home.social

#statesponsoredmalware โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #statesponsoredmalware, aggregated by home.social.

  1. CW: #infosec ecosystems

    One thing that is great about the threat intelligence gathering community is that simple things can feed known and unknown exploits, from ONE ENDPOINT, into the greater ecosystem to engineer fixes & mitigations FOR THE WHOLE ECOSYSTEM.

    Keep this in mind when you BURN your #zerodays on me, for nothing. ๐Ÿ˜‚

    Ta! ๐Ÿคฃ

    #StateSponsoredMalware ๐Ÿ” ๐ŸŽฅ๐Ÿง#investigations

    #GammaGroup๐Ÿค#Meta๐Ÿ”๐Ÿ“๐ŸŽฅ๐Ÿง
    #RTDNA #infosec reporting ๐Ÿ“๐Ÿง

  2. CW: #uspol triage #news summary

    A quick #news triage for the last month + summary:

    ยน Removal of #Oversight at multiple US institutions checking Government Fraud & Abuse

    ยฒ Checks & Balance of Court vs. Executive Power under attack & under the microscope

    ยณ #RNC #GishGallop technique to ' spray ' the #news with B.S. , i.e. distraction to grab headlines to hide from the larger coup-in-progress dismantle government issues on the rise

    โด Usage of #StateSponsoredMalware increases

    โต Attacking of #EU & N.AMER partners

    โถ Attack on #CivilRights of #AMER continues

    Did I miss anything else?

    #uspol #RTDNA #news

  3. I wonder when more people in the #press will call out Mark's #segregationstrategy in the largest #malware software pusher on #SocialMedia & how 5/6th of the world isn't on #Meta ๐Ÿ‘€๐Ÿ‘€

    Perhaps they could ask about the use of #GammaGroup's #FinFisher #FinSpy #Finsky software used for targeting users at around a 250k run rate since 2015 & how that's a key user acquisition strategy software component wise but is never mentioned for some reason in the #press as a key component of ' non-organic growth ' but basic racketeering ( #RICO ) ยฏ\_(ใƒ„)_/ยฏ

    #infosec #KiwiFarmsClone site #Meta #FacebookGroups #StalkerForums #StateSponsoredMalware use cases

  4. CW: #infosec song quiz about #StateSponsoredMalware from #GammaGroup

    Katey Perry wrote a song about #GammaGroup's #FinFisher #FinSpy #Finsky

    Bonus points for calling out the song!

    #infosec song quiz about #StateSponsoredMalware from #GammaGroup

  5. #Meta, #Telegram & #Discord is a hub of coordination for transnational gangs coordinating #stalking, Break & Entering ( #miniWaterGate ) using #StateSponsoredMalware by #GammaGroup's #FinFisher #FinSpy #Finsky linked to #stalkerforums like #KiWiFarms clones but are organized on #Meta, specifically, for multiple decades now.

    High profile targeting of high value subjects makes the #news but their bread and butter is targeting anyone they want, especially #SiliconValley workers linked to the under #Fortune100 companies.

    #infosec #GreyMarketCALEA software

    usatoday.com/story/sports/nfl/

  6. CW: #infosec #GreyMarketCALEA #attaccc proxy servers on InfoSec.Exchange

    Hmm, two infrastructure IPs behind InfoSecExchange used for attaccc's today from fast.ly & bunny.net. โ˜ฃ๏ธ๐Ÿ”

    ๐Ÿง

    Fast.ly โ˜ฃ๏ธโš ๏ธ๐Ÿ‘‰ 151.101.43.52

    Bunny.Net โ˜ฃ๏ธโš ๏ธ๐Ÿ‘‰ 143-244-50-84.bunnyinfra.net

    #GreyMarketCALEA #infosec
    #investigations #StateSponsoredMalware #GammaGroup #FinFisher #FinSpy #RTDNA #news

    @jerry

  7. @samirx @TechCrunch

    It's for mass surveillance, use of felons coordinating of Meta to target someone for assaults/murder/theft type targeting, physical property theft ( like WaterGate), breaking & entering coordination, targeting by gps the targeting of vehicle car wrecks, etc, as a used by felons type of non-law enforcement kind of thing in the #CALEA #CALEAGreyMarket, when used against ' the press ' or anyone else they target.

    #GammaGroup #FinFisher #FinSpy #Finsky

    #Meta #GangStalkers & use this software.

    It's installed via #GooglePlayStore & #AppleAppStore with #MITM targeting as well as with a phone call or text message from an infected device.
    #StateSponsoredMalware

    Currently there are some REALLY misconfigured #GammaGroup clients which when called will infect EVERYTHING from you phone to your computer to tablet. It's basically digital rape & slavery. Basically.

    Luckily on #Android OS it's super easy to detect without software because it is so overt, not covert.

    #RTDNA #infosec #StateSponsoredMalwareโ„ข

    #NSOGroup & #GammaGroup are the most commonly used varieties in USA.

