State of Iraq and Syria (ISIS), relies largely on supporters from the Arabic-speaking regions of the Levant. But according to estimates, Sunnis constitute about 10 percent of Iran’s population, and ISIS has found some fertile ground among Iran’s 8 million-strong Sunni minority. As a result, the government in Tehran is highly mistrustful of Iranian Sunnis, many of whom are ethnic Kurds, Baluchis, Azeris or Turkomans, and systematically spies on them.

According to the Israeli online security firm Check Point Software Technologies, one way in which Tehran has spied on Persian-speaking ISIS supporters is through fake smartphone applications. In an article published last week, the company said it had uncovered a state-sponsored surveillance operation that it had codenamed “Domestic Kitten”. The Check Point article said that the operation had gone on for more than two years, but had remained undetected “due to the artful deception of its attackers towards their targets”. The surveillance of targeted phones was carried out with the help of an application that featured pro-ISIS-themed wallpapers, which users could download on their devices. Yet another program linked to the same vendor was a fake version of the Firat News Agency mobile phone application. The Firat News Agency is a legitimate Iranian information service featuring news about Iran’s Kurdish minority. But both applications were in fact malware that gave a remote party full access to all text messages sent or received on the compromised phones. They also gave a remote party access to records of phone calls, Internet browser activity and bookmarks, and all files stored on the compromised phones. Additionally, the fake applications gave away the geo-location of compromised devices, and used their built-in cameras and microphones as surveillance devices.

Check Point said that the majority of compromised phones belonged to Persian-speaking members of Iran’s Kurdish and Turkoman minorities. The company stressed that it was not able to confirm the identity of the sponsoring party with absolute accuracy. However, the nature of the fake applications, the infrastructure of the surveillance operation, as well as the identities of those targeted, posed a strong possibility that “Domestic Kitten” was sponsored by the government of Iran, it concluded. Last July, the American cyber security firm Symantec said that it had uncovered a new cyber espionage group called “Leafminer”, which was allegedly sponsored by the Iranian state. The group had reportedly launched attacks on more than 800 agencies and organizations in in countries such as Israel, Egypt, Bahrain, Qatar, Kuwait, the United Arab Emirates, Afghanistan and Azerbaijan.

Author: Ian Allen | Date: 14 September 2018 | Permalink

Most government hackers now target cell phones, not computers, experts say

Cell Phone - IAThe majority of government-sponsored hacking now targets cell phones, not personal computers, according to researchers who say that political dissidents are especially targeted by totalitarian regimes around the world. Until 2015, most government-sponsored hacking operations were directed against the personal computers of targeted individuals. However, experts tell The Wall Street Journal that as of this year cell phones have become a far more lucrative target than personal computers in government-sponsored hacking operations. Researchers with Lookout Mobile Security, a security software company based in the United States, say that detected phone-hacking operations that are believed to be sponsored by governments have increased by a factor of 10 in the first five months of this year, compared to 2015.

According to Lookout, the increase in hacking operations targeting mobile phones reflects the proliferation of smartphone usage around the world, as well as the increase in consumption of cell phone software. Government-sponsored hackers usually compromise their targets’ cell phones through malicious software disguised as cell phone applications. The Wall Street Journal also reports that the software needed to build malicious software for cell phones has become cheaper and more readily available. Compromising a target’s cell phone provides hackers with information that is far more personal and sensitive than what can be found on a personal computer. The paper quotes Mike Murray, Lookout’s vice president of security research, who says: “It is one thing to compromise someone’s computer. It’s another thing to have a listening device that they carry around with them 24 hours a day”. Compromised phones become immensely powerful espionage tools, explains Murray.

Many of the individuals whose cell phones are targeted by governments are activists or dissidents who campaign for political or economic reforms in their countries. Their cell phones are targeted in systematic hacking campaigns by countries like Ethiopia, the United Arab Emirates, Cambodia, and Mexico, said Lookout. The Wall Street Journal cites Raj Samani, chief scientist for the antivirus firm McAfee, who claims that nearly 11 percent of cell phones worldwide were infected with some kind of malware in 2017. That statistic is likely to rise significantly by the end of 2018, says Samani.

Author: Ian Allen | Date: 08 June 2018 | Permalink