Spies used Android malware to try collecting intelligence from a Togolese activist, Amnesty says
Full article675 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The group behind the attack may have ties to an Indian surveillance firm.
A threat group known for using Android-based malware to target victims in Southeast Asia has been detected in Africa for the first time, according to Amnesty International research released Wednesday.
Attackers tried to trick a Togolese activist into installing Android spyware via a series of WhatsApp messages and emails. The spyware would have allowed attackers to access a wealth of information including files stored on the device, WhatsApp messages as well as access to the phone’s camera and microphone.
Spies targeted the human rights advocate, who Amnesty refused to name as a security precaution, between December 2019 and January 2020 during the lead-up to the country’s presidential election. Human rights experts and opposition leaders accused incumbent president Faure Gnassingbé of using police force to silence and brutalize protestors, disrupting election results.
Groups including Amnesty International and the United Nations have called for a moratorium on the sale of surveillance technology, including facial recognition technology until countries agree on a human rights framework and the impact of the technology is more thoroughly understood.
While the Android spyware used was custom-built, Amnesty said it found “technical evidence” that connected the campaign to infrastructure built by Innefu Labs, an Indian digital security and surveillance company that works with the Indian government and other clients. Amnesty found no evidence of direct involvement from Innefu Labs and says that multiple actors may have had access to the same custom spyware and shared infrastructure. Researchers did not provide more details about the technical evidence by press time.
Innefu Labs in a written statement to Amnesty International denied any connections with the group and said it was unaware of the use of their IP addresses for attacks. Innefu Labs did not respond to a request for comment from CyberScoop.
Researchers at CrowdStrike previously tied the group, which is most heavily active in India and Pakistan, to Appin Security Group. Appin Security Group and Innefu Labs share a co-founder.
Amnesty and other groups have in the past tied surveillance of Togolese activists to spyware from Israel-based NSO Group. The new research shows that the growth in the surveillance market is making it even easier for states and other actors to spy on activists and other perceived threats.
“Across the world, cyber-mercenaries are unscrupulously cashing in on the unlawful surveillance of human rights defenders,” said Danna Ingleton, deputy director of Amnesty Tech. “Anyone can be a target — attackers living hundreds of miles away can hack your phone or computer, watch where you go and who you talk to, and sell your private information to repressive governments and criminals.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/amnesty-international-togo-spyware/