#finfisher — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #finfisher, aggregated by home.social.
-
One thing in #amer you _never_ hear about is how #GammaGroup's #FinFisher #FinSpy #Finsky is WAAAY WORSE than #NSOGroup's #Pegasus but do hear about their competition alternatives, #paragon
#RTDNA #infosec #SpyWare #StateSponsoredMalware #SSM #journalism
-
CW: #BOLO #StateSponsoredMalware used by #Transnational #CrimeSyndicateSoftware #GammaGroup #FinFisher #FinSpy #Finsky
Misconfigurations in #GammaGroup's #FinFisher #FinSpy #Finsky sold as ' targeted investigations software ' but used by these #TransnationalCartels taking advantage of misconfigured & unaudited #UnlimitedClientLicenses, led to this #CALEA software configurations blocking their detection of their hacked #LEOCredentials being used.
👀
🔬
#LEO admins have not detected this spoofing of their own credentials used by this #Transnational criminal cartel either by being paid, a quid pro quo / leverage of said people, or just incompetence teaming up with willful ignorance (a deadly combination) using ( #Meta's #FacebookForums , a #KiwiFarm clone ) for use as a coordinated low to high profile #BreakingAndEntering heists & harassment #cult using #COINTELPRO & 🤝Cartel like stalking techniques & campaigns before, during & after the pandemic, for the past 19+ years.This misconfigured client targeting investigations software is being used for illegal #MassSuveillence, unchecked & #unaudited, & is currently _not audited_ nor reviewable for #LicenseAndRegistration checking, as a perfect cover for this #Transnational #UnlimitedClientInstalls & targeting proxies which is installed from the #appleappstore & #GooglePlayStore.
#TransnationalCrimeSyndicate, a #KiwiFarmsClone site called #Meta in #infosec #CALEA #masssurveillance #investigations #infosec #kakistocracy #RTNDA #BreakingNews #news
-
CW: #infosec SecuredDNS🤝👉☣️ #YIL
opendns.com:853 👉☣️ &
doh.sse.cisco.com:853 👉☣️Is a part of the #GreyMarketCALEA
attaccc server proxy server network for #GammaGroup's #FinFisher #FinSpy #Finsky via logged attacccs' on specific honeypot clients online 🔍🧐 -
CW: #infosec #GreyMarketCALEA #attaccc proxy servers on InfoSec.Exchange
Hmm, two infrastructure IPs behind InfoSecExchange used for attaccc's today from fast.ly & bunny.net. ☣️🔍
🧐
Fast.ly ☣️⚠️👉 151.101.43.52
Bunny.Net ☣️⚠️👉 143-244-50-84.bunnyinfra.net
#GreyMarketCALEA #infosec
#investigations #StateSponsoredMalware #GammaGroup #FinFisher #FinSpy #RTDNA #news -
It's for mass surveillance, use of felons coordinating of Meta to target someone for assaults/murder/theft type targeting, physical property theft ( like WaterGate), breaking & entering coordination, targeting by gps the targeting of vehicle car wrecks, etc, as a used by felons type of non-law enforcement kind of thing in the #CALEA #CALEAGreyMarket, when used against ' the press ' or anyone else they target.
#GammaGroup #FinFisher #FinSpy #Finsky
#Meta #GangStalkers & use this software.
It's installed via #GooglePlayStore & #AppleAppStore with #MITM targeting as well as with a phone call or text message from an infected device.
#StateSponsoredMalwareCurrently there are some REALLY misconfigured #GammaGroup clients which when called will infect EVERYTHING from you phone to your computer to tablet. It's basically digital rape & slavery. Basically.
Luckily on #Android OS it's super easy to detect without software because it is so overt, not covert.
#RTDNA #infosec #StateSponsoredMalware™
#NSOGroup & #GammaGroup are the most commonly used varieties in USA.
-
Attributes of these #identitytheft rings include:
¹ #cryptowallettheft
² #breakingandentering coordination
³ #stalking
⁴ #theft#GammaGroup #FinFisher #FinSpy #Finsky #StateSponsoredMalware™ #SSM™ #CALEA #CALEAGreyMarket #RTDNA #news
-
I wonder how much #GammaGroup's #FinFisher #FinSpy #Finsky played a role in this? 🔦📰🤔
-
Sure. Depends on the OS.
I focus on Android OS 10, 11 & 12 currently #VirusTota'ing the client #FinFisher, #FinSpy & #finsky & their attaccc proxy servers also.
Android 13, 14, 15 for https://GammaGroup.Com client is on my roadmap this year & into next year though.
