- Sophisticated spyware was used to hack the phones of 36 Al Jazeera journalists, Citizen Lab said in a new report.
- Citizen Lab said the hack, which it dubbed “Kismet,” could be traced back to software made by Israeli security company NSO Group.
- NSO Group denied any involvement.
- Citizen Lab said it believed the hack was ineffective against iPhones with the iOS 14 update, but that the scale of the hack prior to that update could be worryingly large.
- Visit Business Insider’s homepage for more stories.
Journalists at news organization Al Jazeera were targeted by an iPhone hack that sent iMessages loaded with malware, the University of Toronto’s Citizen Lab reports.
The hacking tool, dubbed “Kismet,” was a zero-click, zero-day hack, meaning Apple had no idea the exploit existed, and the malware didn’t need targets to click on anything for it to take effect.
Citizen Lab said the attack used the “Pegasus” software made by well-known Israeli security company NSO Group.
Citizen Lab said it had identified four separate entities using Pegasus in the attack. It said it could, with “medium confidence,” link one of the four to Saudi Arabia, and another to the United Arab Emirates.
In a statement to Business Insider, NSO Group denied involvement, saying Citizen Lab’s report was based on “speculation.”
“NSO provides products that enable governmental law enforcement agencies to tackle serious organized crime and counterterrorism only, and as stated in the past we do not operate them,” a spokesperson for NSO Group said.
“However, when we receive credible evidence of misuse with enough information which can enable us to assess such credibility, we take all necessary steps in accordance with our investigation procedure in order to review the allegations,” they added.
This isn’t the first time NSO Group’s Pegasus software has been linked with hacking journalists’ phones.
In June of this year, Amnesty International said Pegasus had been used by the Moroccan government to hack a Moroccan journalist’s phone. NSO Group did not confirm nor deny the claims, and promised to investigate.
In October last year, Facebook filed a lawsuit against the company claiming its software was used to perpetrate a large-scale hack of WhatsApp users, including journalists and human rights activists. NSO is fighting the lawsuit.
Citizen Lab said it believed the hack was ineffective against iPhones with the iOS 14 update, but that the scale of the hack prior to that update rolling out could be worryingly large.
“Given the global reach of NSO Group’s customer base and the apparent vulnerability of almost all iPhone devices prior to the iOS 14 update, we suspect that the infections that we observed were a minuscule fraction of the total attacks leveraging this exploit,” Citizen Lab said in its report.
While Citizen Lab first detected Kismet in July 2020, it said device logs suggest the hack was being used as far back as October 2019.
An Apple spokesperson told Business Insider that iOS 14, which was launched in September of this year, was more robust.
“At Apple, our teams work tirelessly to strengthen the security of our users’ data and devices. iOS 14 is a major leap forward in security and delivered new protections against these kinds of attacks. The attack described in the research was highly targeted by nation states against specific individuals. We always urge customers to download the latest version of the software to protect themselves and their data,” the spokesperson said.
View original article here Source
Fire HD 8 Plus tablet, HD display, 32 GB, our best 8" tablet for portable entertainment, Slate
$79.99 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)Roku Streaming Stick+ | HD/4K/HDR Streaming Device with Long-range Wireless and Voice Remote with TV Controls
$46.89 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)All-new Blink Outdoor – wireless, weather-resistant HD security camera with two-year battery life and motion detection – 1 camera kit
$89.99 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)SUPERDANNY USB Surge Protector Power Strip Mountable Extension Cord Multiple Protection 5 Outlet 3 USB Port with Hook & Loop Fastener for iPhone iPad PC Home Office Travel Black
$13.59 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)TCL 32" 3-Series 720p Roku Smart TV - 32S335
$128.00 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)Blink Mini – Compact indoor plug-in smart security camera, 1080 HD video, night vision, motion detection, two-way audio, Works with Alexa – 1 camera
$34.99 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)Fujifilm Instax Mini Instant Film Twin Pack (White)
$13.38 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)Wyze Cam Pan 1080p Pan/Tilt/Zoom Wi-Fi Indoor Smart Home Camera with Night Vision, 2-Way Audio, Works with Alexa & the Google Assistant, White - WYZECP1
$37.95 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)Fire 7 tablet (7" display, 16 GB) - Black
$39.99 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)Kindle Paperwhite – Now Waterproof with more than 2x the Storage – Ad-Supported + Kindle Unlimited (with auto-renewal)
$129.99 (as of January 18, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)Amazon Auto Links: Could not resolve the given unit type, . Please be sure to update the auto-insert definition if you have deleted the unit.