TechCrunch News 2024年12月04日
Business leaders among Pegasus spyware victims, says security firm
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

安全公司iVerify发现,多名iPhone用户,包括一家大型公司的领导者,成为Pegasus间谍软件的攻击目标。虽然记者、人权维护者和政治官员经常成为国家监控的目标,但商业领袖的手机被间谍软件入侵的案例相对较少。此次事件再次警示,政府以防止严重犯罪和恐怖主义为由使用的间谍软件,也可能被用于商业间谍活动。iVerify首席执行官Rocky Cole表示,他们发现7部iPhone存在被入侵的迹象,其中一些运行的是iOS 16.6的较新版本,且攻击者可能利用旧漏洞进行攻击。此外,安全研究人员发现,政府支持的黑客正在重复利用间谍软件漏洞,包括来自中国、伊朗和俄罗斯的黑客,甚至可能与Salt Typhoon黑客组织有关,该组织与美国和国际电信巨头的入侵事件有关。

🤔 **商业领袖成间谍软件攻击目标:**iVerify发现多名iPhone用户,包括一家大型公司领导者,成为Pegasus间谍软件的攻击目标,这表明间谍软件的应用范围正在扩大,不仅针对政治人物和记者,也开始瞄准商业领域。

⚠️ **间谍软件被用于商业间谍活动:**该事件再次提醒人们,政府以防止犯罪和恐怖主义为由使用的间谍软件,也可能被滥用于商业间谍活动,获取商业机密和敏感信息。

📱 **iOS 16.6版本也存在安全风险:**iVerify在7部iPhone上发现了被入侵的迹象,其中一些运行的是iOS 16.6的较新版本,这表明即使是最新版本的iOS系统也可能存在安全漏洞,攻击者可能利用旧漏洞进行攻击。

🌍 **政府支持的黑客重复利用间谍软件漏洞:**安全研究人员发现,政府支持的黑客,包括来自中国、伊朗和俄罗斯的黑客,正在重复利用间谍软件漏洞,这使得间谍软件的控制和滥用变得更加困难。

🇨🇳 **Salt Typhoon黑客组织可能参与其中:**iVerify正在调查Salt Typhoon黑客组织是否利用其对电信网络的访问权限,识别并针对个人使用手机间谍软件。该组织与美国和国际电信巨头的入侵事件有关,FBI正在调查其是否利用网络访问权限针对美国高级官员的手机安装恶意软件。

Security firm iVerify said a leader of a big company was among several individuals whose iPhones were recently targeted with the Pegasus spyware. 

While journalists, human rights defenders, lawmakers and political officials are frequent targets of state surveillance, reports of spyware compromising the phones of business leaders are rare, but not unheard of. The findings come as a fresh warning that spyware typically used by governments under the guise of preventing serious crime and terrorism can also be misused for commercial espionage.

In a call with TechCrunch this week, iVerify chief executive Rocky Cole declined to name who was targeted, but said that the spyware targeted a business “that you’ve heard about.” Cole, a former analyst at the National Security Agency, said the business leader, who iVerify is in contact with, was “completely surprised” by the attempt to compromise their phone.

NSO Group, which develops the Pegasus spyware, did not comment by press time on Wednesday.

iVerify, which offers an eponymous app that can scan iPhones and iPads for signs of malware, said it detected evidence of compromise on seven iPhones, some of which were running newer versions of iOS 16.6 in late 2023 at the time of detection. The security firm said the seven devices were identified out of a pool of 2,500 iVerify users who opted to scan their devices for possible traces of spyware in recent months. Cole said the number of newly identified infections was not representative of the general population, given that its app users are more likely to be at higher risk of state-backed targeting.

The company’s app is designed to look for potentially anomalous signals deep inside the iPhone and iPad operating systems that can be caused by the side effects of malware infections. Since Apple tightly controls the software on iPhones and iPads to make it difficult for apps like iVerify to examine the security of other installed apps, or the kernel of the underlying software, the security firm analyzes other telemetry data within those privacy constraints — such as on-device diagnostic logs — to help determine if the device might be compromised.

It is not known if the targeted iPhones were compromised at the time iVerify identified the anomalous signals. Cole said any detected signals could indicate a historical spyware compromise at an earlier point in time. Some of the targeted phones may not have been patched with the latest software update when they were compromised, which may have left the devices exposed to older exploits.

Though iVerify is not the only way to detect if a phone is compromised by spyware, Cole said his company’s app allows the detection of spyware “at scale.”

Confirmed spyware attacks against business leaders are seldom made public. The phone of Amazon founder Jeff Bezos was hacked several years ago, which a United Nations report concluded was likely the result of Saudi officials purchasing access to Pegasus and using WhatsApp to deliver the spyware. NSO Group claimed at the time that its spyware “was not used in this instance.”

Security researchers say the proliferation of spyware is making its use — and misuse — harder to contain. Earlier this year, Google sounded the alarm after its security researchers found evidence that Russian government-backed hackers acquired exploits that were “identical or strikingly similar” to code developed by NSO Group, which said it had never sold its spyware to Russia.

Cole told TechCrunch that iVerify is also seeing the reuse of spyware exploits by government-backed hackers from countries like China, Iran, and Russia, as “becoming more widespread.” Cole said the company was investigating whether Salt Typhoon, a China-backed hacking group linked to ongoing intrusions at several U.S. and international phone and internet giants, may have used its access to the telecom networks to identify and target individuals with phone spyware.

iVerify recently identified an uptick in anomalous signals from two phones belonging to senior officials at the Harris-Walz presidential campaign, Cole told TechCrunch, at a time when Salt Typhoon was “really active” in the phone companies’ networks. 

The company said it wasn’t yet clear if those devices were fully compromised, as its investigation is “ongoing.” The FBI is reportedly examining whether the China-backed hackers used their access to phone networks to target the phones of senior American officials with malware. 

Cole said if Salt Typhoon is linked to the targeting of these phones, the attempted intrusions “very well could be the reuse of commercial capabilities.”

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Pegasus 间谍软件 iPhone 网络安全 商业间谍
相关文章