{"id":11179,"date":"2012-07-25T12:40:10","date_gmt":"2012-07-25T19:40:10","guid":{"rendered":"http:\/\/www.crookedbough.com\/?p=11179"},"modified":"2012-07-25T12:40:10","modified_gmt":"2012-07-25T19:40:10","slug":"gamma-international-uk-ltd-finfishers-spy-kit-exposed","status":"publish","type":"post","link":"https:\/\/www.crookedbough.com\/?p=11179","title":{"rendered":"Gamma International UK Ltd. &#8211; FinFisher\u2019s Spy Kit Exposed?"},"content":{"rendered":"<p><strong>From Bahrain With Love: FinFisher\u2019s Spy Kit Exposed?<\/strong><br \/>\n25 July, 2012 &#8211; The Citizen Lab<\/p>\n<p>The FinFisher Suite is described by its distributors, Gamma International UK Ltd., as \u201cGovernmental IT Intrusion and Remote Monitoring Solutions.\u201d 1 The toolset first gained notoriety after it was revealed that the Egyptian Government\u2019s state security apparatus had been involved in negotiations with Gamma International UK Ltd. over the purchase of the software. Promotional materials have been leaked that describe the tools as providing a wide range of intrusion and monitoring capabilities.2 Despite this, however, the toolset itself has not been publicly analyzed.<\/p>\n<p>This post contains analysis of several pieces of malware obtained by Vernon Silver of Bloomberg News that were sent to Bahraini pro-democracy activists in April and May of this year. The purpose of this work is identification and classification of the malware to better understand the actors behind the attacks and the risk to victims. In order to accomplish this, we undertook several different approaches during the investigation.<\/p>\n<p>As well as directly examining the samples through static and dynamic analysis, we infected a virtual machine (VM) with the malware. We monitored the filesystem, network, and running operating system of the infected VM.<\/p>\n<p>This analysis suggests the use of \u201cFinspy\u201d, part of the commercial intrusion kit, Finfisher, distributed by Gamma International.<br \/>\nDelivery<\/p>\n<p>This section describes how the malware was delivered to potential victims using e-mails with malicious attachments.<\/p>\n<p>In early May, we were alerted that Bahraini activists were targeted with apparently malicious e-mails. The emails ostensibly pertained to the ongoing turmoil in Bahrain, and encouraged recipients to open a series of suspicious attachments. The screenshot below is indicative of typical message content:   <a href=\"https:\/\/citizenlab.org\/2012\/07\/from-bahrain-with-love-finfishers-spy-kit-exposed\/\" target=\"_blank\">&#8230;more<\/a><\/p>\n<div class=\"igit_tsb_button\" style=\"float: left; margin-right: 10px;\"><a href=\"http:\/\/twitter.com\/share?url=https%3A%2F%2Fwww.crookedbough.com%2F%3Fp%3D11179&amp;text=Gamma+International+UK+Ltd.+-+FinFisher%E2%80%99s+Spy+Kit+Exposed%3F&amp;count=horizontal&amp;via=\" style=\"\" class=\"twitter-share-button\">Tweet<\/a><\/div>","protected":false},"excerpt":{"rendered":"<p>From Bahrain With Love: FinFisher\u2019s Spy Kit Exposed? 25 July, 2012 &#8211; The Citizen Lab The FinFisher Suite is described by its distributors, Gamma International UK Ltd., as \u201cGovernmental IT Intrusion and Remote Monitoring Solutions.\u201d 1 The toolset first gained notoriety after it was revealed that the Egyptian Government\u2019s state security apparatus had been involved <a href=\"https:\/\/www.crookedbough.com\/?p=11179#more-'\" class=\"more-link\">more \u00bb<\/a><\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[247],"tags":[2699],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=\/wp\/v2\/posts\/11179"}],"collection":[{"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11179"}],"version-history":[{"count":2,"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=\/wp\/v2\/posts\/11179\/revisions"}],"predecessor-version":[{"id":11181,"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=\/wp\/v2\/posts\/11179\/revisions\/11181"}],"wp:attachment":[{"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11179"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.crookedbough.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}