Catalan pro-independence leader’s phone hacked using Israeli spy software

Roger TorrentThe personal smartphones of leading Catalan pro-independence politicians were hacked using a highly invasive software built by a controversial Israeli firm, according to an investigative report by two newspapers. The revelation is likely to reignite a tense row between Madrid and pro-independence activists in one of the country’s wealthiest regions, which led to a major political crisis in 2017.

An estimated 50 percent of the population of the autonomous Spanish region of Catalonia wishes to secede from Spain. However, Madrid refused to recognize the legitimacy of an independence referendum organized by secessionist activists in 2017. The stalemate led to massive protests throughout the country, which were marred by violence and thousands of arrests, as Spain faced its deepest political crisis since the 1970s. In response to the protests, the central government suspended Catalonia’s autonomous status and arrested many of the independent movement’s leaders. Many of them have been given lengthy jail terms, while others remain abroad and are wanted by the Spanish government for promoting insurrection.

On Monday, British newspaper The Guardian and Spanish newspaper El País revealed the results of a joint investigation, according to which the smartphones of senior Catalan pro-independence politicians were targeted by hackers in 2019, and possibly even earlier. Among them was Roger Torrent, who serves as the speaker of the Parliament of Catalonia. The newspapers said he had been alerted to the hacking by cybersecurity employees of WhatsApp, a Facebook-owned company whose application was allegedly used by the hackers to take control of Torrent’s phone.

The software that was allegedly used to hack the Catalan politicians’ phones was Pegasus. It was built by NSO Group, an Israeli software development company that specializes in surveillance technologies. According to WhatsApp, which sued NSO Group in 2019, NSO Group specifically developed the Pegasus hacking platform to enable its users to exploit flaws in WhatsApp’s servers and to gain access to the telephone devices of targeted individuals. Pegasus allegedly allows its users to covertly operate a compromised phone’s camera and microphone. Read more of this post

Saudi Arabia may be abusing global phone tracking system to spy on dissidents

Saudi TelecomThe government of Saudi Arabia may be exploiting a decades-old tracking system embedded in the global mobile telecommu- nications network in order to spy on its citizens as they travel abroad, a report suggests. The report was published on Sunday in the British broadsheet The Guardian, based on documents provided by an anonymous whistle-blower.

The alleged documents may implicate Saudi Arabia’s three largest cellular telecommuni- cations service providers, said The Guardian, namely Mobily, Zain and Saudi Telecom. The anonymous whistle-blower told the paper that these companies were “weaponizing mobile technologies”, allegedly under the direction of Saudi Arabia’s ruling monarchy, which is notorious for suppressing political dissent within and outside the oil kingdom.

The alleged method of surveillance relies on SS7, a decades-old feature of the global cellular telecommunications system, which allows cellular providers to provide service to mobile phone users as they travel internationally. The SS7 system allows a mobile phone registered in a specific country to be used from a different country, and its user to be charged for the service. But to do so with accuracy, the SS7 system enables the service provider to track the owner of the device being charged for the phone call. This is done through what is known in cellular telecommunications parlance as a Provide Subscriber Location, or PSL, request.

According to The Guardian, Saudi cellular telecommunications providers have been making “excessive use” of PSLs in recent years. This indicates possible attempts to track the physical movements of Saudi cell mobile phone users who are traveling to the United States, and possibly other countries. The paper said that millions of PSLs were filed by Saudi Arabia in a one-month period in November of 2019. There is no telling how long this alleged surveillance operation has been going on, and in how many countries.

The paper also said that Ron Wyden, a Democratic senator from the US state of Oregon, who is a member of the Senate’s powerful Committee on Intelligence, has written to the Federal Communications Commission (FCC) about the privacy vulnerabilities of the SS7 system. However, the FCC has taken no action on the matter.

Author: Ian Allen | Date: 30 March 2020 | Permalink

Google removes Iranian government’s COVID-19 app amidst claims of espionage

Iran Ministry of Health and Medical EducationAn Android application developed by the Iranian government to assist in coordinating the country’s response to the COVID-19 epidemic has been removed by Google amidst accusations that it may be used to track Iranian dissidents. The application, named AC19, was released several days ago by Iran’s Ministry of Health and Medical Education. Its release was announced through a text message sent by the Iranian government to every mobile telephone subscriber in the country. The text message urged citizens to download the application through a dedicated website or third-party app stores, including the Google Play Store. Millions have since done so.

The purpose of AC19 is to help coordinate the nationwide response to COVID-19, known as coronavirus, in a country that is experiencing one of the world’s most prolific outbreaks of the disease. App users can register using their unique phone number and determine whether their flu-like symptoms resemble those of COVID-19. The app’s developers argue that it can help keep people from flooding local hospitals throughout the country, which are already overwhelmed.

But some users have raised concerns that the app also requests access to the real-time geolocation data of users, which it then stores in remote databases. As technology news website ZDNet reports, some have accused the government in Tehran of using the AC19 app in order to track the movements of citizens. An expert consulted by ZDNet to examine the app’s technical details said that it did not appear to contain unusually intrusive features or functions.

However, the company used to develop the app, called Smart Land Strategy, has previously built apps that, according to ZDNet, were used by the Iranian intelligence services and were subsequently removed from the Google Play Store. Some Iranians claim that, given the connection between AC19 and Smart Land Strategy, it is possible that the new app may be used in the future by the Iranian government to spy on citizens, despite the fact that it may be presently useful in efforts to contain the COVID-19 epidemic.

The app continues to be available through Iranian government websites and app sites other than Google’s.

Author: Ian Allen | Date: 10 March 2020 | Permalink

WhatsApp sues Israeli firm for enabling spy attacks on 1,400 users worldwide

NSO GroupThe Facebook-owned company WhatsApp has filed a lawsuit against a leading Israeli technology firm, accusing it of enabling governments around the world to spy on 1,400 high-profile users, including politicians and diplomats. The Reuters news agency said it spoke to “people familiar” with the investigation into the spy scandal, which it says was launched “earlier this year”.

What is interesting about the case, says Reuters, is that a “significant” proportion of the hundreds of WhatsApp users who were targeted by governments worldwide are “high profile” officials. The victims reportedly serve in various government agencies, including the armed forces, of at least 20 countries on five continents. They allegedly include politicians, diplomats, military officers, academics, journalists, lawyers and human-rights activists in countries such as the United States, India, Mexico, Bahrain, the United Arab Emirates and Pakistan.

WhatsApp alleges that the spy activities against these individuals were enabled by NSO Group, an Israeli software development company that specializes in surveillance technologies. The Facebook-owned company alleges that NSO Group specifically developed a hacking platform that allows its users to exploit flaws in WhatsApp’s servers in order to gain access to the telephone devices of targeted individuals. At least 1,400 of WhatsApp’s users had their telephones compromised between April 29 and May 10, 2019, says WhatsApp.

NSO Group, whose clientele consists exclusively of government agencies worldwide, denies any wrongdoing. The company claims that its products are designed to “help governments catch terrorists and criminals”, says Reuters. But WhatsApp and Citizen Lab, a research initiative based at the University of Toronto, which worked with WhatsApp on the NGO Group case, claim that at least 100 of the 1,400 victims were news journalists, political activists and the lawyers who defend them. There was no overlap between ongoing criminal or terrorism investigations and those targeted by NSO Group’s software, they claim.

The names on the list of espionage victims are not known. But Reuters said that, depending on how high-profile the victims are, the WhatsApp-NSO Group spy scandal could have worldwide political and diplomatic consequences.

Author: Joseph Fitsanakis | Date: 01 November 2019 | Permalink

Israel planted surveillance devices targeting Trump, claims report

White HouseThe intelligence services of Israel planted surveillance devices around the White House in an attempt to spy on United States President Donald Trump and his senior advisors, according to a report published on Thursday. The report, authored by Politico’s Daniel Lippman, cited three former US officials with knowledge on the matter, “several of whom served in top intelligence and national security posts”, it said.

