pastebin - collaborative debugging tool
kpaste.net RSS


Digital Spying, The Commercialization of - 117 Pages .PDF
Posted by Anonymous on Wed 1st May 2013 22:20
raw | new post

  1. For Their Eyes Only: The Commercialization of Digital Spying
  2.  
  3. https://citizenlab.org/2013/04/for-their-eyes-only-2/
  4.  
  5. April 30, 2013
  6.  
  7. by: Morgan Marquis-Boire,  Bill Marczak, Claudio Guarnieri & John Scott-Railton
  8.  
  9. Citizen Lab is pleased to announce the release of “For Their Eyes Only: The Commercialization of Digital Spying.”
  10.  
  11. 117 Pages .PDF:
  12. https://citizenlab.org/storage/finfisher/final/fortheireyesonly.pdf
  13.  
  14. View safely online at: http://view.samurajdata.se/
  15.  
  16. ####
  17.  
  18. "The report features new findings, as well as consolidating a year of our research on the commercial market for offensive computer network intrusion capabilities developed by Western companies.
  19.  
  20. Our new findings include:
  21.  
  22.     We have identified FinFisher Command & Control servers in 11 new Countries. Hungary, Turkey, Romania, Panama, Lithuania, Macedonia, South Africa, Pakistan, Nigeria, Bulgaria, Austria.
  23.  
  24.     Taken together with our previous research, we can now assert that FinFisher Command & Control servers are currently active, or have been present, in 36 countries.
  25.  
  26.     We have also identified a FinSpy sample that appears to be specifically targeting Malay language speakers, masquerading as a document discussing Malaysia’s upcoming 2013 General Elections.
  27.  
  28.     We identify instances where FinSpy makes use of Mozilla’s Trademark and Code. The latest Malay-language sample masquerades as Mozilla Firefox in both file properties and in manifest. This behavior is similar to samples discussed in some of our previous reports, including a demo copy of the product, and samples targeting Bahraini activists.
  29.  
  30. Our previous research uncovered evidence that FinFisher (commercial network intrusion malware) developed by UK-based company Gamma International was targeting activists in Bahrain. It analyzed mobile variants of the FinFisher suite.  It also exposed the use of commercial surveillance malware developed by Italy-based company Hacking Team to target a dissident in the United Arab Emirates.  Most recently, we documented the global proliferation of FinFisher command and control servers.
  31.  
  32. This research is one of the first extended projects to attempt to map out the operation and prevalence of commercial surveillance software.  Our work opens a window into this space, but it remains crucial that the nature and impact of the commercial surveillance market be better understood. Technical research in this field has only just begun, but it is already clear that the stakes are high. We hope this report will contribute to discussions on this issue in technical, civil society, and policy making communities.
  33.  
  34. This research represents the joint work of Morgan Marquis-Boire, Bill Marczak, Claudio Guarnieri, and John Scott-Railton."
  35.  
  36. ####
  37.  
  38. https://citizenlab.org/2012/07/from-bahrain-with-love-finfishers-spy-kit-exposed/
  39. https://citizenlab.org/2012/08/the-smartphone-who-loved-me-finfisher-goes-mobile/
  40. https://citizenlab.org/2012/10/backdoors-are-forever-hacking-team-and-the-targeting-of-dissent/
  41. https://citizenlab.org/2013/03/you-only-click-twice-finfishers-global-proliferation-2/
  42.  
  43. ####
  44.  
  45. FinFisher’s Global Proliferation: Updated Map:
  46. https://citizenlab.org/wp-content/uploads/2013/04/TheirEyesMap-web.jpg

Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.

Syntax highlighting:

To highlight particular lines, prefix each line with {%HIGHLIGHT}





All content is user-submitted.
The administrators of this site (kpaste.net) are not responsible for their content.
Abuse reports should be emailed to us at