Euro area GDP growth accelerates in Q1'25    Germany's regional inflation ticks up in April    Kenya to cut budget deficit to 4.5%    Taiwan GDP surges on tech demand    Germany among EU's priciest labour markets – official data    UNFPA Egypt, Bayer sign agreement to promote reproductive health    Egypt to boost marine protection with new tech partnership    Eygpt's El-Sherbiny directs new cities to brace for adverse weather    Cabinet approves establishment of national medical tourism council to boost healthcare sector    CBE governor meets Beijing delegation to discuss economic, financial cooperation    Egypt's investment authority GAFI hosts forum with China to link business, innovation leaders    Egypt's Gypto Pharma, US Dawa Pharmaceuticals sign strategic alliance    Egypt's Foreign Minister calls new Somali counterpart, reaffirms support    "5,000 Years of Civilizational Dialogue" theme for Korea-Egypt 30th anniversary event    Egypt's Al-Mashat urges lower borrowing costs, more debt swaps at UN forum    Egypt's Al-Sisi, Angola's Lourenço discuss ties, African security in Cairo talks    Two new recycling projects launched in Egypt with EGP 1.7bn investment    Egypt pleads before ICJ over Israel's obligations in occupied Palestine    Egypt's ambassador to Palestine congratulates Al-Sheikh on new senior state role    Sudan conflict, bilateral ties dominate talks between Al-Sisi, Al-Burhan in Cairo    Cairo's Madinaty and Katameya Dunes Golf Courses set to host 2025 Pan Arab Golf Championship from May 7-10    Egypt's Ministry of Health launches trachoma elimination campaign in 7 governorates    EHA explores strategic partnership with Türkiye's Modest Group    Between Women Filmmakers' Caravan opens 5th round of Film Consultancy Programme for Arab filmmakers    Fourth Cairo Photo Week set for May, expanding across 14 Downtown locations    Egypt's PM follows up on Julius Nyerere dam project in Tanzania    Ancient military commander's tomb unearthed in Ismailia    Egypt's FM inspects Julius Nyerere Dam project in Tanzania    Egypt's FM praises ties with Tanzania    Egypt to host global celebration for Grand Egyptian Museum opening on July 3    Ancient Egyptian royal tomb unearthed in Sohag    Egypt hosts World Aquatics Open Water Swimming World Cup in Somabay for 3rd consecutive year    Egyptian Minister praises Nile Basin consultations, voices GERD concerns    49th Hassan II Trophy and 28th Lalla Meryem Cup Officially Launched in Morocco    Paris Olympic gold '24 medals hit record value    A minute of silence for Egyptian sports    Russia says it's in sync with US, China, Pakistan on Taliban    It's a bit frustrating to draw at home: Real Madrid keeper after Villarreal game    Shoukry reviews with Guterres Egypt's efforts to achieve SDGs, promote human rights    Sudan says countries must cooperate on vaccines    Johnson & Johnson: Second shot boosts antibodies and protection against COVID-19    Egypt to tax bloggers, YouTubers    Egypt's FM asserts importance of stability in Libya, holding elections as scheduled    We mustn't lose touch: Muller after Bayern win in Bundesliga    Egypt records 36 new deaths from Covid-19, highest since mid June    Egypt sells $3 bln US-dollar dominated eurobonds    Gamal Hanafy's ceramic exhibition at Gezira Arts Centre is a must go    Italian Institute Director Davide Scalmani presents activities of the Cairo Institute for ITALIANA.IT platform    







Thank you for reporting!
This image will be automatically disabled when it gets reported by several people.



Lebanese security agency turns smartphone into selfie spycam: Researchers
Published in Ahram Online on 19 - 01 - 2018

Lebanon's intelligence service may have turned the smartphones of thousands of targeted individuals into cyber-spying machines in one of the first known examples of large-scale state hacking of phones rather than computers, researchers say.
Lebanon's General Directorate of General Security (GDGS) has run more than 10 campaigns since at least 2012 aimed mainly at Android phone users in at least 21 countries, according to a report by mobile security firm Lookout and digital rights group Electronic Frontier Foundation (EFF).
The cyber attacks, which seized control of Android smartphones, allowed the hackers to turn them into victim-monitoring devices and steal any data from them undetected, the researchers said on Thursday. No evidence was found that Apple AAPL.O phone users were targeted, something that may simply reflect the popularity of Android in the Middle East.
The state-backed hackers, dubbed "Dark Caracal" by the report's authors - after a wild cat native to the Middle East - used phishing attacks and other tricks to lure victims into downloading fake versions of encrypted messaging apps, giving the attackers full control over the devices of unwitting users.
Michael Flossman, the group's lead security researcher, told Reuters that EFF and Lookout took advantage of the Lebanon cyber spying group's failure to secure their own command and control servers, creating an opening to connect them back to the GDGS.
"Looking at the servers, who had registered it when, in conjunction with being able to identify the stolen content of victims: That gave us a pretty good indication of how long they had been operating," Flossman said in a phone interview.
Dark Caracal has focused their attacks on government officials, military targets, utilities, financial institutions, manufacturing companies, and defense contractors, according to the report.
The researchers found technical evidence linking servers used to control the attacks to a GDGS office in Beirut by locating wi-fi networks and internet protocol address in or near the building. They cannot say for sure whether the evidence proves GDGS is responsible or is the work of a rogue employee.
The malware, once installed, could do things like remotely take photos with front or back camera and silently activate the phone's microphone to record conservations, researchers said.
Responding to a question from Reuters about the claims made in the report, Major General Abbas Ibrahim, director general of GDGS, said he wanted to see the report before commenting on its contents. He added: "General Security does not have these type of capabilities. We wish we had these capabilities."
Ibrahim was speaking ahead of the report's publication.
FLYING BENEATH THE RADAR
The EFF/Lookout team said they uncovered spy tools and a massive trove of hundreds of gigabytes of data stolen from the phones of thousands of victims that included text messages, contacts, encrypted conversations, documents, audio and photos.
Targets were located mainly in Lebanon and the surrounding region, including Syria and Saudi Arabia, but not Iran or Israel, two frequent targets of government cyber spy attacks. Victims also lived in five European countries, Russia, the United States, China, Vietnam and South Korea, researchers said.
The researchers notified Google GOOGL.O, the developer of the Android operating system, late in 2017. Google worked closely with the researchers to identify the apps associated with this attack, none of which were available on the Google Play Store for Android phone users, a company spokesman said.
Google Play Protect, the internet company's unified security system that runs on many Android smartphones, has been updated to protect users from these malicious apps and is in the process of removing them from any affected phones, the spokesman said.
The attackers borrowed code to create their own malicious software from developer sites, while relying heavily on social engineering to trick people to click on links that sent them to a site called SecureAndroid, a fake Android app store.
There, users were encouraged to download fake, but fully functioning versions of encrypted messaging apps and privacy tools including WhatsApp, Viber and Signal, that Flossman said promised victims secure software "better than the original".
Lookout found links between the Lebanon-linked attacks and ones tied to the Kazakh government in Central Asia in 2016 in a report called "Operation Manual" by EFF and other experts. The two research groups agreed to team up and now believe the Kazakh group was a customer of the Lebanon-based hackers.


Clic here to read the story from its source.