Researchers link mobile spyware cases with FinFisher toolkit

FinFisher, spyware which has been used to spy on dissidents in nations overseas, also can infect mobile devices, according to a new report.

Researchers at the Citizen Lab, based at the University of Toronto's Munk School of Global Affairs, published a report Wednesday analyzing mobile variants that appeared to be the work of FinSpy Mobile, a product of the FinFisher surveillance toolkit distributed by U.K-based Gamma International.

The mobile trojans have compromised several platforms, including iOS, Android, BlackBerry, Windows Mobile and Symbian, according to the report.

Eva Galperin, a coordinator at the Electronic Frontier Foundation, which collaborates with the Citizen Lab, told SCMagazine.com on Thursday that suspicions about how FinFisher was being used, termed by Gamma as “governmental IT intrusion and remote-monitoring solutions,” began last year.

“Gamma appears to be selling FinFisher and FinSpy to different countries,” Galperin said. “Citizen Lab [found] samples of what they thought were FinSpy software on Bahraini government computers [to spy on dissidents] about a month ago.”

Earlier this month, The New York Times reported that Gamma executives denied the claim that spyware running on servers in several countries was their product.

“The latest report from the Citizen Lab shows a few interesting things,” Galperin said. “They have a whole bunch of samples, some of which are for phones. Some of the samples appear to be demo copies, which are consistent with [Gamma's] claims that [their] demo copies were stolen. Some of the [samples] were legitimate copies, some running in Turkmenistan, which is one of the most repressive regimes in the world.”

FinFisher can turn on users' microphones or cameras without them knowing, take periodic screenshots and log keystrokes, she said. The FinSpy Mobile component carries a range of capabilities – including recording phone calls, tracking GPS locations, intercepting text messages and logging keystrokes.

Galperin did not disclose a specific number of mobile malware cases discovered so far, but said “many samples” have been spotted. Users can be infected only by them taking some action to install the trojan, such as clicking on a malicious email or instant message.

Research in Motion (RIM), BlackBerry's Canada-based manufacturer, responded to SCMagazine.com on Thursday via email, with advice for users on its platform.

“The spyware in question requires extensive user interaction to be installed, and we urge customers to use the controls built into their BlackBerry [devices], such as requiring a password to install applications,” said Michael Brown, vice president of BlackBerry security management and research at RIM.

Apple did not respond to a request for comment.

One tactic the mobile spyware may use to dupe victims into installing it is through messages directing users to download programs from an app store, Galperin said. Victims see no immediate signs that their devices have been infected.

In an email to SCMagazine.com Thursday, Claudio Guarnieri, a security researcher at Boston-based vulnerability management firm Rapid7, advised smartphone users to avoid jailbreaking their devices, along with keeping applications updated.

"These trojans are very silent and resilient, and it's very hard for a regular user to even spot an anomaly," said Guarnieri. "If you do suspect that your device has been compromised, you should verify the SMS and phone call logs with your operator, [as] the logs on the device are most likely tampered to not show the trojan's traffic. [Also] see if there is suspicious activity with numbers you don't recognize."

(责任编辑:)

分享到:

更多
发表评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
  • 微笑/wx
  • 撇嘴/pz
  • 抓狂/zk
  • 流汗/lh
  • 大兵/db
  • 奋斗/fd
  • 疑问/yw
  • 晕/y
  • 偷笑/wx
  • 可爱/ka
  • 傲慢/am
  • 惊恐/jk
用户名: 验证码:点击我更换图片
资料下载专区
图文资讯

英国官员:让华为参与英国5G建设风险可控

英国官员:让华为参与英国5G建设风险可控

2月21日,英国金融时报报道称,在布鲁塞尔发表的一次演讲中,英国信号情报机构政府通...[详细]

西媒:以色列打造网络安全“硅谷”

西媒:以色列打造网络安全“硅谷”

2月13日报道 西媒称,凭借每年超过10亿美元的企业投资,以色列已经成为全球网络安全领...[详细]

俄罗斯力推脱离互联网计划 确保应急状态下

俄罗斯力推脱离互联网计划 确保应急状态下网络安全

俄罗斯新闻机构 RosBiznesKonsalting(RBK)上周报道称:作为计划实验的一部分,当局正...[详细]

GSMA呼吁欧洲守住网络安全和网络基建供应竞

GSMA呼吁欧洲守住网络安全和网络基建供应竞争力

5G将改变欧洲公民的生活和工作方式。5G作为现有4G网络的补充,与之协同工作将比以往更...[详细]

涉嫌窃取近千政界人士信息 德国20岁黑客遭

涉嫌窃取近千政界人士信息 德国20岁黑客遭逮捕

涉嫌窃取德国近千政界人士信息的黑客落网 政府拟修法加强网络安全 德国当局8日宣布,...[详细]

返回首页 返回顶部