home.social

#cytrox — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cytrox, aggregated by home.social.

fetched live
  1. #Cybersecurity #Egypt #Spyware #Predator #Cytrox: "- Between May and September 2023, former Egyptian MP Ahmed Eltantawy was targeted with Cytrox’s Predator spyware via links sent on SMS and WhatsApp. The targeting took place after Eltantawy publicly stated his plans to run for President in the 2024 Egyptian elections.

    - In August and September 2023, Eltantawy’s Vodafone Egypt mobile connection was persistently selected for targeting via network injection; when Eltantawy visited certain websites not using HTTPS, a device installed at the border of Vodafone Egypt’s network automatically redirected him to a malicious website to infect his phone with Cytrox’s Predator spyware.

    - During our investigation, we worked with Google’s Threat Analysis Group (TAG) to obtain an iPhone zero-day exploit chain (CVE-2023-41991, CVE-2023-41992, CVE-2023-41993) designed to install Predator on iOS versions through 16.6.1. We also obtained the first stage of the spyware, which has notable similarities to a sample of Cytrox’s Predator spyware we obtained in 2021. We attribute the spyware to Cytrox’s Predator spyware with high confidence.

    - Given that Egypt is a known customer of Cytrox’s Predator spyware, and the spyware was delivered via network injection from a device located physically inside Egypt, we attribute the network injection attack to the Egyptian government with high confidence.

    - Eltantawy’s phone was additionally infected with Cytrox’s Predator spyware two years prior, in November 2021, via a text message containing a link to a Predator website."

    citizenlab.ca/2023/09/predator

  2. #Cybersecurity #Egypt #Spyware #Predator #Cytrox: "- Between May and September 2023, former Egyptian MP Ahmed Eltantawy was targeted with Cytrox’s Predator spyware via links sent on SMS and WhatsApp. The targeting took place after Eltantawy publicly stated his plans to run for President in the 2024 Egyptian elections.

    - In August and September 2023, Eltantawy’s Vodafone Egypt mobile connection was persistently selected for targeting via network injection; when Eltantawy visited certain websites not using HTTPS, a device installed at the border of Vodafone Egypt’s network automatically redirected him to a malicious website to infect his phone with Cytrox’s Predator spyware.

    - During our investigation, we worked with Google’s Threat Analysis Group (TAG) to obtain an iPhone zero-day exploit chain (CVE-2023-41991, CVE-2023-41992, CVE-2023-41993) designed to install Predator on iOS versions through 16.6.1. We also obtained the first stage of the spyware, which has notable similarities to a sample of Cytrox’s Predator spyware we obtained in 2021. We attribute the spyware to Cytrox’s Predator spyware with high confidence.

    - Given that Egypt is a known customer of Cytrox’s Predator spyware, and the spyware was delivered via network injection from a device located physically inside Egypt, we attribute the network injection attack to the Egyptian government with high confidence.

    - Eltantawy’s phone was additionally infected with Cytrox’s Predator spyware two years prior, in November 2021, via a text message containing a link to a Predator website."

    citizenlab.ca/2023/09/predator

  3. #Cybersecurity #Egypt #Spyware #Predator #Cytrox: "- Between May and September 2023, former Egyptian MP Ahmed Eltantawy was targeted with Cytrox’s Predator spyware via links sent on SMS and WhatsApp. The targeting took place after Eltantawy publicly stated his plans to run for President in the 2024 Egyptian elections.

    - In August and September 2023, Eltantawy’s Vodafone Egypt mobile connection was persistently selected for targeting via network injection; when Eltantawy visited certain websites not using HTTPS, a device installed at the border of Vodafone Egypt’s network automatically redirected him to a malicious website to infect his phone with Cytrox’s Predator spyware.

    - During our investigation, we worked with Google’s Threat Analysis Group (TAG) to obtain an iPhone zero-day exploit chain (CVE-2023-41991, CVE-2023-41992, CVE-2023-41993) designed to install Predator on iOS versions through 16.6.1. We also obtained the first stage of the spyware, which has notable similarities to a sample of Cytrox’s Predator spyware we obtained in 2021. We attribute the spyware to Cytrox’s Predator spyware with high confidence.

    - Given that Egypt is a known customer of Cytrox’s Predator spyware, and the spyware was delivered via network injection from a device located physically inside Egypt, we attribute the network injection attack to the Egyptian government with high confidence.

    - Eltantawy’s phone was additionally infected with Cytrox’s Predator spyware two years prior, in November 2021, via a text message containing a link to a Predator website."

    citizenlab.ca/2023/09/predator

  4. #Cybersecurity #Egypt #Spyware #Predator #Cytrox: "- Between May and September 2023, former Egyptian MP Ahmed Eltantawy was targeted with Cytrox’s Predator spyware via links sent on SMS and WhatsApp. The targeting took place after Eltantawy publicly stated his plans to run for President in the 2024 Egyptian elections.

    - In August and September 2023, Eltantawy’s Vodafone Egypt mobile connection was persistently selected for targeting via network injection; when Eltantawy visited certain websites not using HTTPS, a device installed at the border of Vodafone Egypt’s network automatically redirected him to a malicious website to infect his phone with Cytrox’s Predator spyware.

    - During our investigation, we worked with Google’s Threat Analysis Group (TAG) to obtain an iPhone zero-day exploit chain (CVE-2023-41991, CVE-2023-41992, CVE-2023-41993) designed to install Predator on iOS versions through 16.6.1. We also obtained the first stage of the spyware, which has notable similarities to a sample of Cytrox’s Predator spyware we obtained in 2021. We attribute the spyware to Cytrox’s Predator spyware with high confidence.

    - Given that Egypt is a known customer of Cytrox’s Predator spyware, and the spyware was delivered via network injection from a device located physically inside Egypt, we attribute the network injection attack to the Egyptian government with high confidence.

    - Eltantawy’s phone was additionally infected with Cytrox’s Predator spyware two years prior, in November 2021, via a text message containing a link to a Predator website."

    citizenlab.ca/2023/09/predator

  5. #Cybersecurity #Egypt #Spyware #Predator #Cytrox: "- Between May and September 2023, former Egyptian MP Ahmed Eltantawy was targeted with Cytrox’s Predator spyware via links sent on SMS and WhatsApp. The targeting took place after Eltantawy publicly stated his plans to run for President in the 2024 Egyptian elections.

    - In August and September 2023, Eltantawy’s Vodafone Egypt mobile connection was persistently selected for targeting via network injection; when Eltantawy visited certain websites not using HTTPS, a device installed at the border of Vodafone Egypt’s network automatically redirected him to a malicious website to infect his phone with Cytrox’s Predator spyware.

    - During our investigation, we worked with Google’s Threat Analysis Group (TAG) to obtain an iPhone zero-day exploit chain (CVE-2023-41991, CVE-2023-41992, CVE-2023-41993) designed to install Predator on iOS versions through 16.6.1. We also obtained the first stage of the spyware, which has notable similarities to a sample of Cytrox’s Predator spyware we obtained in 2021. We attribute the spyware to Cytrox’s Predator spyware with high confidence.

    - Given that Egypt is a known customer of Cytrox’s Predator spyware, and the spyware was delivered via network injection from a device located physically inside Egypt, we attribute the network injection attack to the Egyptian government with high confidence.

    - Eltantawy’s phone was additionally infected with Cytrox’s Predator spyware two years prior, in November 2021, via a text message containing a link to a Predator website."

    citizenlab.ca/2023/09/predator

  6. US government adds two more #spyware makers to denylist
    The U.S. government put #Intellexa and #Cytrox, two European spyware makers, on an economic denylist. The addition of the two companies, based in Greece and Hungary, as well as two related entities in Ireland and North Macedonia, is part of a wider effort from the Biden administration against makers of malware that is sold exclusively to #lawenforcement and intelligence agencies.
    techcrunch.com/2023/07/18/us-g #surveillance #privacy #NSOGroup

  7. US government adds two more #spyware makers to denylist
    The U.S. government put #Intellexa and #Cytrox, two European spyware makers, on an economic denylist. The addition of the two companies, based in Greece and Hungary, as well as two related entities in Ireland and North Macedonia, is part of a wider effort from the Biden administration against makers of malware that is sold exclusively to #lawenforcement and intelligence agencies.
    techcrunch.com/2023/07/18/us-g #surveillance #privacy #NSOGroup

  8. US government adds two more makers to denylist
    The U.S. government put and , two European spyware makers, on an economic denylist. The addition of the two companies, based in Greece and Hungary, as well as two related entities in Ireland and North Macedonia, is part of a wider effort from the Biden administration against makers of malware that is sold exclusively to and intelligence agencies.
    techcrunch.com/2023/07/18/us-g

  9. US government adds two more #spyware makers to denylist
    The U.S. government put #Intellexa and #Cytrox, two European spyware makers, on an economic denylist. The addition of the two companies, based in Greece and Hungary, as well as two related entities in Ireland and North Macedonia, is part of a wider effort from the Biden administration against makers of malware that is sold exclusively to #lawenforcement and intelligence agencies.
    techcrunch.com/2023/07/18/us-g #surveillance #privacy #NSOGroup

  10. US government adds two more #spyware makers to denylist
    The U.S. government put #Intellexa and #Cytrox, two European spyware makers, on an economic denylist. The addition of the two companies, based in Greece and Hungary, as well as two related entities in Ireland and North Macedonia, is part of a wider effort from the Biden administration against makers of malware that is sold exclusively to #lawenforcement and intelligence agencies.
    techcrunch.com/2023/07/18/us-g #surveillance #privacy #NSOGroup

