A/HRC/41/35/Add.3
7.
FinFisher sells tools similar to NSO Group’s Pegasus. FinFisher is a private
surveillance company based in Munich, Germany, and was previously part of the UK-based
Gamma Group. FinFisher’s command and control servers (computers that attackers use to
send commands to target systems compromised by malware) have been identified in 25
countries, including the United States. (Citizen Lab, 10-11) One of the most well-known
FinFisher products is FinSpy, a tool that has been used by governments to intercept and
monitor the activities of human rights activists, journalists, and opposition leaders. (Id., 9 10)
8.
Hacking Team is an Italian private surveillance company backed by “private
investment” which manufactures “offensive technology” technology and “lawful
interception ” tools to law enforcement agencies around the world and has been identified
in at least 21 countries. (Citizen Lab, 10; Sarah McKune, 5). Hacking Team is also linked
to a new company called Grey Heron, which markets itself as a technology company that
provides “lawful access” to the most popular encrypted services (Access Now, 9). One of
the most well-known Hacking Team products is the company’s Remote Control System
(RCS). RCS can intercept and transmit data from a target’s infected phone or computer
before the data is transmitted or encrypted. Additionally, RCS can turn on a device’s
webcam and microphone as well as record emails, instant messages, information typed into
a Web browser, and record video calls (Citizen Lab, 10). The Ethiopian government has
reportedly used RCS to target Ethiopian American journalists and activists. (Id.). Cyberbit
has also been found to target researchers and Ethiopian academics and activists.
9.
Cyberbit is an Israeli cybersecurity company owned by Elbit Systems. It sells the PC
Surveillance System (recently renamed PC 360), which can “monitor and extract
information including VoIP, calls, files, emails, audio recordings, key logs and virtually any
information available on the target device.” (Citizen Lab, 9) Its products has been linked to
spyware attacks on dozens of activists, researchers and journalists. (Id.; Committee to
Protect Journalists (CPJ), 3)
10.
M.L.M. Protection Ltd. is an Israeli surveillance firm that sells “long-range
interception technology” which allows customers to record a wide range of content,
including text messages and communications sent through popular messaging services such
as WhatsApp. (Derechos Digitales, 2). The former President of Panama, Ricardo Martinelli
reportedly purchased approximately 13.5 million dollars in private surveillance
technologies from M.L.M. Protection Ltd. and NSO Group between 2009 and 2014, and is
currently facing criminal charges for spying on approximately 150 individuals “including
journalists, businessmen, civil society leaders and members of the opposition.” (AI Sur, 9).
Social Engineering
11.
The main report discusses how the effectiveness of malware attacks is enhanced
through the use of social engineering techniques. The malware attack on Omar Abduaziz
Alzahrani, a Saudi human rights activist living in Canada, is a paradigmatic example of
how social engineering techniques have advanced. On the day that he made an online
Amazon purchase, Mr. Alzahrani received a text message with the domain link Sundaydeals[dot]com disguised as a shipment notification. On closer examination, however,
Citizen Lab identified the exploit domain as part of Pegasus’s spyware suite (HRF, 4).
Human rights defenders, journalists, and political activists in Azerbaijan have also been
targeted through e-mails impersonating their colleagues (Amnesty International, 17). Rasul
Jafarov, a prominent lawyer and human rights defender, was told by friends and colleagues
that they received an email about political prisoners from an e-mail address similar to
Jafarov’s and that included an attachment infected with malware. If clicked, the attachment
would have installed a keylogger recording the user’s keystrokes and malware that would
send screenshots of targets’ computers back to the attacker. The target would not
necessarily be aware of the infection because after the attachment was clicked, “the
malware also opened an Office document in Azeri dealing with political prisoners.”
(Amnesty International, 16).
12.
Elaborate social engineering campaigns have also been designed to lure targets to
click on malicious links on websites and social media. (Access Now, 6). In Turkey, during
the March for Justice in July 2017, FinFisher attackers impersonated the social media
4
Select target paragraph3
Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents