News: 1689723729

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

US adds Euro spyware makers to export naughty list

(2023/07/19)


The US government on Tuesday added commercial spyware makers Intellexa and Cytrox to its Entity List, saying the duo are a possible threat to national security.

According to the Feds, Greece's Intellexa SA, Ireland's Intellexa Limited, North Macedonia's Cytrox AD, and Hungary's Cytrox Holdings are allied companies that developed and sold software that could be used by clients to infect and monitor other people's electronic devices and equipment. This "is acting contrary to the national security or foreign policy interests of the United States," as the US Dept of Commerce put it

[1]PDF

.

Adding Intellexa and Cytrox to the Entity List places export restrictions on the software vendors as part of the Biden administration's [2]ongoing crackdown against commercial surveillance technology. It is now impossible for US organizations to do business legally with those placed on the list without [3]special permission from Uncle Sam; the list effectively cuts off Intellexa et al from America.

[4]

The move also follows warnings from cybersecurity researchers about abuses committed using the firms' snooping products.

Alliances

Google's Threat Analysis Group (TAG), Cisco Talos, and Canadian nonprofit Citizen Lab have published reports on Cytrox's [5]Predator and Alien spyware , which we're told have been used by the biz's customers to target politicians, journalists and activists.

Like similar snoopware package [6]Pegasus , whose maker NSO Group was [7]added to the federal Entity List in 2021, Predator and Alien have been documented exploiting zero-day flaws and other vulnerabilities to infect and take over Android phones and Apple iOS devices to spy on users and extracting data.

[8]

[9]

According to Citizen Lab, Cytrox is part of Intellexa, which formed the "Star Alliance of spyware" in 2019 to compete against NSO. Although, as the nonprofit noted in a [10]2021 report , "the specific link between Cytrox and Intellexa, as well as other companies in the 'alliance,' remains murky at best."

Last year, Google TAG said [11]Cytrox sold zero-day exploits to government-backed snoops who used them to deploy Predator in at least three campaigns in 2021. The TAG team believes the buyers of these exploits are in Egypt, Armenia, Greece, Madagascar, Côte d'Ivoire, Serbia, Spain, Indonesia, and possibly other countries.

[12]

"We assess with high confidence that these exploits were packaged by a single commercial surveillance company, Cytrox, and sold to different government-backed actors who used them in at least the three campaigns," Google security researchers Clement Lecigne and Christian Resell [13]said .

And in March, Meta's former security policy manager, who split her time between the US and Greece, sued the Hellenic national intelligence service for compromising her phone and [14]deploying Predator spyware. The case is as yet unresolved.

[15]US govt pushes spyware to other countries? Senator Wyden would like a word

[16]President Biden kind of mostly bans commercial spyware from US govt

[17]Alien versus Predator? No, this Android spyware works together

[18]Pegasus-pusher NSO gets new owner keen on the commercial spyware biz

"This rule reaffirms the protection of human rights worldwide as a fundamental US. foreign policy interest," Deputy Secretary of Commerce Don Graves said in a [19]statement today. "The Entity List remains a powerful tool in our arsenal to prevent bad actors around the world from using American technology to reach their nefarious goals."

Google, Citizen Lab, and other digital privacy advocates have [20]called on Congress to weigh in on spyware, asking for sanctions and increased enforcement against surveillanceware makers.

The Commerce Department updated its list a few months after US President Joe Biden issued an executive order to (somewhat) [21]prohibit the US government from using commercial spyware.

[22]

Meanwhile, the Feds continue to [23]promote the sale of American-approved commercial spyware to foreign governments at the expense of US taxpayers. ®

Get our [24]Tech Resources



[1] https://public-inspection.federalregister.gov/2023-15343.pdf

[2] https://www.theregister.com/2023/03/28/biden_spyware_executive_order/

[3] https://www.bis.doc.gov/index.php/policy-guidance/lists-of-parties-of-concern/entity-list

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZLdf50lE8pEjAHplsiCYUgAAA4w&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.theregister.com/2023/05/27/predator_analysis_talos/

[6] https://www.theregister.com/2023/01/09/supreme_court_pegasus_spyware/

[7] https://www.theregister.com/2021/10/20/us_intrusion_software_rules/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLdf50lE8pEjAHplsiCYUgAAA4w&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLdf50lE8pEjAHplsiCYUgAAA4w&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/

[11] https://www.theregister.com/2022/05/24/predator_spyware_zero_days/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLdf50lE8pEjAHplsiCYUgAAA4w&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://blog.google/threat-analysis-group/protecting-android-users-from-0-day-attacks/

[14] https://www.theregister.com/2023/03/21/meta_employee_spyware/

[15] https://www.theregister.com/2023/05/26/wyden_ita_spyware_policy/

[16] https://www.theregister.com/2023/03/28/biden_spyware_executive_order/

[17] https://www.theregister.com/2023/05/27/predator_analysis_talos/

[18] https://www.theregister.com/2023/05/30/nso_owner_hacking/

[19] https://www.bis.doc.gov/index.php/documents/about-bis/newsroom/press-releases/3297-2023-07-18-bis-press-package-spyware-document/file

[20] https://www.theregister.com/2022/07/27/us_congress_spyware_debate/

[21] https://www.theregister.com/2023/03/28/biden_spyware_executive_order/

[22] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLdf50lE8pEjAHplsiCYUgAAA4w&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[23] https://www.theregister.com/2023/05/26/wyden_ita_spyware_policy/

[24] https://whitepapers.theregister.com/



Who's fault is it?

Anonymous Coward

Pegasus, Predator, Alien et. al. use weaknesses in supposedly secure systems, advertised as being impenetrable

Why is no-one looking at the device marketers?

Re: Who's fault is it?

Dinanziame

Claims of a device or system being secure should be considered the same as a house or building being called secure. You can work to make things more secure, but ultimately it's impossible for anything to be 100% secure, for a device to be hack-proof or for a house to be burglar-proof. And if you insist on making things even more secure, they eventually become unusable due to the restrictions you need to place on them.

Death wish, n.:
The only wish that always comes true, whether or not one wishes it to.