I've been super busy on other projects since this one is very charity work oriented in #infosec of #CALEA & #GreyMarket #CALEA software.
Occasionally I also post about #NSOGroup since they are a competitor to GammaGroup in the UK.
#StateSponsoredMalware
#WhitelistedMalware
#LawfulIntercept
#UnlawfulIntercept
#investigations -
This one node is quite the repeat offender in attacccing as a many year logged attaccc server of exploits.
Fastly DNS GammaGroup FinFisher FinSpy
Attaccc Node Proxy IP : 151.101.3.52#Fastly #DNS
#GamaGroup #FinFisher #FinSpy #AttacccProxyServersRescanned today after 2 months of not being scanned.
#infosec #CALEAMalware #GreyMarketInvestigations #RTDNA #news
-
CW: Interesting #CALEA #GreyMarket usage of #StateSponsoredMalware™ key capabilities & logged attributes
One of the key attributes of #StateSponsoredMalware™ from #GammaGroup's #FinFisher #FinSpy #Finsky is understanding that it is a shim based mish mash of resident files that point to different parts of the other background services running.
Some are replaced stock system files modified to look like and are named the same as the original but are supplemented with additional API's that call the mutiple shims that has as it's main goal of getting complete persistence on your systems if it has not done so already.
🚩🚩🚩🚩One first sign is the battery drain this software uses. It has a weird side effect of NOT logging in this battery usage like normal applications and system. 🚩🚩🚩🚩
⚠️🚨⚠️🚨⚠️🚨⚠️ 🚨⚠️🚨⚠️🚨
This BATTERY DRAIN is a HUGE
first indicator of compromise.
⚠️🚨⚠️🚨⚠️🚨⚠️🚨⚠️🚨⚠️🚨Second is checking the BACKGROUND programs running list. There are SEVERAL background programs that indicates you have been compromised by GammaGroup's software, especially on #Android , #IOS, #MacOS, #Windows, & #Linux.
There are attaccc features also which spread, from a library of PNGs with URL arrays embedded to their #malware services that launch attaccc's based on certain PSTN calls, web browsing & also MMS & SMS interactions.
For example, receiving an SMS or MMS can activate things on your computer or wireless device to do things like start a running process shim like start or restart specific services.
There is also a #MITM #ForcedMDM & #proxying ability to use your end point as an attaccc node completely behind the scenes without your intervention or knowledge unless you are logging your traffic which also could be bypassed also as has been seen previously. That is on purpose.
Continued..... #infosec #GreyMarket #CALEA #malware #investigations #RTDNA ☣️🔍🧐
-
Great #news today on three new #Google #GammaGroup #FinFisher #FinSpy #Finsky nodes to publish today #investigations wise
So they tried to update the ip proxy config and push some new shims.
Today's new servers, TWO, are setup with the EXACT SAME configurations!
☣️ #1111 shim files!!!! ☣️ 🔍🧐
Some notes 📝on these hosts of interest:
All three hosts had been scanned from about 7 months to 5 months ago. Then, one, recently added, was scanned about 10mins BEFORE I even got to it!
Fascinating!!! Someone else is ALSO
L👀king where I am also investigating! All within the window of about ~72hrs ago.So COOL I am on the same P☣️GE 🔍🧐 as someone else.
☕ *Cheers*
Details about these three hosts to follow shortly!
-
CW: #SSM™ #StateSponsoredMalware #Demo #FinFisher Plays from #GammaGroup
So after having a $1200 Samsung phone bricked by #SSM™ #StateSponsoredMalware™ from #GammaGroup's #FinFisher #FinSpy #Finsky I am writing a post analysis of some 'features' to be detailed at a later time when I have time.
Suffice to say some items available include:
¹ Disabling Digitizer
² Disabling the lower part of the
"◀️ ◼️ ⚫" so you can't minimize, go back or home key."
³ Neu use of #QuciksandModule to #BatteryDrain and change the voltage input on the charger and/or altering the 🔋 #battery power display
⁴ #Nuking & #Disabling the #Phone dialer app to make the #CallLog show nothing.
⁵ #Nuking & #Disabling the #Contacts app so you can't add any numbers
⁶ #Corrupting the #Addressbook so that all your #contacts go 💥
⁷ Intermittent Display of items
⁸ #E911Backdoor usage such that even without a #SIMCard comms & even #AirplaneMode overlay shows airplane mode but really the phone is ON the Data network.
⁹ Removal of the #simcard got temporary usage of my phone and it went back to normal use wise but then the #E911Backdoor was data enabled once they got approval.