  8. BOLO for #OfficerProxy

    #OfficerProxy has been known to hide #IdentityTheftRings & #GangStalkers using #OfficerProxies access to this #CALEA #StateSponsoredMalware access to #GammaGroup's #FinFisher #FinSpy #Finsky #malware by #FacebookGroups organizing their targeted #IdentityTheft using #FakeProfiles of their targets.

    Be aware that some #OfficerProxies are getting thousands of dollars of ' kickbacks for access ' for their criminal #Facebook leverage #OrganizedCrimeRings in multiple states and cities.

    #InternalAffairs #investigations

    #infosec #Fortune1000 #CorporateEspionage #CISO #TCPDUMP #MetaUsers ๐Ÿ‘จโ€โš–๏ธ๐Ÿ‘ฉโ€โš–๏ธโš–๏ธ๐Ÿ‘ฎ

  9. Today is also a remeberence day of how #StateSponsoredMalware from #GammaGroup is used for a #masssurveillance #GreyMarketCALEA #DigitalSlaverySystem but also is being watched by other #StateSponsoredMalware that competes with #FinFisher #FinSpy #Finsky who's 100's of MILLIONS of installs of its clients in #AMER is used for #cryptowallettheft, #identitytheft , #propaganda & #GangStalking purposes by #OfficerProxys', luckily, #InternalAffairs can review who accessed what, when & where, for public reviews ๐Ÿ”๐Ÿง.

    Every Day is #infosec
    ๐Ÿ‘€
    ๐Ÿ”ฌ
    โ˜ฃ๏ธ๐Ÿ“ฒโ˜ฃ๏ธ
    ๐Ÿ‘จโ€โš–๏ธ #CALEA #TCPDUMP #watchDay ๐Ÿ‘ฉโ€โš–๏ธ

  10. #GammaGroup clients use

    ๐Ÿ”Ž UDP port 123 ๐Ÿ”

    as default #RedTeam data #exfiltration ports

    #gammagroup #finfsher #finspy #infosec #memes
    #BlueTeam
    #statesponsoredmalware โ˜ฃ๏ธ๐Ÿคณ๐Ÿโ˜ฃ๏ธ

    Update: Add logging before implementing BLOCKING the #exfil shim, obviously. โ˜ฃ๏ธ๐Ÿคณ๐Ÿ”Ž๐Ÿโ˜ฃ๏ธ๐Ÿ”๐Ÿง

  11. What iF there was an 18-24yr old group of new voters, let's say 3M of them, & #StateSponsoredMalware was used to ' force a vote a certain way '.

    That would definitely be on the ledger of investigations, for sure, right Brazil? ๐Ÿ™„๐Ÿคจ

    #uspol #SSMโ„ข #VoterIntimidation #SwingStates #Elwction2024 ๐Ÿ™„๐Ÿคจ
    #infosec #delivers_dtignite_com
    #GammaGroup #FinFisher #FinSpy #Finsky

  12. @remixtures

    The more you know about how the #GreyMarket of #CALEA #malware is whitelisted #StateSponsoredMalwareโ„ข from #GammaGroup #FinFisher #FinSpy #Finsky which is already installed on 100's of MILLIONS of devices in #AMER already.... the better.

    ๐Ÿ‘€
    ๐Ÿ”ฌ

    #infosec #SSMโ„ข โ˜ฃ๏ธโ˜ฃ๏ธ๐Ÿคณโ˜ฃ๏ธโ˜ฃ๏ธ

  13. @davidaugust

    Sure. Depends on the OS.

    I focus on Android OS 10, 11 & 12 currently #VirusTota'ing the client #FinFisher, #FinSpy & #finsky & their attaccc proxy servers also.

    Android 13, 14, 15 for GammaGroup.Com client is on my roadmap this year & into next year though.

    I've been super busy on other projects since this one is very charity work oriented in #infosec of #CALEA & #GreyMarket #CALEA software.

    Occasionally I also post about #NSOGroup since they are a competitor to GammaGroup in the UK.

    #StateSponsoredMalware
    #WhitelistedMalware
    #LawfulIntercept
    #UnlawfulIntercept
    #investigations

    #RTDNA #malware #journalism

  14. CW: Any reason why these under $300 #Motorola phones you sell have #GammaGroup's #FinFisher #FinSpy #Finsky โ˜ฃ๏ธ๐Ÿ”๐Ÿง preinstalled?

    @[email protected]
    @MOTOROLA
    @[email protected]

    Any reason why these under $300 #Motorola phones you sell have #GammaGroup's #FinFisher #FinSpy #Finsky โ˜ฃ๏ธ๐Ÿ”๐Ÿงpreinstalled?

    #infosec questions about #StateSponsoredMalware from the #UK

    @citizenlab
    @eff
    @epicprivacy

    #lawfedi #fedlaw

  15. In the future the 1975 Church Committee hearings will replay in the 2020's and the findings will prove to be even worse in public hearings especially when the domestic #AMER from #Meta's #GangStalker forum #databreach hits the front pages of the domestic / international #news with the same response as per Meta usual.

