Budapest Post

Cum Deo pro Patria et Libertate
Budapest, Europe and world news

Israeli firm’s spyware linked to attacks on websites in UK and Middle East

Israeli firm’s spyware linked to attacks on websites in UK and Middle East

Canada-based researchers say new evidence suggests Candiru’s software used to target critics of autocratic regimes
Researchers have found new evidence that suggests spyware made by an Israeli company that was recently blacklisted in the US has been used to target critics of Saudi Arabia and other autocratic regimes, including some readers of a London-based news website.

A report by Montreal-based researchers from Slovakian company Eset, an internet security firm, found links between attacks against high-profile websites in the Middle East and UK, and the Israeli company Candiru, which has been called Israel’s “most mysterious cyberwarfare company”.

Candiru and NSO Group, a much more prominent Israeli surveillance company, were both added to a US blacklist this month after the Biden administration took the rare step of accusing the firms of acting against US national security interests.

The Eset report revealed new information about so-called “watering hole attacks”. In such attacks, spyware users launch malware against ordinary websites that are known to attract readers or users who are considered “targets of interest” by the user of the malware.

The sophisticated attacks allow the malware user to identify characteristics about the individuals who have visited the website, including what kind of browser and operating system they are using. In some cases the malware user can then launch an exploit that allows them to take over an individual target’s computer.

Unlike NSO Group’s signature spyware, which is called Pegasus and infects mobile phones, Candiru’s malware is believed by researchers to infect computers. The company appears to be named after a parasitic freshwater catfish that can be found in the Amazon.

The researchers found that the websites that were “known targets” of this kind of attack included Middle East Eye, a London-based news website, and multiple websites associated with government ministries in Iran and Yemen.

Candiru did not respond to the Guardian’s request for comment.

Middle East Eye condemned the attacks. In a statement, its editor-in-chief, David Hearst, said the outlet was no stranger to attempts to take the website down by state and non-state actors.

“Substantial sums of money have been spent trying to take us out. This has not stopped us reporting what is going on in all corners of the region and I am confident that they will not stop us in future,” he said.

Once websites are compromised, researchers at Eset say, they are considered “jumping off sites” that help malware users target individuals. In other words, not every individual who visited one of the compromised websites would have been in danger of being hacked, but users of the malware are believed to have used the websites as a starting point to help identify a much smaller group of individuals who were then targeted.

Matthieu Faou, who uncovered the campaigns, said Eset developed a custom in-house system in 2018 to uncover “watering holes” on high-profile websites. In July 2020, the system notified them that an Iranian embassy website in Abu Dhabi had been tainted with malicious code.

“Our curiosity was aroused by the high-profile nature of the targeted website, and in the following weeks we noticed that other websites with connections to the Middle East were also targeted,” Faou said.

The “threat group” then “went quiet” until it resurfaced in January 2021 and was active until late summer in 2021, when all the websites that were observed to have been victims of attacks were then “cleaned”, Eset said.

Eset said it believed hacking activities ended in late July 2021 after a report by researchers at Citizen Lab, released in conjunction with Microsoft, detailed Candiru’s alleged surveillance activities. That report accused Candiru of selling spyware to governments linked to fake Black Lives Matter and Amnesty International websites that were used to hack targets.

In the July 2021 report, Citizen Lab, a research group affiliated with the University of Toronto, said the Tel Aviv-based Candiru made “untraceable” spyware that could infect computers and phones.

At the time, Candiru declined to comment.

Microsoft said in July that it appeared that Candiru sold the spyware that enabled the hacks, and that the governments generally chose who to target and ran the operations themselves. The company also announced at the time that it had disabled the “cyberweapons” of Candiru and built protections against the malware, including issuing a Windows software update.

There is little public information available about Candiru, which was founded in 2014 and has undergone several name changes. In 2017 the company was selling its malware to clients in the Gulf, western Europe and Asia, according to a lawsuit reported in an Israeli newspaper. Candiru may have deals with Uzbekistan, Saudi Arabia and the UAE, Forbes has reported.

Microsoft reported that it had found victims of the spyware in Israel and Iran. Citizen Lab said it was able to identify a computer that had been hacked by Candiru’s malware, and then used that hard drive to extract a copy of the firm’s Windows spyware. The owner of the computer was a “politically active” individual in western Europe, it said.

This month Candiru made headlines after the Biden administration announced it had added the company to the commerce department’s entity list, a blacklist usually reserved for America’s worst enemies, including Chinese and Russian hackers.

In its press release, the commerce department said it had evidence that Candiru developed and supplied spyware to foreign governments that used it to maliciously target government officials, journalists, businesspeople, activists, academics and embassy workers. The tools also helped to enable foreign governments to conduct “transnational repression”, the department said.

Candiru has not commented on its placement on the entity list.
AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

0:00
0:00
Close
United Nations Calls for Global Action Against Disinformation and Hate Speech Online
Tucker Carlson warns of an inevitable clash in Western societies over mass migration
OpenAI CEO Sam Altman praises the rapid progress of Chinese tech companies.
Poland's President Karol Nawrocki ENDS support for Ukrainian citizens:
Italy's PM Giorgia Meloni highlights record employment and economic growth
Chancellor Friedrich Merz Re-elected as CDU Leader, Opposes AfD Influence
Trump Directs Government to Release UFO and Alien Information
Trump Signs Global 10% Tariffs on Imports
UK Government Considers Law to Remove Prince Andrew from Royal Line of Succession
Two teens arrested in France for alleged terror plot.
US Supreme Court Voids Trump’s Emergency Tariff Plan, Reshaping Trade Power and Fiscal Risk
Greek Prime Minister Kyriakos Mitsotakis advocates for a ban on minors using social media.
Meanwhile in Time Square, NYC One of the most famous landmarks
Jensen Huang just told the story of how Elon Musk became NVIDIA’s very first customer for their powerful AI supercomputer
Former British Prince Andrew Arrested on Suspicion of Misconduct in Public Office
Former President Yoon Suk Yeol Sentenced to Life in Prison for Abuse of Authority
Unitree Robotics founder Wang Xingxing showcases future robot deployment during Spring Festival Gala.
German Chancellor Friedrich Merz calls for real name use on social media.
Italian Police Arrest Man After Alleged Attempt to Abduct Toddler at Bergamo Supermarket, Child Hospitalised With Fractured Femur
British Tourist Arrested at Hong Kong Airport After Meltdown and Vandalism
European Commission Plans Purchase Incentives Limited to Vehicles Manufactured Largely in the EU
French District of Pas-de-Calais Introduces Immediate License Suspension for Drivers Using Mobile Phones
Volkswagen Targets €60 Billion in Cost Reductions as Sales Decline and Global Pressures Intensify
Eighty-Year-Old Lottery Winner Sentenced to 16.5 Years for Drug Trafficking
Rubio Calls for Sweeping U.N. Reform, Saying It Has Failed to End Wars in Gaza and Ukraine
10,000 Condoms Distributed at Winter Olympics 2026 Athlete Village Depleted Within 72 Hours
Poland's President Advocates for Evaluating Independent Nuclear Weapons Development
Mayor of Serdobsk in Russia’s Penza Region Resigns After Housing Certificates Granted to Migrant Family Trigger Public Outcry
China’s EV Makers Face Mandatory Return to Physical Buttons and Door Handles in Driver-Distraction Safety Overhaul
UK Green Party Considering Proposal to Legalize Heroin for an Inclusive Society
OpenAI and DeepCent Superintelligence Race: Artificial General Intelligence and AI Agents as a National Security Arms Race
We will protect them from the digital Wild West.’ Another country will ban social media for under-16s
Heineken announces cut of 6,000 jobs due to declining beer demand
Apple iPhone Lockdown Mode blocks FBI data access in journalist device seizure
Belgium: Man Charged with Rape After Faking Payment to Sex Worker
KPMG Urges Auditor to Relay AI Cost Savings
Canada Opens First Consulate in Greenland Amid Rising Geopolitical Tensions
China unveils plans for a 'Death Star' capable of launching missile strikes from space
Investigation Launched at Winter Olympics Over Ski Jumpers Injecting Hyaluronic Acid
U.S. State Department Issues Urgent Travel Warning for Citizens to Leave Iran Immediately
Wall Street Erases All Gains of 2026; Bitcoin Plummets 14% to $63,000
Eighty-one-year-old man in the United States fatally shoots Uber driver after scam threat
Political Censorship: French Prosecutors Raid Musk’s X Offices in Paris
AI Invented “Hot Springs” — Tourists Arrived and Were Shocked
France Begins Phasing Out Zoom and Microsoft Teams to Advance Digital Sovereignty
Tech Market Shifts and AI Investment Surge Drive Global Innovation and Layoffs
Global Shifts in War, Trade, Energy and Security Mark Major International Developments
Markets Jolt as AI Spending, US Policy Shifts, and Global Security Moves Drive New Volatility
Tesla Ends Model S and X Production and Sends $2 Billion to xAI as 2025 Revenue Declines
Starmer Signals UK Push for a More ‘Sophisticated’ Relationship With China in Talks With Xi
×