Sophisticated Spyware

Forumite Members General Topics Tech Android Talk Sophisticated Spyware

Viewing 3 posts - 1 through 3 (of 3 total)
  • Author
    Posts
  • #15763
    Ed PEd P
    Participant
      @edps
      Forumite Points: 39

      Unfortunately the Grey-hats are at it again with a suite of Android spyware that turn an Android into a remote listening device and other equally intrusive actions. Although this is probably targeted at the Italian Mafia I really wonder at the wisdom of this race to the bottom that Government and Pseudo-Government organisations indulge in.

      CSO link

      #15766
      RichardRichard
      Participant
        @sawboman
        Forumite Points: 16

        There was a good write up on The Register http://www.theregister.co.uk/2018/01/16/skygofree_android_spyware/ and a link to this explanation https://securelist.com/skygofree-following-in-the-footsteps-of-hackingteam/83603/

        It appears to have made extensive use of tools created by others and put out more or less publicly and to be targetting Italian activities. The source of the nasty appears to be user carelessness in selecting the wrong website and then agreeing to install the initial form. However, as a none user of Italian resources, or WhatsApp, FaceBook for that matter I can feel more sanguine about the affair. The fact that it turns on some features based on geographic location suggests a desire not to overload its inbound servers with excess crap. To that point it appears quite well thought out. Apparently Kaspersky Lab have identified the item and tracked it back for close on 4 years. If it is targetting the Mafia I do not have any sympathy with the targets, some write ups suggested other money related or industrial targets, but I saw no details of the geofencing locations to allow possible targets to be identified.

         

        #15775
        RichardRichard
        Participant
          @sawboman
          Forumite Points: 16

          While not quite the same level of secrecy an new Mirai ‘Okiru’ botnet which targets billions of ARC-based IoT devices could well be more destructive as it appears far from narrowly targetted. Essentially, if you have an IOT thing of the target type you are at risk. The rest of us become collateral damage.

        Viewing 3 posts - 1 through 3 (of 3 total)
        • You must be logged in to reply to this topic.