A spyware app designed to monitor Kurdish targets attracted more than 1,400 downloads
Full article581 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The identity of the spies remains unclear, though the hacking tool is capable of collecting vast amounts of data.
More than 1,400 people have downloaded a spyware app that, while appearing to deliver news, enables hackers to collect sensitive data about the Kurds, an ethnic community living throughout Iran, Iraq and northern Syria.
The espionage campaign involves duping Android smartphone owners into downloading a program that spies use to record phone calls, extract files, take screenshots and gather other information from unwitting victims, according to details published Tuesday by the security vendor ESET.
The endeavor marks the latest attempt to undercut the Kurds, an indigenous people embedded in conflicts of the Middle East over the past generation. Kurdish fighters have been active in the fight against the Islamic State group dating back to 2014, aligning with U.S forces while also struggling against the Turkish government.
Suspected Iranian hackers also used mobile spyware to monitor Kurdish targets, the security firm Check Point reported in February.
The effort that ESET discovered has been active since March 2020, including numerous incidents in which Facebook profiles promoted malicious links, encouraging Kurd supporters to download the apps. Researchers identified six Facebook profiles that vocally promoted the URLs on the social media site, all of which have been removed.
In some cases the profiles shared the espionage with larger Facebook groups, including one page with more than 11,000 followers that was dedicated to supporting the former president of the Kurdistan region.
Investigators pinned the hacking activity on a group called BladeHawk, initially named by the QiAnXin Threat Intelligence Center, a unit of a China-based technology company.
QiAnXin researchers also published details in December 2020 describing a series of “continuous attacks” that it said were aimed at some Turkish groups, Kurdish targets and suspected members of terrorist groups. QiAnXin said the BladeHawk group originated in “a certain country in the Middle East,” though few other details were available.
Third-party websites, rather than the Google Play store or iOS market, hosted the programs, which attracted 1,481 downloads at the time of publication.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/spyware-kurds-eset-bladehawk-iran/