TechCrunch News 01月31日
WhatsApp says it disrupted a hacking campaign targeting journalists with Paragon spyware
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

WhatsApp近日披露,一款名为Paragon的以色列间谍软件公司发起的黑客活动,攻击了包括记者和民间社会成员在内的约90名用户。该攻击通过WhatsApp群组发送恶意PDF文件进行,WhatsApp已发布修复程序。Citizen Lab的研究员也证实了Paragon使用此攻击方式。WhatsApp已于去年12月向Paragon发送了停止和终止函。Paragon此前一直保持低调,但这次事件首次将其与针对记者和民间社会成员的攻击联系起来。尽管如此,Paragon仍与美国移民和海关执法部门签订了合同。此次事件引发了对商业间谍软件行业滥用行为的担忧。

🚨 WhatsApp 发现并阻止了一起针对约90名用户的黑客活动,攻击者利用恶意PDF文件通过WhatsApp群组传播。

🕵️‍♂️ 该黑客活动与以色列间谍软件公司Paragon有关,该公司于去年12月被美国私募股权巨头AE Industrial收购。WhatsApp已向受影响的用户发出通知,并采取措施修复漏洞。

📝 Citizen Lab 的研究员也证实了Paragon使用此攻击方式,并正在对此进行调查。WhatsApp表示,攻击活动发生在去年12月,并已向Paragon发出停止和终止函。

💼 Paragon 虽然此前保持低调,但此次事件首次将其与针对记者和民间社会成员的攻击联系起来。该公司还曾与美国移民和海关执法部门签订合同。

🛡️ 数字权利组织 Access Now 的高级技术法律顾问指出,此次事件表明商业间谍软件行业的滥用行为并非个例,而是普遍现象。

WhatsApp said on Friday that it had disrupted a hacking campaign that targeted around 90 users, including journalists and members of civil society. 

A WhatsApp spokesperson told TechCrunch that the campaign was linked to Paragon, an Israeli spyware maker that was acquired in December of last year by American private equity giant AE Industrial.

“We’ve reached out directly to people who we believe were affected. This is the latest example of why spyware companies must be held accountable for their unlawful actions. WhatsApp will continue to protect people’s ability to communicate privately,” WhatsApp spokesperson Zade Alsawah told TechCrunch.

WhatsApp said that the hacking campaign used malicious PDFs sent via WhatsApp groups to compromise targets and said it had pushed a fix to prevent this mechanism. 

John Scott-Railton, a senior researcher who has for years investigated spyware companies and their abuses at Citizen Lab, told TechCrunch that they also have observed this hacking campaign by Paragon using this specific attack vector and that they are investigating it.

WhatsApp told TechCrunch that it believed the hacking campaign happened in December, and that it sent a cease and desist letter to Paragon. 

Do you have more information about Paragon, and this spyware campaign? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

Idan Nurick, the CEO of Paragon, did not respond to a request for comment sent via LinkedIn. AE Industrial did not respond to a request for comment.

This is the first time that Paragon has been publicly linked to a hacking campaign that allegedly targeted journalists and members of civil society. Ever since its founding in 2019, Paragon has been able to keep a low profile and avoid getting ensnared in scandals like other spyware makers such as Intellexa and NSO Group, which have both been sanctioned by the U.S. government. 

Paragon, through its U.S. subsidiary, signed a contract with the U.S. Immigration and Customs Enforcement in September, as Wired revealed last year. The New Yorker cited a Paragon source as saying the contract came after a vetting process whereby the company demonstrated its technology had controls to prevent customers abroad from targeting U.S. residents. 

At this point, it’s unclear who are targets of this spyware campaign revealed by WhatsApp. 

Natalia Krapiva, the senior tech-legal counsel at Access Now, a digital rights organization that investigates spyware abuses, celebrated the actions taken by WhatsApp.

“For some time Paragon has had the reputation of a ‘better’ spyware company not implicated in obvious abuses, but WhatsApp’s recent revelations suggest otherwise,” Krapiva told TechCrunch.“This is not just a question of some bad apples — these types of abuses are a feature of the commercial spyware industry.”

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

WhatsApp Paragon 间谍软件 黑客攻击 网络安全
相关文章