Turkish Twitter users targeted with mobile FinFisher spyware

Posted by   Martijn Grooten on   May 15, 2018

A new research paper by digital rights organization Access Now looks at how FinFisher has been used against people interested in anti-government protests in Turkey.

Access-Now-report-FinFisher.jpg

Through fake social media accounts, users were tricked into installing an Android application which was actually a mobile version of the FinFisher spyware.

The use of a massive campaign, as opposed to targeting very specific individuals, fits in with other recent FinFisher activity. At VB2017, ESET researcher Filip Kafka showed how the same campaign used ISPs to serve malware.

The use of larger scale attacks by government spyware is, on the one hand, a worrying sign that shows a growth in this kind of activity. On the other hand, it does make it easier for the malware campaigns to be detected, both by security tools and by the platforms, such as Twitter, that are being abused.

Filip Kafka will be back at VB2018 in Montreal to talk about that other European company selling spyware to governments: Hacking Team. The video of his VB2017 presentation on FinFisher can be seen on our YouTube channel.

Registration for VB2018 is now open. Book your ticket now to guarantee a place at one of the most international security conferences – register before 1 July to qualify for an Early Bird discount.

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

New paper: Does malware based on Spectre exist?

It is likely that, by now, everyone in computer science has at least heard of the Spectre attack, and many excellent explanations of the attack already exist. But what is the likelihood of finding Spectre being exploited on Android smartphones?

More VB2018 partners announced

We are excited to announce several more companies that have partnered with VB2018.

Malware authors' continued use of stolen certificates isn't all bad news

A new malware campaign that uses two stolen code-signing certificates shows that such certificates continue to be popular among malware authors. But there is a positive side to malware authors' use of stolen certificates.

Save the dates: VB2019 to take place 2-4 October 2019

Though the location will remain under wraps for a few more months, we are pleased to announce the dates for VB2019, the 29th Virus Bulletin International Conference.

Necurs update reminds us that the botnet cannot be ignored

The operators of the Necurs botnet, best known for being one of the most prolific spam botnets of the past few years, have pushed out updates to its client, which provide some important lessons about why malware infections matter.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.