ESET researchers have identified surveillance campaigns using a new variant of FinFisher, the infamous spyware also known as FinSpy. Seven countries have been targeted by the campaign (for security reasons, ESET will not name them). 
In two of these, it is possible that large internet service providers were involved in infecting the targets of the surveillance campaign.
“In two cases across the campaigns, the spyware has been spread via a man - in - the - middle attack and we believe that large internet providers played the role of man - in- the- middle ,” explains Filip Kafka, the ESET malware analyst who conducted the research.
FinFisher a spyware program that has been promoted as a law enforcement tool and has been used by government agencies worldwide. It is also believed to have been used by repressive regimes.
FinFisher spyware has extensive spying capabilities, including live webcam and microphone monitoring, keylogging, and file extraction. However, its most significant innovation is the way the surveillance tool infiltrates target computers.
When a targeted user is about to download one of the many popular applications, such as WhatsApp, Skype or VLC Player, they are redirected to the attacker's server to obtain a trojan software package infected with FinFisher.
"During our investigations, we found several indications that suggest that redirection is occurring at levels that concern large internet service providers," commented Filip Kafka.
According to Kafka, this is the first time that a major Internet service provider has been publicly exposed for its involvement in the spread of malware. “These FinFisher campaigns are sophisticated, complex, and covert surveillance schemes, with an unprecedented combination of methodology and scope.”
For more details, read Filip Kafka's related article on ESET's security blog, WeLiveSecurity.com.
Note:
FinFisher brings back to the forefront the debate about alleged government-sponsored malware and the security industry’s stance on these claims. For ESET, there is no such thing as good malware. Please see ESET’s response to an open letter from digital rights activist group Bits of Freedom.
