Skip to main content

Microsoft says Israeli company's malware used to hack dissidents, activists

Microsoft said around half of the victims were located in the Palestinian territories, and many of the remaining targets were based in the Middle East.

Munk School
The University of Toronto's Munk School is seen on Sept. 19, 2009. The school's Citizen Lab watchdog told Microsoft about malware that the computing giant has disrupted. — SimonP/Wikipedia

Microsoft says it disrupted an Israeli private company’s unique malware that hackers in other countries used to spy on political dissidents and rights campaigners. 

After receiving a tip from researchers at Citizen Lab, a watchdog organization at the University of Toronto's Munk School of Global Affairs, Microsoft began investigating malware from a group it dubbed “Sourgum.” 

Sourgum’s malware appeared to use a chain of browser and Windows exploits, including zero-day exploits, the company said. The hackers sent the browser exploits to targets with single-use URLs on messaging applications such as WhatsApp. 

Citizen Lab has assessed with high confidence that the actor Microsoft is calling Sourgum is an Israeli company that goes by the name Candiru. According to the watchdog, Candiru sells spyware that can infect and monitor a range of devices and platforms, including Microsoft's Windows operating system.

SUBSCRIBER EXCLUSIVE

Continue reading this exclusive analysis

Original reporting and analysis unavailable elsewhere. Subscribe to AL-MONITOR to read this story and access everything we publish