Citizen Lab and Microsoft detail mercenary spyware from Tel Aviv-based QuaDream used to hack iOS 14-based iPhones of journalists, politicians, and an NGO worker
why didn't Apple warn us? Wall Street Journal : New Spyware Firm Said to Have Helped Hack iPhones Around the Globe Phil Muncaster / Infosecurity : New Zero-Click iOS Exploit Deploys Israeli Spyware Eduard Kovacs / SecurityWeek : Details Emerge On Israeli Spyware Vendor QuaDream And Its IOS Malware Ashwin / gHacks Technology News : Pegasus-like spyware Reign was used in targeted iPhone attacks Preslav Mladenov / PhoneArena : A new report exposes Reign: a Pegasus-like spyware used to hack iPhones Brandon Vigliarolo / The Register : Another zero-click Apple spyware maker just popped up on the radar again Duncan Riley / SiliconANGLE : Little-known Israeli vendor found selling dangerous iPhone spyware Habiba Rashid / HackRead : QuaDream: Israeli Cyber Mercenary Behind iPhone Hacks Nick Heer / Pixel Envy : A Look at QuaDream's Exploits, Victims, and Customers Zac Hall / 9to5Mac : Report reveals details about iOS 14 exploit, spyware, and the mysterious group behind it Tech Xplore : New Israeli spyware targets journalists, politicians: watchdog Michael Kan / PCMag : Israeli Firm Using Spyware to Infect iPhones Via Calendar Invites iTnews : Israeli spyware used to hack across 10 countries David Perera / BankInfoSecurity.com : Suspected Apple iOS Zero-Day Used to Spread ‘Reign’ Spyware MacDailyNews : Spyware firm QuaDream said to have helped hack iPhones running older iOS 14 Karandeep Oberoi / MobileSyrup : Hackers use spyware-infected calendar invites to target iPhones Prayank / Candid.Technology : New Israeli spyware hacks iPhones of journalists and politicians Tweets: John Scott-Railton / @jsrailton : NEW INVESTIGATION🚨: exposing zero-click mercenary #spyware company #QuaDream. Victims include journalists, opposition politicians, an NGO worker... Many countries w/suspected operators. THREAD 1/ https://citizenlab.ca/... https://twitter.com/... Bill Marczak / @billmarczak : Check out our NEW @citizenlab report “Sweet QuaDreams: A First Look at Spyware Vendor QuaDream's Exploits, Victims, and Customers”, in which we uncover traces of a new iOS 14 zero-click deployed against civil society from (at least) Jan through Nov 2021 https://citizenlab.ca/... Marc Owen Jones / @marcowenjones : “Citizen Lab also said it was able to detect operator locations for the spyware in Bulgaria, the Czech Republic, Hungary, Ghana, Israel, Mexico, Romania, Singapore, the UAE and Uzbekistan.” https://www.theguardian.com/ ... Manish Tewari / @manishtewari : There is urgent need to put in place a proper regulatory mechanism to protect privacy of Citizens from increasingly weaponised spyware that makes hacking virtually impossible to detect iPhones hacked via invisible calendar invites to drop QuaDream spyware https://www.bleepingcomputer.com/ ... Caroline Orr Bueno, Ph.D / @rvawonk : Welp. There's a new zero-click spyware targeting journalists and political figures. It has all the features of Pegasus but this one can also be used to generate two-factor authentication codes on an iPhone to infiltrate a user's iCloud account. https://www.theguardian.com/ ... @citizenlab : The suspected exploit appears to make use of invisible iCloud calendar invitations sent from the spyware's operator to victims. The report identifies victims of QuaDream exploits include journalists, political opposition figures and an NGO worker. Bill Marczak / @billmarczak : We worked jointly on this report with the amazing folks at @MsftSecIntel, who shared samples of QuaDream's spyware with us. Read Microsoft's report here: https://www.microsoft.com/.... Thanks also to @AccessNow and other partners that assisted with this research! @msftsecintel : A threat group tracked by Microsoft as DEV-0196 is linked to an Israel-based private sector offensive actor (PSOA) known as QuaDream, which reportedly sells a suite of exploits, malware, and infra. Read our analysis in collaboration with @citizenlab: https://www.microsoft.com/... Rickey Gevers / @uid_ : I will repeat it again. Any government has access to your mobile phone and you are not able to detect it. This is a big problem at this moment. ‘Mercenary spyware hacked iPhone victims with rogue calendar invites, researchers say’ https://techcrunch.com/... Jonathan Scott / @jonathandata1 : 🤦♂️ @citizenlab partnered with Microsoft to help bolster their spyware claims and there is nothing in any of their posts that can definitely attribute anything to QuaDream If anyone can find the malware sample please link. So much talk & no sample. https://www.microsoft.com/... John Scott-Railton / @jsrailton : 7/ Fresh reporting by @lorenzofb of @TechCrunch has some juicy details on #QuaDream. ❌Efforts to skirt export export regulations ❌Use by 🇲🇽#Mexico & efforts to disguise end user. Super concerning, an investigation is clearly warranted. https://techcrunch.com/... https://twitter.com/... @citizenlab : Like other #spyware, the implant has a range of capabilities from hot -mix audio recording of calls to more advanced #surveillance capabilities 🍎📱👀 https://twitter.com/... @citizenlab : QuaDream is an Israeli company that specializes in development and sale of advanced digital offensive tech to governments. The map below is an illustration of suspected locations of QuaDream operations https://twitter.com/... Stephanie Kirchgaessner / @skirchy : So far, researchers at @citizenlab have identified more than five victims and it's a familiar group of people: journalists, political opposition figures, an employee at an NGO. Even as the US has sought to curtail NSO Group, Reign has the same powerful capabilities as Pegasus https://twitter.com/... John Scott-Railton / @jsrailton : 3/ @MsftSecIntel #QuaDream shared samples w/ us @citizenlab. We developed forensic techniques to identify the spyware on iOS devices. In the binaries we found a fully featured implant that cleans up its own traces. And we found evidence of suspected zero click exploits... https://twitter.com/... John Scott-Railton / @jsrailton : 2/ #QuaDream keeps a low profile & avoids the limelight, unlike it's competitor NSO Group (of #Pegasus notoriety). But it's had some brushes with attention, including about deals & pitches. And after being called out by @meta for testing on their platforms. https://twitter.com/... @citizenlab : NEW REPORT: SWEET QUADREAMS: A first look at #spyware vendor QuaDream's spy tools, victims and customers. We identified traces of suspected exploit deployed against iOS versions 14.4 and 14.4.2 and possibly other versions as zero-day vulnerability. https://citizenlab.ca/... @rondeibert : NEW @citizenlab REPORT: Identifies another Israeli-based mercenary spyware vendor: QuaDream * Civil society victims in several regions * Operators in Bulgaria, Czech Republic, Hungary, Ghana, Israel, Mexico, Romania, Singapore, UAE) & Uzbekistan https://citizenlab.ca/... @lorenzofb : A source who used to be in the spyware industry tells us QuaDream has indeed set up a company in Cyprus to skirt export regulations. The source also confirmed some of the customers that have been reported previously (KSA) and others (Mexico etc). https://techcrunch.com/... @lorenzofb : NEW: Government hackers breached the iPhones of at least five victims (journalists, politicians, NGO worker) using spyware made by QuaDream, according to Microsoft and Citizen Lab. https://techcrunch.com/... See also Mediagazer