    #CALEA โ˜ฃ๏ธ๐Ÿ”๐Ÿ‘€ #Malware #audits โ˜ฃ๏ธ๐Ÿ”๐Ÿ‘€

    #RTDNA #TorturePrograms #Meta โ˜ฃ๏ธ #StateSponsoredMalware โ˜ฃ๏ธ #CALEAMalware โ˜ฃ๏ธ #GreyMarket โ˜ฃ๏ธ #investigations โ˜ฃ๏ธ ๐Ÿ”๐Ÿ‘€๐Ÿ‘€

    Don't forget the โ™ป๏ธ๐Ÿ“จ๐Ÿ“ฅ๐Ÿ“ฒ #HistoryLoops #APnews ๐Ÿ”๐Ÿ‘€๐Ÿ‘€

    #SIC ๐Ÿค #HIC ๐Ÿค โš–๏ธ ๐Ÿค ๐Ÿ‘จโ€โš–๏ธ๐Ÿค๐Ÿ‘ฉโ€โš–๏ธ๐Ÿค๐Ÿ“ฐ

  16. The #investigation into the #CoIntelPro program side program of calling someone #CI ( #CounterIntelligence ) so that they can physically #torture you is under #investigationdiscovery & how #StateSponsoredMalwareโ„ข from #GammaGroup is used to try to manage this #miniWaterGate operations, domesticly, in #AMER .

    #DomesticTerrorists at #Meta

    #Meta ๐Ÿ”๐Ÿง #DoJ โš–๏ธ๐Ÿ”Ž #CI

    โš–๏ธ๐Ÿ”Ž #CIA ๐Ÿ”๐Ÿง

    โš–๏ธ๐Ÿ”Ž #FBI ๐Ÿ”๐Ÿง

    โš–๏ธ๐Ÿ”Ž#COPSProgram ๐Ÿ”๐Ÿง

    #RTDNA #investigations #news #Meta #infosec

  17. CW: Interesting #CALEA #GreyMarket usage of #StateSponsoredMalwareโ„ข key capabilities & logged attributes

    One of the key attributes of #StateSponsoredMalwareโ„ข from #GammaGroup's #FinFisher #FinSpy #Finsky is understanding that it is a shim based mish mash of resident files that point to different parts of the other background services running.

    Some are replaced stock system files modified to look like and are named the same as the original but are supplemented with additional API's that call the mutiple shims that has as it's main goal of getting complete persistence on your systems if it has not done so already.

    ๐Ÿšฉ๐Ÿšฉ๐Ÿšฉ๐ŸšฉOne first sign is the battery drain this software uses. It has a weird side effect of NOT logging in this battery usage like normal applications and system. ๐Ÿšฉ๐Ÿšฉ๐Ÿšฉ๐Ÿšฉ

    โš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจ
    This BATTERY DRAIN is a HUGE
    first indicator of compromise.
    โš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจ

    Second is checking the BACKGROUND programs running list. There are SEVERAL background programs that indicates you have been compromised by GammaGroup's software, especially on #Android , #IOS, #MacOS, #Windows, & #Linux.

    There are attaccc features also which spread, from a library of PNGs with URL arrays embedded to their #malware services that launch attaccc's based on certain PSTN calls, web browsing & also MMS & SMS interactions.

    For example, receiving an SMS or MMS can activate things on your computer or wireless device to do things like start a running process shim like start or restart specific services.

    There is also a #MITM #ForcedMDM & #proxying ability to use your end point as an attaccc node completely behind the scenes without your intervention or knowledge unless you are logging your traffic which also could be bypassed also as has been seen previously. That is on purpose.

    Continued..... #infosec #GreyMarket #CALEA #malware #investigations #RTDNA โ˜ฃ๏ธ๐Ÿ”๐Ÿง

  18. @da_667 @campuscodi

    #StateSponsoredMalwareโ„ข #SSMโ„ข by #GammaGroup.Com does this also as their #FinFisher #FinSpy #Finsky product dubbed #TheEnemyOfTheInternet since the early 2010's as well as stream the screen in real time with the full disk access to the files, neatly force a #MITM #ForcedMDM #ForcedProxyNetwork on your device for easy fisher price type access to your compromised devices, passwords, all E2E services, online accounts, financial apps, messaging apps, SMS/MMS, iMessage, RCS, everything, from a small company that has 100's of MILLIONS of compromised devices, just on #Android alone, installed via the #GooglePlayStore & #AppleAppStore, infecting #Linux, #Windows, #MacOS, #Solaris, #IOS & more.

    Seems like these ' new features ' are just a cover for the existing installs of this #spyware iF you look at it but, could be a product, locally exploited also, as a new built-in spyware package, as it reads now, for simple #ediscoverable things later in the #Fortune1000s & mom & pop businesses to worry about, especially when $_scenarios_list.xlsx plays out. ๐Ÿ’ฏ๐Ÿคฆโ€โ™‚๏ธ๐Ÿคฆโ€โ™‚๏ธ๐Ÿคฆโ€โ™‚๏ธ๐Ÿคฆโ€โ™‚๏ธ