According to Politico, the Israelis planted International Mobile Subscriber Identity (IMSI) catchers —known in technical-surveillance lingo as “StingRays” after a leading hardware brand. StingRay devices are designed to simulate the activity of legitimate cell towers in order to trick cell phones into communicating with them. That allows StingRay users to monitor the physical whereabouts of targeted cell phones. Some of the more expensive Stingray models can intercept the actual content of telephone conversations and can even plant Trojans on the compromised phones of unsuspecting users.

Politico said that the StingRays found around the White House were of the highest technical sophistication, and were “likely intended” to spy on President Trump, his senior advisers and other close associates. Politico said it had no information on whether the attempt was successful. The spy devices were detected by the Department of Homeland Security (DHS) in 2017 and acknowledged by US government officials in 2018. Senior American intelligence officials allegedly told Politico that an exhaustive two-year investigation into the matter showed “with confidence [that] the Israelis were responsible” for the StingRays.

The investigation was led by the counterintelligence division of the Federal Bureau of Investigation with the help of the DHS and the Secret Service. The National Security Agency and the Central Intelligence Agency are also known to assist such counterintelligence investigations. The devices were disassembled and their technical specifications were carefully inspected to assess their history and origins. Investigators reportedly concluded that very few countries have the technical and financial capabilities to build and plant such devices in the US, and that Israel was the most likely culprit.

Politico also said that some intelligence officials are unhappy about the Trump administration’s lack of response to the alleged spying by Israel. According to the officials, the White House did not file a protest —either publicly or privately— with the Israeli government, and “there were no consequences for Israel’s behavior”.  On Thursday afternoon, the US president voiced skepticism when asked by reporters about the Politico report: “I really would find that hard to believe”, said Trump, adding that his “relationship with Israel has been great”. Meanwhile the office of the Israeli Prime Minister Benjamin Netanyahu dismissed the Politico report as “a blatant lie” and noted that Israel’s spy services had “a directive from the Israeli government not to engage in any intelligence operations in the US”.

Author: Joseph Fitsanakis | Date: 13 September 2019 | Permalink

Trump’s use of unsecured iPhone worries White House officials

Donald TrumpOfficials in the White House are concerned about President Donald Trump’s insistence on using an unsecured iPhone to communicate with friends and associates, despite warnings that foreign spies may be listening in. Prior to being elected president, Trump used an Android phone, made by Google, which the NSA advised him to abandon due to security concerns. That is when he switched to using iPhones. Since his election to the presidency, Trump has routinely used three iPhone cell phones. He uses one of them to access a limited list of authorized applications, including Twitter. He uses the second iPhone for phone calls, but cannot use it to send texts, take pictures, or download and install applications. Both of these iPhones have been vetted and secured by the National Security Agency (NSA).

But The New York Times said on Wednesday that, despite the advice of the NSA, the US president continues to use a third iPhone, which is his personal device. The newspaper cited “current and former American officials” who said that the president’s third iPhone has not been secured by the NSA, and is thus “no different from hundreds of millions of iPhones in use around the world”. Trump uses that third iPhone to call many of his old friends and associates. The president has been repeatedly warned, sources said, to abandon the use of his unsecured third iPhone. Moreover, US intelligence agencies have confirmed that Chinese, Russian, and possibly other spy agencies have been “routinely eavesdropping” on the US president’s calls made on his personal iPhone.

To some extent, Trump has heeded the advice of his intelligence agencies in recent months and has begun to rely on his secure White House landline to make important calls, thus avoiding cell phones altogether. But he refuses to give up use of his iPhones, despite repeated warnings by the NSA, sources told The Times. They added that “they can only hope [Trump] refrains from discussing classified information when he is on them”. The president’s use of unsecured phone devices adds to what sources described as “frustration” with his “casual approach” to communications security. In July of this year, Nada Bakos, a 20-year veteran of the Central Intelligence Agency, said in an editorial that President Trump’s “Twitter feed is a gold mine for every foreign intelligence agency”. The CIA veteran described Trump’s use of social media is too impulsive and potentially dangerous from a national-security perspective.

