Bahraini activists targeted with new iOS zero
Full article851 words · extracted from therecord.media · click to collapse
A new Citizen Lab investigation published today has revealed the existence of a new iOS zero-click exploit that has been abused since at least February this year to hack into the iPhones of several Bahraini activists and political dissidents. Citizen Lab, a political, human rights, and cybersecurity research center at the University of Toronto, said it linked the new iOS exploit to NSO Group, a well-known Israeli company specializing in the sale of offensive hacking and surveillance technologies. Named FORCEDENTRY, the exploit was one of many offensive tools that were used to infect the devices with Pegasus, a surveillance tool developed by NSO Group. Citizen Lab said FORCEDENTRY had been used in a broader hacking campaign that began in July 2021 and targeted the devices of at least nine Bahraini activists. "At least four of the activists were hacked by LULU, a Pegasus operator that we attribute with high confidence to the government of Bahrain, a well-known abuser of spyware," Citizen Lab said in a report published today. This campaign didn't center around the use of FORCEDENTRY, but went through three different stages, researchers said, and FORCEDENTRY appears to have been developed earlier this year as a way to bypass new security features that Apple introduced in iOS 14. The stages are below: At the time of writing, technical details about the iMessage vulnerability exploited by the FORCEDENTRY tool are not available—primarily because the vulnerability is still unpatched. However, Citizen Lab revealed some details in its report: Citizen Lab researchers said they've seen the FORCEDENTRY exploit deployed against iOS versions 14.4 and 14.6, and the exploit is believed to work against current iOS versions as well. In addition, there's an indication that the new exploit was also used against other targets besides Bahraini activists. Citizen Lab researchers said the technical details of the FORCEDENTRY exploit are the same with the technical details of Megalodon, an iOS zero-click exploit detailed in a July 2021 Amnesty International report. Amnesty researchers said they found this exploit while investigating the iPhones of a French human rights lawyer and an Indian journalist. Both Amnesty and Citizen Lab said they reported their findings to Apple's security team, who said they started an investigation. The findings of this report paint NSO Group in a negative light once again, as a company that has no qualms in selling surveillance technology to oppressive governments that abuse it to spy on critics, journalists, and political rivals, instead of fighting crime and terrorism. NSO Group has stated in the past that it would investigate cases where its tools have been abused to violate human rights, and, answering to a Forbes inquiry about Citizen Lab's new report today, the company decried that they haven't been contacted to investigate the new findings before the report was published. Since FORCEDENTRY is currently a carefully guarded exploit in the arsenal of a surveillance vendor and deployed in very limited and targeted operations, the danger to most iOS users is low until Apple learns more and releases an official fix. However, the danger is high for individuals who have their own government and NSO Group in their threat model.Target Description Date(s) of Hacking Moosa Abd-Ali * Activist (Sometime before September 2020) Yusuf Al-Jamri Blogger (Sometime before September 2019) Activist A Member of Waad September 16, 2020 Activist B * Member of Waad, Labor Law Researcher June 3, 2020 July 12, 2020 July 19, 2020 July 24, 2020 August 6, 2020 September 15, 2020 Activist C Member of Waad September 14, 2020 Activist D * Member of BCHR September 14, 2020 Activist E Member of BCHR February 10, 2021 Activist F * Member of BCHR July 11, 2020 July 15, 2020 July 22, 2020 October 13, 2020 Activist G * Member of Al Wefaq (Sometime before October 2019) FORCEDENTRY can bypass BlastDoor
FORCEDENTRY exploit used against French and Indian targets
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/bahraini-activists-targeted-with-new-ios-zero-click-exploit