article thumbnail

Google TAG argues surveillance firm RCS Labs was helped by ISPs to infect mobile users

Security Affairs

Google’s Threat Analysis Group (TAG) revealed that the Italian spyware vendor RCS Labs was supported by ISPs to spy on users. This week, Lookout Threat Lab researchers uncovered enterprise-grade Android surveillance spyware, named Hermit, used by the government of Kazakhstan to track individuals within the country.

article thumbnail

Weakness at the Network Edge: Mandiant Examines 2022’s Zero-Day Exploits

eSecurity Planet

” The three activity sets included a campaign against the Philippine government between March and May 2022; a campaign against telecommunications and business service providers in South Asia in April 2022; and a campaign against organizations in Belarus and Russia in May 2022.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Syria-linked APT group SEA targets Android users with COVID19 lures

Security Affairs

The experts found 71 malicious Android applications that were connecting to the same C2 server having an IP address linked to the Syrian Telecommunications Establishment (STE). STE was used by the notorious Syria-linked APT group tracked as Syrian Electronic Army (SEA) to host its C2 infrastructure. ” continues the expert.

article thumbnail

APT trends report Q1 2021

SecureList

During routine monitoring of detections for FinFisher spyware tools, we discovered traces that point to recent FinFly Web deployments. The victims we observed were all high-profile Tunisian organizations, such as telecommunications or aviation companies.

Malware 138
article thumbnail

Spam and phishing in Q3 2021

SecureList

Third place was taken by the Noon spyware (5.19%), whose 32-bit relatives (1.71%) moved down to ninth. Global internet portals (20.68%) lead the list of organizations whose brands were most often used by cybercriminals as bait. Online stores (20.63%) are in second place by a whisker. Phishing in messengers.

article thumbnail

Spam and phishing in 2023

SecureList

Some of the scam sites discovered promised to reimburse a certain sum to the customers of a major international telecommunications company. In 2023, phishing pages mimicking global internet portals (16.46%) reclaimed the top spot by number of attempted redirects. Refunds were offered not only under the guise of government agencies.

article thumbnail

Advanced threat predictions for 2023

SecureList

From a different angle, reporting from The Intercept revealed mobile surveillance capabilities available to Iran for the purposes of domestic investigations that leverage direct access to (and cooperation of) local telecommunication companies. In the past years, we have seen vulnerability researchers increasingly focus on emailing software.

Firmware 106