Israeli company linked to Middle East cyberattacks

Published November 17, 2021
Israeli spyware company Candiru was blacklisted by the US government earlier this month. — AFP/File
Israeli spyware company Candiru was blacklisted by the US government earlier this month. — AFP/File

PARIS: Technology sold by Israeli spyware company Candiru appears to have been used for a campaign of cyberattacks targeting high-profile Middle Eastern websites, an analysis by cyber-security firm Eset said on Tuesday.

“We think it was a client of Candiru that carried out these attacks,” Eset investigator Matthieu Faou said.

Eset did not name the client, but pointed to an investigation by researchers at the University of Toronto that suggested in June that Saudi Arabia may have used similar techniques.

Based in Tel Aviv, Candiru sells sophisticated spyware to governments.

It was blacklisted by the US government earlier this month.

The offensive revealed by Eset used what are known as “watering hole” attacks, which add malicious code to legitimate websites that the targeted user is likely to visit.

Once the person visits the site, the code can then be used to infect their computer — potentially to spy on them or inflict harm in other ways.

The websites targeted in this campaign included UK-based news site Middle East Eye as well as Yemeni media outlets like Almasirah linked to the Houthi militants battling the Saudis, Eset said.

Another victim was thesaudireality.com, which Eset said was likely a dissident media outlet in Saudi Arabia.

Internet service providers in Yemen and Syria were also targeted along with the Iranian foreign ministry, Syria’s electricity ministry, and Yemen’s interior and finance ministries.

Other targets included sites run by the pro-Iranian group Hezbollah, Italian company Piaggio Aerospace and Denel, a state-owned South African aerospace and military technology conglomerate.

“The attackers also created a website mimicking a medical trade fair in Germany,” Eset noted in a press release, adding that the intrusions were recorded between July 2020 and August this year.

Candiru has earned comparisons with NSO, another Israeli company that was engulfed in scandal this year over accusations that governments used its Pegasus technology to spy on rights activists, politicians, journalists and business executives. The US government blacklisted NSO earlier this month, restricting exports from American firms.

Faou said the Candiru campaign did not appear to be aimed at mass data collection, specifically targeting a “very, very small” number of people.

Published in Dawn, November 17th, 2021

Opinion

First line of defence

First line of defence

Pakistan’s foreign service has long needed reform to be able to adapt to global changes and leverage opportunities in a more multipolar world.

Editorial

Eid amidst crises
Updated 31 Mar, 2025

Eid amidst crises

Until the Muslim world takes practical steps to end these atrocities, these besieged populations will see no joy.
Women’s rights
Updated 01 Apr, 2025

Women’s rights

Such judgements, and others directly impacting women’s rights should be given more airtime in media.
Not helping
Updated 02 Apr, 2025

Not helping

If it's committed to peace in Balochistan, the state must draw a line between militancy and legitimate protest.
Hard habits
Updated 30 Mar, 2025

Hard habits

Their job is to ensure that social pressures do not build to the point where problems like militancy and terrorism become a national headache.
Dreams of gold
30 Mar, 2025

Dreams of gold

PROSPECTS of the Reko Diq project taking off soon seem to have brightened lately following the completion of the...
No invitation
30 Mar, 2025

No invitation

FOR all of Pakistan’s hockey struggles, including their failure to qualify for the Olympics and World Cup as well...