HomeInvestigationsDISCLOSURE: Italian company behind cyber espionage software!

DISCLOSURE: Italian company behind cyber espionage software!

RCS_MAP

Malicious software used by governments around the world to surveil citizens without their knowledge has been uncovered by researchers from the University of Toronto's Citizen Lab in collaboration with the well-known security company Kaspersky . The analysis by the Citizen Lab researchers reveals that the software used to violate human rights regarding the privacy of communications affects Android phones as well as iPhones, as well as computers with almost any operating system!

The software

The cyberespionage software is a creation of the Italian company HackingTeam and is released as a product for government clients under the name Remote Control System (RCS) or Da Vinci or Galileo.

Its latest version seems to be available for computers with any operating system and mobile phones. According to its creators and as revealed by Citizen Lab, the software can be installed remotely on Android, iOS, Windows Mobile, Symbian and Blackberry. Even if the iPhone is not jailbroken , the software has the ability to use the well-known Evasi0n exploit and install the Malware with particular ease.

mobile-hacking-map

The researchers presented the results of their research at an international conference in London. According to the study, the HackingTeam company's monitoring network includes 326 control points (Command and Control Centers) covering over 40 countries (including even Cyprus)! No control point or installation of the monitoring software was found in Greece, according to the study.

HackingTeam is based in Milan, Italy and has 50 employees. The company has completely changed the way offensive tools and surveillance software are sold, making their sale extremely easy and accessible in almost all countries and on 6 continents. According to information from researchers, “suspicious governments” that use the software against their citizens, as well as possible installation points of the software, are shown in the graph below:

software

 

[quote]The company's activity had been known for some time, specifically that they sold products for monitoring Android and iPhone mobile phones. However, the Trojans they used were the "gap" in the whole story, since they had never been detected and analyzed as happened this time, Kaspersky executives note.[/quote]

The 326 control server points

hackingteam-controlservers
The cyberespionage software is a creation of the Italian company HackingTeam and is released as a product for government clients under the name Remote Control System (RCS) or Da Vinci or Galileo.

Using network artifact analysis methodology combined with IP address scanning, the analysts were able to accurately identify the IP addresses of the RCS or government cyberespionage software control points. The country with the most control points of the software was identified as the United States of America with 64 control points (Command and Control), followed by Kazakhstan (hosting 49 control points), Ecuador (with 35 control points) and the United Kingdom with 32 control systems. A total of 326 Command and Control servers were identified and captured where the malware sent the information it collected from unsuspecting users.

[box_alert]The presence of servers in a given country does not necessarily mean that the country in question is using HackingTeam's malware against its citizens, said Kaspersky's principal researcher Sergei Golovanov. What it does suggest is perhaps the ease with which malware users have used the legal framework in the above countries to install surveillance software checkpoints, exploiting legal loopholes in the country's legislation.[/box_alert]

Ways of using and capabilities of cyber espionage software

RCS can be installed on the target either by physical access via USB/CD or remotely using phishing attacks, exploit kits or water-holing type attacks. Additionally, in cooperation with Internet Service Providers (ISPs), it can be installed via Injection or redirection in the target user's network traffic.

After installing the software, government officials have the ability to:

  • Remotely control the device/computer
  • To steal data
  • To locate the exact location
  • To steal email passwords
  • To steal files
  • Place files without the user's knowledge
  • Monitor incoming/outgoing SMS&MMS
  • Access call history
  • Use the device's microphone and camera in real time
  • Detect messages or voice through Skype, WhatsApp and Viber applications

The software appears to be particularly widespread for installation on Android mobile targets as we can see in the relevant graph for installations that have taken place within 7 days (up to June 4, 2014):

Affection_Android
Software Distribution on Android Mobiles

The architecture of the attack model used by HackingTeam's RCS  is shown in the graphic below. It is worth noting the Anonymizing network they use to hide the identities of government officials using the cyberespionage software.

 

Architecture-RCS
Software Attack Network Architecture

 

To create the Agent through Factory, software engineers can create custom-made versions of RCS for Linux, MacOS, Windows, Android & iPhone, Blackberry and Windows Phone operating systems. There are many installation options: via local WiFi, via a pre-built legal application package, using an exploit, installing from a USB/SD card as well as USB/U3, using a CD, using a QR Code, using a Java Applet via a created website and finally with a WAP Message on mobile phones (except iOS). 

Ways-Of-Infection
Creating a Cyber ​​Espionage Software Agent

 

If you think that using an Antivirus will protect you, then you are kidding yourself. The company offers its customers a list of checks it performs with all modern Antiviruses, which clearly shows which ones detect the software's digital signatures!

Non-Detection by Antivirus
Non-Detection by Antivirus

The architecture clearly allows the use of continuous anonymous Proxy servers (Anonymous & Proxy Chain Architecture) to completely hide the original trace of government officials

Carrying out cover-up of government officials
Carrying out cover-up of government officials

The software is enriched with file extraction capabilities, file placement if desired, and even Skype conversation interception capabilities!

Extract files from target
Extract files from target

 

Skype Chat Eavesdropping
Skype Chat Eavesdropping
Running and monitoring applications without the user's knowledge.
Running and monitoring applications without the user's knowledge.

Additionally, the latest version has added the ability to visualize information. The software can “build” the profile of the monitored user by performing a connection analysis according to the data it draws from the subject of monitoring, in order to provide the government official with the monitored person’s contacts in an understandable and graphical way (combining address books, emails, etc.).

people-investigation
Follower survey

 

The Android version is highly protected and cannot be easily analyzed. Researchers have found that RCS has been used in various ways in the past to monitor political opponents, dissidents, journalists, human rights defenders, and political figures!

The questions that arise regarding the use of this software are many. Mainly regarding the invasive capabilities provided by the RCS software (giving the ability to extract and also place data at the will of the one who controls it)!. Take it for granted that those monitoring unsuspecting citizens with this software are ethical, act legally and strictly supervised by prosecutorial authorities and do not use the software for their own benefit.

[quote]However, practice has shown that this is not the case and many times these tools are used above the law, for political purposes or against dissidents. Furthermore, no one ensures that this software is sold exclusively to governments and not to individuals who can allocate the amounts requested by the company (which are not particularly high) to then use the software to carry out cyber espionage against competitors or even government agencies![/quote]

The full study of the RCS cyberespionage software is available [here]

[box_alert]The ways in which the software infiltrates are specific (mentioned above), so if someone believes for any reason that they are a target, it is worth being particularly careful about the messages we receive/open and the websites we visit! We do not uncritically accept an e-mail admonition to visit a website or open an attached message!

In addition, businesses and key people within them (CEOs, CFOs, Legal Advisors, CIOs, Internal Audit Services) who have access to sensitive information should be particularly careful and take all recommended measures to ensure the use of software like RCS against cases of industrial cyber espionage and data theft! The best protection is information and awareness against the ever-increasing risks! [/box_alert]

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS