, , , , , , , , ,

Mercenary spyware hacked iPhone victims with rogue calendar invites, researchers say

Hackers using spyware made by a little known cyber mercenary company used malicious calendar invites to hack the iPhones of journalists, political opposition figures, and an NGO worker, according to two reports.

Researchers at Microsoft and the digital rights group Citizen Lab analyzed samples of malware they say was created by QuaDream, an Israeli spyware maker that has been reported to develop zero-click exploits — meaning hacking tools that don’t require the target to click on malicious links — for iPhones.

QuaDream has been able to mostly fly under the radar until recently. In 2021, Israeli newspaper Haaretz reported that QuaDream sold its wares to Saudi Arabia. The next year, Reuters reported that QuaDream sold an exploit to hack iPhones that was similar to one provided by NSO Group, and that the company doesn’t operate the spyware, its government customers do — a common practice in the surveillance tech industry.

QuaDream’s customers operated servers from several countries around the world: Bulgaria, Czech Republic, Hungary, Romania, Ghana, Israel, Mexico, Singapore, United Arab Emirates (UAE), and Uzbekistan, according to internet scans done by Citizen Lab.

Both Citizen Lab and Microsoft published groundbreaking new technical reports on QuaDream’s alleged spyware on Tuesday.

Microsoft said it found the original malware samples, and then shared them with Citizen Lab’s researchers, who were able to identify more than five victims — an NGO worker, politicians, and journalists — whose iPhones were hacked. The exploit used to hack those targets was developed for iOS 14, and at the time was unpatched and unknown to Apple, making it a so-called zero-day. The government hackers who were equipped with QuaDream’s exploit used malicious calendar invites with dates in the past to deliver the malware, according to Citizen Lab.

Those invites didn’t trigger a notification on the phone, which made them invisible to the target, Bill Marczak, a senior researcher at Citizen Lab who worked on the report, told TechCrunch.

Apple’s spokesperson Scott Radcliffe said that there’s no evidence showing the exploit discovered by Microsoft and Citizen Lab has been used after March 2021, when the company released an update.

Citizen Lab is not naming the victims since they don’t want to be identified. Marczak said that they are all in different countries, which makes it harder for the victims to come out.

“Nobody necessarily wants to be the first one in their community to come out and say, ‘yes, I was targeted,’” he said, adding that it’s usually easier if the victims are all in the same country and part of the same community or group.

Before Microsoft contacted Citizen Lab, Marczak said he and his colleagues had identified several people targeted by an exploit that was similar to the one used by NSO Group customers in 2021, known as FORCEDENTRY. At the time, Marczak and colleagues concluded that those people were targeted with a tool made by another company, not NSO Group.

The analyzed samples include the initial payload, which is designed to then download the actual malware — the second sample — if it’s on the device of the intended target. The final payload records phone calls, record audio using the phone’s microphone surreptitiously, take pictures, steal files, track the person’s granular location, and delete forensic traces of its own existence, among other functionalities, according to Citizen Lab and Microsoft.

Still, Citizen Lab researchers said the malware does leave certain traces that allowed them to track QuaDream’s spyware. The researchers said they don’t want to reveal what these traces are in order to retain their ability to track the malware. They called the traces of malware the “Ectoplasm Factor,” a name that Marzak said was inspired by a quest in the popular game Stardew Valley, which he said he plays.

Citizen Lab researchers also claimed that QuaDream uses a Cyprus-based company called InReach to sell its products.

A person who has worked in the spyware industry confirmed to TechCrunch that QuaDream used InReach “to bypass the Israeli [export] regulator.” For example, the person said, that’s how QuaDream sold to Saudi Arabia.

This workaround, however, apparently didn’t allow them to skirt regulations completely.

“[QuaDream] had four signed deals with countries in Africa (Morocco and few others) but because of the change in the regulation in Israel (limited to only 36 countries), they couldn’t deliver them,” said the person, who asked to remain anonymous to discuss sensitive industry details.