Author: Joseph Fitsanakis | Date: 25 October 2018 | Permalink

Iran spied on ISIS supporters through fake phone wallpaper app, say researchers

Cell Phone - IASupporters of the Islamic State, most of them Persian speakers, were spied on by the government of Iran after they downloaded a fake smartphone application with wallpaper images, according to an online security firm. Iran is a major adversary of the radical Sunni group Islamic State. The latter considers Shiism (Iran’s state religion) as an abomination. Not surprisingly, therefore, the Islamic State, which is also known as the Islamic State of Iraq and Syria (ISIS), relies largely on supporters from the Arabic-speaking regions of the Levant. But according to estimates, Sunnis constitute about 10 percent of Iran’s population, and ISIS has found some fertile ground among Iran’s 8 million-strong Sunni minority. As a result, the government in Tehran is highly mistrustful of Iranian Sunnis, many of whom are ethnic Kurds, Baluchis, Azeris or Turkomans, and systematically spies on them.

According to the Israeli online security firm Check Point Software Technologies, one way in which Tehran has spied on Persian-speaking ISIS supporters is through fake smartphone applications. In an article published last week, the company said it had uncovered a state-sponsored surveillance operation that it had codenamed “Domestic Kitten”. The Check Point article said that the operation had gone on for more than two years, but had remained undetected “due to the artful deception of its attackers towards their targets”. The surveillance of targeted phones was carried out with the help of an application that featured pro-ISIS-themed wallpapers, which users could download on their devices. Yet another program linked to the same vendor was a fake version of the Firat News Agency mobile phone application. The Firat News Agency is a legitimate Iranian information service featuring news about Iran’s Kurdish minority. But both applications were in fact malware that gave a remote party full access to all text messages sent or received on the compromised phones. They also gave a remote party access to records of phone calls, Internet browser activity and bookmarks, and all files stored on the compromised phones. Additionally, the fake applications gave away the geo-location of compromised devices, and used their built-in cameras and microphones as surveillance devices.

Check Point said that the majority of compromised phones belonged to Persian-speaking members of Iran’s Kurdish and Turkoman minorities. The company stressed that it was not able to confirm the identity of the sponsoring party with absolute accuracy. However, the nature of the fake applications, the infrastructure of the surveillance operation, as well as the identities of those targeted, posed a strong possibility that “Domestic Kitten” was sponsored by the government of Iran, it concluded. Last July, the American cyber security firm Symantec said that it had uncovered a new cyber espionage group called “Leafminer”, which was allegedly sponsored by the Iranian state. The group had reportedly launched attacks on more than 800 agencies and organizations in in countries such as Israel, Egypt, Bahrain, Qatar, Kuwait, the United Arab Emirates, Afghanistan and Azerbaijan.

Author: Ian Allen | Date: 14 September 2018 | Permalink

Most government hackers now target cell phones, not computers, experts say

Cell Phone - IAThe majority of government-sponsored hacking now targets cell phones, not personal computers, according to researchers who say that political dissidents are especially targeted by totalitarian regimes around the world. Until 2015, most government-sponsored hacking operations were directed against the personal computers of targeted individuals. However, experts tell The Wall Street Journal that as of this year cell phones have become a far more lucrative target than personal computers in government-sponsored hacking operations. Researchers with Lookout Mobile Security, a security software company based in the United States, say that detected phone-hacking operations that are believed to be sponsored by governments have increased by a factor of 10 in the first five months of this year, compared to 2015.

According to Lookout, the increase in hacking operations targeting mobile phones reflects the proliferation of smartphone usage around the world, as well as the increase in consumption of cell phone software. Government-sponsored hackers usually compromise their targets’ cell phones through malicious software disguised as cell phone applications. The Wall Street Journal also reports that the software needed to build malicious software for cell phones has become cheaper and more readily available. Compromising a target’s cell phone provides hackers with information that is far more personal and sensitive than what can be found on a personal computer. The paper quotes Mike Murray, Lookout’s vice president of security research, who says: “It is one thing to compromise someone’s computer. It’s another thing to have a listening device that they carry around with them 24 hours a day”. Compromised phones become immensely powerful espionage tools, explains Murray.

Many of the individuals whose cell phones are targeted by governments are activists or dissidents who campaign for political or economic reforms in their countries. Their cell phones are targeted in systematic hacking campaigns by countries like Ethiopia, the United Arab Emirates, Cambodia, and Mexico, said Lookout. The Wall Street Journal cites Raj Samani, chief scientist for the antivirus firm McAfee, who claims that nearly 11 percent of cell phones worldwide were infected with some kind of malware in 2017. That statistic is likely to rise significantly by the end of 2018, says Samani.

Author: Ian Allen | Date: 08 June 2018 | Permalink

Spy collection program using fake mobile phone apps linked to Pakistani military

Cellular telephoneThe Pakistani military is suspected of having orchestrated a lucrative intelligence collection campaign using mobile phones, which targeted diplomats from India, Israel and Australia, as well as from North Atlantic Treaty Organization (NATO) member countries such as the United States and Britain. Others targeted in the operation include officials from Iraq, Iran and the United Arab Emirates. News of the alleged spy operation was published earlier this month by Lookout Mobile Security, a security software company based in the United States.

The company said that the perpetrators of the operation managed to hack into a number of diplomats’ phones by creating a number of fake applications for Android and iOS mobile phone systems. The applications, called Tangelo (for iOS) and Stealth Mango (for Android), took control of mobile phone devices once their owners downloaded them through fake third-party app stores advertising online. According to Lookout, the two apps were designed by a consortium of freelance software developers who have close links with the Pakistani military establishment. The technical report published by Lookout points to the use of IP addresses that lead to a server housed in Pakistan’s Ministry of Education in the country’s capital, Islamabad. Lookout also said that it managed to trace the identity of the person who was the main developer of the two fake mobile phone applications. He is reportedly a full-time government employee who “moonlights as a mobile app developer”. The group that built the fake apps is known for creating legitimate apps, said Lookout, but also works for hire creating surveillanceware for mobile phone systems. In the past, the same group has been found to target military and civilian government officials in India, according to Lookout.

In its technical report, the Lookout security team describes how the Pakistani hackers collected a variety of data from their victims, by having it stealthily transmitted from compromised mobile phones to servers in Islamabad. The data included photos and videos, lists of contacts, logs of phone calls and texts, as well as detailed calendar entries. German and Australian diplomats had their travel plans stolen, and a letter from the United States Central Command to Afghanistan’s assistant minister of defense for intelligence was also acquired by the hackers. The latter also gained access to the contents of an entire database of pictures of traveler passports —many of them diplomatic— from the Kandahar International Airport in southern Afghanistan. The report said it was impossible to know for certain when Tangelo and Stealth Mango were first developed and utilized. However, the most recent version of the apps was released in April of this year.

Author: Joseph Fitsanakis | Date: 22 May 2018 | Permalink

Joint US-Iraqi intelligence operation used cell phone app to trap senior ISIS figures

Abu Bakr al-BaghdadiAn joint operation conducted by American and Iraqi intelligence officers employed a popular messaging app on the phone of a captured Islamic State commander to apprehend four very senior figures in the organization, according to reports. The Reuters news agency said on Thursday that the ambitious intelligence operation began in February, when Turkish authorities captured a close aide to Abu Bakr al-Baghdadi, the Iraqi-born leader of the group known as Islamic State of Iraq and Syria (ISIS). According to Hisham al-Hashimi, security advisor to the government of Iraq, the ISIS aide was Ismail al-Eithawi, also known by his alias, Abu Zaid al-Iraqi. Iraqi officials claim that al-Eithawi was appointed by al-Baghdadi to handle the secret transfer of ISIS funds to bank accounts around the world.

It appears that al-Eithawi had managed to escape to Turkey when the United States-led coalition shattered ISIS’ self-proclaimed caliphate. But he was captured by Turkish counterterrorism forces and handed over to Iraqi authorities. Baghdad then shared the contents of al-Eithawi’s cell phone with US intelligence officers. The latter were able to help their Iraqi counterparts utilize the popular messaging app WhatsApp, a version of which was installed on al-Eithawi’s cell phone. According to al-Hashimi, the Iraqis and Americans made it seem like al-Eithawi was calling an emergency face-to-face meeting between senior ISIS commanders in the area. But when these Syria-based commanders crossed into Iraq to meet in secret, they were captured by Iraqi and American forces.

According to al-Hashimi, those captured include a Syrian and two Iraqi ISIS field commanders. More importantly, they include Saddam Jamal, a notorious ISIS fighter who rose through the ranks to become the organization’s governor of the Euphrates’ region, located on Syria’s east. Al-Hashimi told reporters on Thursday that Jamal and al-Eithawi were the most senior ISIS figures to have ever been captured alive by US-led coalition forces. The Iraqi government advisor also said that al-Eithawi’s captors were able to uncover a treasure trove of covert bank accounts belonging to ISIS, as well as several pages of secret communication codes used by the militant group.

Author: Joseph Fitsanakis | Date: 11 May 2018 | Permalink

US government publicly admits existence of rogue phone-tapping devices in DC

Embassy RowThe United States government has for the first time admitted publicly that it has detected devices known to be used by foreign intelligence services to spy on cellular communications in the nation’s capital. Known commonly as Stingrays, after a leading hardware brand, these devices are primarily used by government agencies, including law enforcement. But they can be purchased by anyone with anywhere from $1,000 to $200,000 to spare. They work by simulating the activity of legitimate cell towers and tricking cell phones into communicating with them. That allows the users of these cellphone-site simulators to monitor the physical whereabouts of targeted cell phones. Some of the more expensive Stingray models can intercept the actual content of telephone conversations and can even plant Trojans on the compromised phones of unsuspecting users.

Many governments have expressed concerns about the use of these devices, which are known to be used by intelligence agencies to monitor cellular communications on foreign soil. Major cities around the world, including Washington, are major targets of cellphone-site simulators, which are frequently located inside foreign embassies. However, the US government has never publicly commented on this issue, despite intense rumors that government agencies headquartered in Washington are major targets of Stingray devices. This changed recently, however, after Senator Ron Wyden (D-OR) wrote a letter to the Department of Homeland Security seeking information about the use of such devices in Washington. Wyden received a written response from Christopher Krebs, who heads the DHS’ National Protection and Programs Directorate. In the letter, dated March 26, Krebs confirmed that the DHS detected a number of active Stingrays in the DC area in 2017, which he referred to as “anomalous activity consistent with Stingrays”. But he added that the DHS lacks both funding and equipment needed to detect the full number of the devices and the full spectrum of Stingrays that are active in the nation’s capital.

The Associated Press, which published Krebs’ letter, said it acquired it from Wyden’s office in the US Senate. The news agency noted that the letter from DHS did not provide the technical specifications of the cellphone-site simulators, and did not enter into speculation about who might be employing them. Additionally the letter did not provide the exact number of Stingrays detected in DC in 2017, nor did it provide the exact locations in DC where Stingray activity was traced. In response to Krebs’ letter, Senator Wyden’s office released a statement blaming the US Federal Communications Commission for having failed to hold the cellular telecommunications industry accountable for the lack of security against Stingrays. “Leaving security to the phone companies has proven to be disastrous”, Senator Wyden’s statement concluded.

