abusesaffiliationarrow-downarrow-leftarrow-rightarrow-upattack-typeburgerchevron-downchevron-leftchevron-rightchevron-upClock iconclosedeletedevelopment-povertydiscriminationdollardownloademailenvironmentexternal-linkfacebookfiltergenderglobegroupshealthC4067174-3DD9-4B9E-AD64-284FDAAE6338@1xinformation-outlineinformationinstagraminvestment-trade-globalisationissueslabourlanguagesShapeCombined Shapeline, chart, up, arrow, graphLinkedInlocationmap-pinminusnewsorganisationotheroverviewpluspreviewArtboard 185profilerefreshIconnewssearchsecurityPathStock downStock steadyStock uptagticktooltiptwitteruniversalityweb
Article

22 Jul 2022

Author:
Middle East Eye

Cybersecurity company reveals Candiru spyware exploited vulnerabilities in Google Chrome to target journalists across the Middle East; incl. co. comments

"Israeli spyware maker behind new attack on journalists, cybersecurity firm says" 21 July 2022

Security researchers have linked the discovery of an actively exploited, but since-fixed, zero-day vulnerability in Google Chrome to an Israeli spyware maker known to target journalists in the Middle East.

Avast Threat Labs, a global cybersecurity company, attributed the attacks to the Tel Aviv-based spyware vendor commonly known as Candiru...

Candiru was sanctioned in November 2021 by the US Commerce Department for engaging in activities contrary to US national security.

Avast detected the latest Candiru attack in March using an updated toolset that aimed to target individuals in Turkey, Yemen and Palestine - as well as journalists in Lebanon where Candiru compromised a website used by employees of an unnamed news agency.

“We can’t say for sure what the attackers might have been after, however often the reason why attackers go after journalists is to spy on them and the stories they’re working on directly, or to get to their sources and gather compromising information and sensitive data they shared with the press,” Avast said in a statement.

The company is currently registered in Tel Aviv under the name, Saito Tech.

Middle East Eye reached out to a Candiru executive last year following the revelations by online security firm ESET and was told that the company and its products don’t hack websites.

“The product of the company [Candiru] is purposed to help law enforcement agencies to fight terror and crime, at a time all unlawful activities are encrypted, hiding from the law.”

"The company is selling its products to government agencies only, after receiving all needed licences from the Israeli MOD [Ministry of Defence] export control...

Privacy information

This site uses cookies and other web storage technologies. You can set your privacy choices below. Changes will take effect immediately.

For more information on our use of web storage, please refer to our Data Usage and Cookies Policy

Strictly necessary storage

ON
OFF

Necessary storage enables core site functionality. This site cannot function without it, so it can only be disabled by changing settings in your browser.

Analytics cookie

ON
OFF

When you access our website we use Google Analytics to collect information on your visit. Accepting this cookie will allow us to understand more details about your journey, and improve how we surface information. All analytics information is anonymous and we do not use it to identify you. Google provides a Google Analytics opt-out add on for all popular browsers.

Promotional cookies

ON
OFF

We share news and updates on business and human rights through third party platforms, including social media and search engines. These cookies help us to understand the performance of these promotions.

Your privacy choices for this site

This site uses cookies and other web storage technologies to enhance your experience beyond necessary core functionality.