The source said that other than Saudi Arabia, QuaDream also sold to Ghana, the UAE, Uzbekistan, and Singapore, its first customer. Also, the person added, “their system is the most important system in Mexico currently,” it’s operated by the country’s president, and it was nominally sold to the local government of Mexico City, “to keep it quiet.”

The Mexican consulate in New York City did not respond to a request for comment.

According to the source, QuaDream “recently shut down their Android division and is now focusing on iOS only.”

Citizen Lab named several people who allegedly work for QuaDream or InReach. None of them, except for one, responded to a request for comment from TechCrunch. The person who responded said that he has no connection to QuaDream, and that his name was wrongly associated with the company in the past.

The discovery of QuaDream’s malware shows once again that the spyware industry — once dominated by Hacking Team and FinFisher — is not only made of NSO Group but several other companies, most of which are still flying under the radar.

“There’s a broader ecosystem of these companies and targeting individual companies is not necessarily the optimal strategy for reining in the industry,” Marczak said.

In a blog post accompanying Microsoft’s report, Amy Hogan-Burney, the company’s general manager and associate general counsel for cybersecurity policy and protection, wrote that “the explosive growth of private ‘cyber mercenary’ companies poses a threat to democracy and human rights around the world.”

“As the technology industry builds and maintains the majority of what we consider ‘cyberspace,’ we as an industry have a responsibility to limit the harm caused by cyber mercenaries,” wrote Hogan-Burney. “It is only a matter of time before the use of the tools and technologies they sell spread even further. This poses real risk to human rights online, but also to the security and stability of the broader online environment. The services they offer require cyber mercenaries to stockpile vulnerabilities and search for new ways to access networks without authorization. Their actions do not only impact the individual they target, but leave whole networks and products exposed and vulnerable to further attacks. We need to act against this threat before the situation escalates beyond what the technology industry can handle.”


Do you have more information about QuaDream? Or another surveillance tech provider? We’d love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Wickr, Telegram and Wire @lorenzofb, or email lorenzo@techcrunch.com. You can also contact TechCrunch via SecureDrop.

Mercenary spyware hacked iPhone victims with rogue calendar invites, researchers say by Lorenzo Franceschi-Bicchierai originally published on TechCrunch

https://techcrunch.com/2023/04/11/quadream-spyware-hacked-iphones-calendar-invites/


September 2024
M T W T F S S
 1
2345678
9101112131415
16171819202122
23242526272829
30  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 998: Artisanal Locally-Sourced Dopamine – Amazon Returns to Office, CA AI Bill, Elon Backs Down This Week in Tech (Audio)

Amazon Returns to Office, CA AI Bill, Elon Backs Down Discussion of the iPhone 16 Qualcomm Approached Intel About a Takeover in Recent Days Hezbollah Pagers Explode in Apparent Attack Across Lebanon Elon Musk's X Backs Down in Brazil Bluesky tops 10 million users Newsom signs California bill to limit 'addictive' social media feeds for kids The AI bill driving a wedge through Silicon Valley Microsoft Would Restart Three Mile Island Nuclear Plant to Power AI Bill requiring AM radio in new cars gets closer to law Mozilla exits the fediverse and will shutter its Mastodon server in December Amazon tells employees to return to office five days a week Host: Leo Laporte Guests: Ben Parr, Alex Lindsay, and Rob Pegoraro Download or subscribe to this show at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: NetSuite.com/TWIT canary.tools/twit – use code: TWIT expressvpn.com/twit shopify.com/twit veeam.com
  1. TWiT 998: Artisanal Locally-Sourced Dopamine – Amazon Returns to Office, CA AI Bill, Elon Backs Down
  2. TWiT 997: Put an OLED on it – iPhone Event 2024, $700 PS5, AI in AU
  3. TWiT 996: The Quiet Office Crackdown – Starlink Backtracks, AI Royalty Heist
  4. TWiT 995: The Story of Us – AnandTech Shuts Down, Brazil Bans X, Alexa Revamp
  5. TWiT 994: Time Moves On, but I Don't – Pavel Durov Arrested, Hacking Bikes, Apple Event Rumors