Author: Joseph Fitsanakis | Date: 4 April 2018 | Permalink

Lebanese spy agency used Android app to spy on thousands, say researchers

GDGS EFF LookoutThe spy agency of Lebanon used a virus designed for the Android mobile operating system to compromise the cell phones of thousands of people in at least 20 countries, according to a new mobile security report. The 50-page report was published on Thursday by a team of researchers from Lookout, a mobile security company, and the Electronic Frontier Foundation in Washington, DC. In an accompanying press release, the researchers said that the virus, which they named Dark Caracal, has been in existence for at least six years. They added that it was traced to a building in Beirut belonging to the General Directorate of General Security (GDGS), Lebanon’s primary external intelligence agency.

According to the Lookout/EFF research team, the trojanized phone application was camouflaged as a secure messaging service, resembling popular applications like Signal or WhatsApp. However, once an Android user downloaded it, it gave remote users access to the compromised phone’s cameras and microphone, thus turning it into a bugging device. The virus also stole email and text messages, pins and passwords, lists of contacts, call logs, photographs, as well as video and audio recordings stored on the compromised device. The report states that compromised devices were found in over 20 countries, including Lebanon, France, Canada, the United States and Germany. The majority of those targeted by the virus were civilian and military officials of foreign governments, defense contractors, and employees of manufacturing companies, financial institutions and utility providers.

On Thursday, Reuters contacted Major General Abbas Ibrahim, who serves as director general of GDGS. He insisted that the GDGS is known for collecting intelligence using human sources, not cyber technologies. “General Security does not have these type[s] of capabilities. We wish we had these capabilities”, General Ibrahim told the news agency.

Author: Joseph Fitsanakis | Date: 19 January 2018 | Permalink

Australian parliament reviews use of Chinese-made cell phones

ZTE CorporationThe Parliament of Australia is reportedly reviewing the use of cell phones built by a Chinese manufacturer, after an Australian news agency expressed concerns about the manufacturer’s links with the Chinese military. The cell phone in question is the popular Telstra Tough T55 handset. It is made available to Australian parliamentarians though the Information, Communications and Technology (ICT) unit of the Department of Parliamentary Services (DST). Any parliamentarian or worker in Australia’s Parliament House can order the device through the Parliament’s ICT website. According to data provided by the DST, 90 Telstra Tough T55 cell phones have been ordered through the ICT in the current financial year.

The handset is manufactured by ZTE Corporation, a leading Chinese telecommunications equipment and systems company that is headquartered in the city of Shenzhen in China’s Guangdong province. On Monday, the News Corp Australia Network, a major Australian news agency, said it had contacted the parliament with information that ZTE Corporation’s links to the Chinese military may be of concern. News Corp said it informed the DST that members of the United States Congress and the House of Representatives’ intelligence committee, have expressed serious concerns about the Chinese telecommunications manufacturer in recent years.

As intelNews reported in 2010, three American senators told the US Federal Communications Commission that the ZTE was “effectively controlled by China’s civilian and military intelligence establishment”. The senators were trying to prevent a proposed collaboration between American wireless telecommunications manufacturers and two Chinese companies, including ZTE Corporation. In 2012, the intelligence committee of the US House of Representatives investigated similar concerns. It concluded that telephone handsets manufactured by ZTE should not be used by US government employees due to the company’s strong links with the Chinese state. And in 2016, US-based security firm Kryptowire warned that some ZTE cell phone handsets contained a suspicious backdoor feature that could potentially allow their users’ private data to be shared with remote servers at regular intervals.

A DST spokesman told the News Corp Australia Network that the ZTE-manufactured cell phones had been selected for use by Australian parliamentarians based on “technical and support requirements, [DST] customers’ feedback and cost”. The spokesman added that the DST “is currently reviewing the ongoing suitability” of the T55 handsets, following reports about ZTE’s links with China’s security establishment.

Author: Ian Allen | Date: 05 September 2017 | Permalink

Israeli military says Hamas lured its soldiers using online profiles of women

Cellular telephoneThe Israel Defense Forces told a press conference on Wednesday that hackers belonging to the Palestinian militant group Hamas lured Israeli soldiers by posing as young women online. Wednesday’s press conference was led by an IDF spokesman who requested to remain anonymous, as is often the case with the Israeli military. He told reporters that the hackers used carefully crafted online profiles of real Israeli women, whose personal details and photographs were expropriated from their publicly available social media profiles. The hackers then made contact with members of the IDF and struck conversations with them that in many cases became intimate over time. At various times in the process, the hackers would send the Israeli soldiers photographs of the women, which were copied from the women’s online public profiles.

The anonymous IDF spokesman said that, if the soldiers continued to show interest, they were eventually asked by the hackers posing as women to download an application on their mobile telephones that would allow them to converse using video. Once the soldiers downloaded the application, the ‘women’ would find excuses to delay using the application, or the relationships would abruptly end. But the soldiers would leave the application on their telephones. It would then be used by the Hamas hackers to take control of the camera and microphones on the soldiers’ mobile devices. According to the IDF spokesman, dozens of Israeli soldiers were lured by the Hamas scam. No precise number was given.

Media reports suggest that the Hamas hackers were primarily interested in finding out information about IDF maneuvers around the Gaza Strip, the narrow plot of densely inhabited territory that is controlled by the Palestinian militant group. They were also interested in collecting information about the size and weaponry of the Israeli forces around Gaza. Media representatives were told on Wednesday that the operation “had potential for great damage”. But the IDF claims that the harm to its operations was “minimal”, because it primarily targeted low-ranking soldiers. Consequently, according to the Israeli military, the hackers were not able to acquire highly sensitive information.

In 2009, dozens of members of Sweden’s armed forces serving with NATO’s International Security Assistance Force in Afghanistan were found to have been approached via Facebook, and asked to provide details on NATO’s military presence in the country. The Afghan Taliban are believed to have carried out the operation.

Hamas has not commented on the allegations by the IDF.

Author: Joseph Fitsanakis | Date: 12 January 2017 | Permalink

Senior South Korean officials’ cell phones hacked by North: report

NIS South KoreaDozens of cell phones belonging to senior government officials in South Korea were compromised by North Korean hackers who systematically targeted them with texts containing malicious codes, according to reports. The National Intelligence Service (NIS), South Korea’s primary intelligence agency, said the cell phone penetrations were part of a concerted campaign by North Korea to target smart phones belonging to South Korean senior government officials. Once they managed to compromise a cell phone, the hackers were able to access the call history stored on the device, the content of text messages exchanged with other users and, in some cases, the content of telephone calls placed on the compromised device. Moreover, according to the NIS, the hackers were able to access the contact lists stored on compromised cell phones, which means that more attacks may be taking place against cell phones belonging to South Korean government officials.

The breach was considered critical enough for the NIS to host an emergency executive meeting with the security heads of 14 government ministries on Tuesday, in order to update them on the situation and to discuss ways of responding to the crisis. According to Korean media, the emergency meeting took place on Tuesday and lasted for over three hours. During the meeting the NIS told ministry representatives that the North Korean operation was launched in late February and was ongoing as of early this week. It specifically targeted government officials and appeared to concentrate on their cell phones, instead of their office phones –probably because the latter are known to be equipped with advanced anti-hacking features. The government employees’ cell phones were reportedly attacked using text messages and emails containing links to web sites that downloaded malicious codes on the users’ phones.

The NIS did not specify the precise purpose of the hacking operation, nor did it explain whether the attacks were informed by an overarching strategic goal. The officials targeted work for a variety of government ministries, but there is no clarification as to whether any operational or administrative links between them exist. The NIS did say, however, that approximately a fifth of all attacks against cell phones were successful in compromising the targeted devices.

Author: Joseph Fitsanakis | Date: 10 March 2016 | Permalink