Commerce Department blacklists spyware companies Cytrox and Intellexa
Full article795 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The actions are the first major initiative on spyware since Biden issued an executive order restricting on government use of surveillance software.
The U.S. Commerce Department on Tuesday added to its trade blacklist the spyware purveyors Cytrox and Intellexa that have been linked to operations spying on journalists, politicians and a Meta executive in Greece.
The stated reason for the blacklist inclusion is “for trafficking in cyber exploits used to gain access to information systems, thereby threatening the privacy and security of individuals and organizations worldwide.”
The full list of entities included are Intellexa S.A. based out of Greece, Cytrox Holdings Zrt. out of Hungary, Intellexa Limited out of Ireland and Cytrox AD out of North Macedonia.
Intellexa is known for its Android spyware Predator that has been described by researchers as one of the most ubiquitous spyware tools after NSO Group’s Pegasus. Cytrox has also previously been banned by Meta for surveillance operations on the platform.
The enforcement actions are the first major initiative on commercial spyware since President Biden issued in March an executive order that places restrictions on the U.S. government’s use of spyware. The order does not, however, completely ban the use of spyware by the U.S. government.
The designations for Cytrox and Intellexa follow the inclusion of Israeli spyware companies NSO Group and Candiru on the Commerce Department’s entity list of companies that pose a national security and foreign policy risk to the U.S. in November 2021.
A senior administration official called the designations “an opportunity for private investors to consider the risk of, and reevaluate, their role in investing in and supporting such commercial spyware companies whose business practices threaten the security and safety of technology used by citizens around the world, not just here in the United States.”
Biden’s March executive order deems a spyware company a security risk if it has been used against a U.S. person without the consent of the U.S. government, has been used in human rights abuses, or is used by governments with a history of systematic political repression.
The Biden administration alongside 10 other countries in March released a statement committing to guardrails against abuse of spyware.
The Biden administration has been outspoken about potential American investment in spyware-for-hire firms, most recently commenting on the potential takeover of NSO Group by a Hollywood financier by telling The Guardian that such a takeover would “not automatically remove the designated entity from the entity list” and may prompt a security review.
This story is developing.
More Scoops
Someone infected a spyware probe overseer with spyware
Citizen Lab says the phone of a member of Europe’s PEGA Committee was infected twice with Pegasus, the NSO Group spyware that gave the panel its name.
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
One House Democrat is pressing Commerce on the government’s spyware use
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/commerce-department-blacklists-spyware-companies/