Showing posts with label spying. Show all posts
Showing posts with label spying. Show all posts

Monday, 11 August 2014

Researchers Uncover Spying Tool Used by Governments to Hijack all Types of Smartphones


Purchasing malware to victimize people is illegal by laws but if the same thing any government official do, then its not!! Yes, the police forces around the World are following the footsteps of U.S. National Security Agency (NSA) and FBI.

Researchers from the Citizen Lab at the Munk School of Global Affairs at the University of Toronto and computer security firm Kaspersky Lab have unearthed a broad network of controversial spyware which is specially designed to give law enforcement agencies complete access to a suspect's phone for the purpose of surveillance.

MALWARE FOR DESKTOPS AND ALL MOBILE DEVICES
mobile hacking tool
The malware, dubbed as Remote Control System (RCS), also known as Da Vinci and Galileo, is developed by an Italian company known as Hacking Team, available for desktop computers, laptops, and mobile devices. The latest version of the malware works for all phone including Android, iOS, Windows Mobile, Symbian and BlackBerry devices, but best on Android devices, and can also be installed on jailbroken iOS devices. But even if the targeted iOS device is not jailbroken, the malware uses the famous Evasi0n jailbreaking tool to install the malware easily.

The team of researchers from both Citizen Lab and Kaspersky Lab in collaboration has presented their findings during an event in London. According to the report published, the diameter of the command infrastructure supporting Hacking Team, which sells the RCS to governments and law enforcement, is very vast with 326 command-and-control (C&C) servers running in more than 40 countries.


MALWARE DEVELOPERS - ‘HACKING TEAM’
Hacking Team is a Milan-based IT company with more than 50 employees that has made a totally different place for itself selling "offensive" intrusion and surveillance software to governments and law enforcement agencies in "several dozen countries" on "six continents."

“It was a well-known fact for quite some time that the HackingTeam products included malware for mobile phones. However, these were rarely seen,” said Kaspersky Lab experts on the blog post. “In particular, the Android and iOS Trojans have never been identified before and represented one of the remaining blank spots in the story.”

WORLD WIDE WEB OF COMMAND-N-CONTROL SERVERS
hackingteam
Kaspersky Lab researchers have used a fingerprinting method to scan the entire IPv4 space and to identify the IP addresses of RCS Command & Control servers around the world and found the biggest host in United States with 64 counts of C&C servers. Next on the list was Kazakhstan with 49, Ecuador has 35, UK which hosts 32 control systems and many other countries with a grand total of 326 Command & Control servers.
"The presence of these servers in a given country doesn't mean to say they are used by that particular country's law enforcement agencies," said Sergey Golovanov, principal security researcher at Kaspersky Lab. "However, it makes sense for the users of RCS to deploy C&Cs in locations they control – where there are minimal risks of cross-border legal issues or server seizures."
ATTACK VECTOR AND MALWARE FEATURES
RCS can be physically implanted on the victim’s device through a USB or SD card, and remotely it can be installed through spear phishing, exploit kits, drive-by downloads or network traffic injection.

Once installed on Apple iOS and Android device, the new module enable governments and law enforcement officers with larger capabilities to monitor victim devices, including the ability to:
  • control phone network
  • steal data from their device
  • record voice E-mail
  • intercept SMS and MMS messages
  • obtain call history
  • report on their location
  • use the device’s microphone in real time
  • intercept voice and SMS messages sent via applications such as Skype, WhatsApp, Viber, and much more.
"Secretly activating the microphone and taking regular camera shots provides constant surveillance of the target—which is much more powerful than traditional cloak and dagger operations," Golovanov wrote.
While, the Android module is protected by an optimizer for Android called DexGuard that made the it extremely difficult to analyze. However, most of the iOS capabilities mentioned above are also available for Android, along with the support for hijacking applications such Facebook, Google Talk, Tencent of China and many more.

The mobile modules for each are custom-built for each target, researchers said. From previous disclosures we have seen that RCS is currently being used to spy on political dissidents, journalists, human rights advocates, and opposing political figures.

End-to-End Encryption for Yahoo Mail Coming Next Year

Yahoo End to End Encryption
Today at Black Hat 2014 hacking conference, Yahoo! Chief Information Security Officer Alex Stamos announced that the company will start giving its consumers the option of end-to-end encryption in its Mail service by next year.

Google showed off a PGP-based encryption plugin for Gmail back in June. The Purple-hued company will offer encryption via a modified version of the same End-to-End browser plug-in that Google uses for PGP in Gmail, Alex Stamos told the audience at his talk titled Building Safe Systems at Scale - Lessons from Six Months at Yahoo.

The PGP plugin will be native in mobile apps allowing Gmail and Yahoo mail to easily exchange encrypted email. Infact, the email providers themselves won’t be able to decrypt messages exchanged between its users. Only senders and recipients will be able to read the messages.
In short, it means that Yahoo email users can reportedly send safe and secure messages between Yahoo users and also Gmail adherents without fear, which makes almost impossible for cyber criminals and well-resourced spying by the US government and its Five Eyes allies to read their private messages.
In a talk today, Stamos said, “If an activist in Sudan wants to email a human rights organization’s Gmail address and they have encryption set up for it, it will automatically detect that and offer them the option to encrypt.”
Stamos (@alexstamos) said that this project has been a priority since he joined one of the world's largest web providers, Yahoo six months ago. He stressed that Yahoo email encryption will be easy to use, with little or no efforts.

The announcement was tweeted by Yan Zhu, who has reportedly been hired to assist in the project. Yan Zhu formerly worked as an engineer at the Electronic Frontier Foundation (EFF), a non-profit organization that has consistently been outspoken in its call for the widespread use of encryption across the Web and the Internet, and he is apparently no friend of the NSA.

But as said earlier, use of encryption will require some amount of education for users also, to make sure their privacy expectations are set appropriately. In an interview with the Wall Street Journal, Stamos explained that PGP encryption won’t cloak the destination of your e-mail.
"We have to make it clear to people it is not [a] secret you’re emailing your priest, but the content of what you’re e-mailing him is secret," Stamos said.
The move to encrypted mail will bring Yahoo! in the list of the most secure technology companies in mail services among web giants, Google and Microsoft that protect their customers in the post-Snowden era of security.

Friday, 21 March 2014

Back off, NSA! Gmail now Encrypts every single Email

Back off, NSA! Gmail now Encrypts every single Email
2014 - The Year for Encryption! Good News for Security & Privacy seekers, Gmail is now more secure than ever before.
Google has announced that it has enhanced encryption for its Gmail email service to protect users from government cyber-spying; by removing the option to turn off HTTPS.

So from today, Gmail will always use an encrypted HTTPS connection by default when you check or send email. Furthermore, Google also assured that every single email message will now be encrypted as it moves internally between the company's data centers.
"Today's change means that no one can listen in on your messages as they go back and forth between you and Gmail’s servers—no matter if you're using public WiFi or logging in from your computer, phone or tablet." Nicolas Lidzborski, Gmail Security Engineering Lead said in a blog post.
It was previously disclosed by Edward Snowden that the National Security Agency (NSA) is intercepting email messages as they move between data centers and servers using controversial PRISM data mining program. 
Google has finally realized that it makes no sense to allow unencrypted HTTP connections. "Our commitment to the security and reliability of your email is absolute, and we’re constantly working on ways to improve." he said.
Does this mean your Gmail messages are now fully secure from government snooping? NSA is still out there!

Popular Posts