  11. BREAKING: US adds 2 European mercenary spyware firms to export control list.

    #Cytrox & #Intellexa = *notorious* proliferators of #Predator spyware,

    Linked to abuses around globe, Greek #spywaregate, hacking of Americans...🧵1/

    Rule: public-inspection.federalregis

  12. BREAKING: US adds 2 European mercenary spyware firms to export control list.

    #Cytrox & #Intellexa = *notorious* proliferators of #Predator spyware,

    Linked to abuses around globe, Greek #spywaregate, hacking of Americans...🧵1/

    Rule: public-inspection.federalregis

  13. BREAKING: US adds 2 European mercenary spyware firms to export control list.

    #Cytrox & #Intellexa = *notorious* proliferators of #Predator spyware,

    Linked to abuses around globe, Greek #spywaregate, hacking of Americans...🧵1/

    Rule: public-inspection.federalregis

  14. BREAKING: US adds 2 European mercenary spyware firms to export control list.

    #Cytrox & #Intellexa = *notorious* proliferators of #Predator spyware,

    Linked to abuses around globe, Greek #spywaregate, hacking of Americans...🧵1/

    Rule: public-inspection.federalregis

  15. BREAKING: US adds 2 European mercenary spyware firms to export control list.

    #Cytrox & #Intellexa = *notorious* proliferators of #Predator spyware,

    Linked to abuses around globe, Greek #spywaregate, hacking of Americans...🧵1/

    Rule: public-inspection.federalregis

  16. The other one was that Intellexa, a spyware vendor operating from Greece and Cyprus, was tracked down delivering surveillance and spyware equipment from the EU to Sudan. The recipient, a militia led by Sudan's richest man, who was once a leader in the genocidal paramilitary group Janjaweed.

    lighthousereports.nl/investiga

    The only good part of this story was that it unraveled because one of the Intellexa engineers posted a selfie from the plane.

    lighthousereports.nl/investiga

    BTW, earlier this year @citizenlab showed that Intellexa was the company behind spyware that was used against a Greek journalist, most likely by the Greek government.

    #journalism #spyware #EuropeanUnion #Europe #Sudan #Dafur #Janjaweed #Intellexa #Cytrox

  17. Πρόσφατη έρευνα επιβεβαιώνει 378 domains που φιλοξενούν το #Predator τα οποία οδηγούν σε 4 μοναδικά IP. Τα 2 από αυτά εδράζουν στη Β.Μακεδονία, έδρα της #Cytrox . Από τους 4 servers μόνο ο 99.83.154.118 είναι σε "μαύρη λίστα".
    circleid.com/posts/20220712-pr

  18. Πρόσφατη έρευνα επιβεβαιώνει 378 domains που φιλοξενούν το #Predator τα οποία οδηγούν σε 4 μοναδικά IP. Τα 2 από αυτά εδράζουν στη Β.Μακεδονία, έδρα της #Cytrox . Από τους 4 servers μόνο ο 99.83.154.118 είναι σε "μαύρη λίστα".
    circleid.com/posts/20220712-pr

  19. CW: Ich nutze meine Tröte und Twitter,daher bin ich nicht immer an meiner Tröte oder Twitter

    RT @[email protected]

    Griechenland: Wie der #Geheimdienst Journalisten überwachte. Auf dem Telefon eines Journalisten wurde der #Staatstrojaner #Predator von #Cytrox gefunden. Wer ist dafür verantwortlich? dw.com/de/h%C3%B6rt-griechenla

    🐦🔗: twitter.com/chaosupdates/statu

  20. #Google's Threat Analysis Group (TAG) lookout for threats & #vulnerabilities across devices & #software that can be exploited by #cybercriminals.

    #TAG in its latest blog post has highlighted a spyware dubbed as #Predator, which was installed by state-backed attackers in three separate campaigns by exploiting 5 #0days.

    Google (TAG) has claimed that Predator is relatively new #spyware, created by the #surveillance company #Cytrox, which is based in #Skopje, North Macedonia 🇲🇰.

  21. RT @[email protected]

    ❗Το @[email protected] ανάρτησε την είδηση για τη νέα έκθεση της @[email protected], σύμφωνα με την οποία φορείς που «υποστηρίζονται από κυβέρνηση» & «εντοπίζονται στην 🇬🇷» αγόρασαν λογισμικό υποκλοπών από την εταιρεία παρακολουθήσεων #Cytrox.

    ❌ Ωστόσο, το δημοσίευμα γρήγορα αποσύρθηκε.

    🐦🔗: twitter.com/reporters_gr/statu