Turkish Twitter users targeted with mobile FinFisher spyware

Posted by   Martijn Grooten on   May 15, 2018

A new research paper by digital rights organization Access Now looks at how FinFisher has been used against people interested in anti-government protests in Turkey.

Access-Now-report-FinFisher.jpg

Through fake social media accounts, users were tricked into installing an Android application which was actually a mobile version of the FinFisher spyware.

The use of a massive campaign, as opposed to targeting very specific individuals, fits in with other recent FinFisher activity. At VB2017, ESET researcher Filip Kafka showed how the same campaign used ISPs to serve malware.

The use of larger scale attacks by government spyware is, on the one hand, a worrying sign that shows a growth in this kind of activity. On the other hand, it does make it easier for the malware campaigns to be detected, both by security tools and by the platforms, such as Twitter, that are being abused.

Filip Kafka will be back at VB2018 in Montreal to talk about that other European company selling spyware to governments: Hacking Team. The video of his VB2017 presentation on FinFisher can be seen on our YouTube channel.

Registration for VB2018 is now open. Book your ticket now to guarantee a place at one of the most international security conferences – register before 1 July to qualify for an Early Bird discount.

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

In memoriam: Prof. Ross Anderson

We were very sorry to learn of the passing of Professor Ross Anderson a few days ago.

In memoriam: Dr Alan Solomon

We were very sorry to learn of the passing of industry pioneer Dr Alan Solomon earlier this week.

New paper: Nexus Android banking botnet – compromising C&C panels and dissecting mobile AppInjects

In a new paper, researchers Aditya K Sood and Rohit Bansal provide details of a security vulnerability in the Nexus Android botnet C&C panel that was exploited in order to gather threat intelligence, and present a model of mobile AppInjects.

New paper: Collector-stealer: a Russian origin credential and information extractor

In a new paper, F5 researchers Aditya K Sood and Rohit Chaturvedi present a 360 analysis of Collector-stealer, a Russian-origin credential and information extractor.

VB2021 localhost videos available on YouTube

VB has made all VB2021 localhost presentations available on the VB YouTube channel, so you can now watch - and share - any part of the conference freely and without registration.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.