Microsoft says Israeli company's malware used to hack dissidents, activists
Microsoft said around half of the victims were located in the Palestinian territories, and many of the remaining targets were based in the Middle East.
Microsoft says it disrupted an Israeli private company’s unique malware that hackers in other countries used to spy on political dissidents and rights campaigners.
After receiving a tip from researchers at Citizen Lab, a watchdog organization at the University of Toronto's Munk School of Global Affairs, Microsoft began investigating malware from a group it dubbed “Sourgum.”
Sourgum’s malware appeared to use a chain of browser and Windows exploits, including zero-day exploits, the company said. The hackers sent the browser exploits to targets with single-use URLs on messaging applications such as WhatsApp.
Citizen Lab has assessed with high confidence that the actor Microsoft is calling Sourgum is an Israeli company that goes by the name Candiru. According to the watchdog, Candiru sells spyware that can infect and monitor a range of devices and platforms, including Microsoft's Windows operating system.