A/HRC/41/35/Add.3 7. FinFisher sells tools similar to NSO Group’s Pegasus. FinFisher is a private surveillance company based in Munich, Germany, and was previously part of the UK-based Gamma Group. FinFisher’s command and control servers (computers that attackers use to send commands to target systems compromised by malware) have been identified in 25 countries, including the United States. (Citizen Lab, 10-11) One of the most well-known FinFisher products is FinSpy, a tool that has been used by governments to intercept and monitor the activities of human rights activists, journalists, and opposition leaders. (Id., 9 10) 8. Hacking Team is an Italian private surveillance company backed by “private investment” which manufactures “offensive technology” technology and “lawful interception ” tools to law enforcement agencies around the world and has been identified in at least 21 countries. (Citizen Lab, 10; Sarah McKune, 5). Hacking Team is also linked to a new company called Grey Heron, which markets itself as a technology company that provides “lawful access” to the most popular encrypted services (Access Now, 9). One of the most well-known Hacking Team products is the company’s Remote Control System (RCS). RCS can intercept and transmit data from a target’s infected phone or computer before the data is transmitted or encrypted. Additionally, RCS can turn on a device’s webcam and microphone as well as record emails, instant messages, information typed into a Web browser, and record video calls (Citizen Lab, 10). The Ethiopian government has reportedly used RCS to target Ethiopian American journalists and activists. (Id.). Cyberbit has also been found to target researchers and Ethiopian academics and activists. 9. Cyberbit is an Israeli cybersecurity company owned by Elbit Systems. It sells the PC Surveillance System (recently renamed PC 360), which can “monitor and extract information including VoIP, calls, files, emails, audio recordings, key logs and virtually any information available on the target device.” (Citizen Lab, 9) Its products has been linked to spyware attacks on dozens of activists, researchers and journalists. (Id.; Committee to Protect Journalists (CPJ), 3) 10. M.L.M. Protection Ltd. is an Israeli surveillance firm that sells “long-range interception technology” which allows customers to record a wide range of content, including text messages and communications sent through popular messaging services such as WhatsApp. (Derechos Digitales, 2). The former President of Panama, Ricardo Martinelli reportedly purchased approximately 13.5 million dollars in private surveillance technologies from M.L.M. Protection Ltd. and NSO Group between 2009 and 2014, and is currently facing criminal charges for spying on approximately 150 individuals “including journalists, businessmen, civil society leaders and members of the opposition.” (AI Sur, 9). Social Engineering 11. The main report discusses how the effectiveness of malware attacks is enhanced through the use of social engineering techniques. The malware attack on Omar Abduaziz Alzahrani, a Saudi human rights activist living in Canada, is a paradigmatic example of how social engineering techniques have advanced. On the day that he made an online Amazon purchase, Mr. Alzahrani received a text message with the domain link Sundaydeals[dot]com disguised as a shipment notification. On closer examination, however, Citizen Lab identified the exploit domain as part of Pegasus’s spyware suite (HRF, 4). Human rights defenders, journalists, and political activists in Azerbaijan have also been targeted through e-mails impersonating their colleagues (Amnesty International, 17). Rasul Jafarov, a prominent lawyer and human rights defender, was told by friends and colleagues that they received an email about political prisoners from an e-mail address similar to Jafarov’s and that included an attachment infected with malware. If clicked, the attachment would have installed a keylogger recording the user’s keystrokes and malware that would send screenshots of targets’ computers back to the attacker. The target would not necessarily be aware of the infection because after the attachment was clicked, “the malware also opened an Office document in Azeri dealing with political prisoners.” (Amnesty International, 16). 12. Elaborate social engineering campaigns have also been designed to lure targets to click on malicious links on websites and social media. (Access Now, 6). In Turkey, during the March for Justice in July 2017, FinFisher attackers impersonated the social media 4

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents