BTC $105491.5018
ETH $2531.2556
XRP $2.1535
BNB $649.5919
SOL $146.0813
DOGE $0.1758
TRX $0.2712
ADA $0.6284
stETH $2528.2090
WBTC $105358.8339
HYPE $40.4385
wstETH $3049.2407
SUI $2.9952
BCH $442.1612
USDS $1.0001
LINK $13.1567
LEO $9.2512
XLM $0.2570
AVAX $18.9878
ONDO $0.7875
TON $2.9631
BTCB $105423.0450
WBT $39.7857
WETH $2528.1581
weETH $2705.3830
LTC $85.5616
HBAR $0.1536
BSC-USD $1.0000
DOT $3.7774
USDE $0.9997
XMR $317.5867
BGB $4.5244
PEPE $0.0000
PI $0.6166
AAVE $273.0608
UNI $7.2286
sUSDe $1.1783
DAI $0.9996
TAO $366.4956
OKB $51.7681
CBBTC $105503.2238
APT $4.4845
ICP $5.3394
NEAR $2.2407
CRO $0.0908
ETC $16.6283
JITOSOL $176.5502
BTC $105491.5018
ETH $2531.2556
XRP $2.1535
BNB $649.5919
SOL $146.0813
DOGE $0.1758
TRX $0.2712
ADA $0.6284
stETH $2528.2090
WBTC $105358.8339
HYPE $40.4385
wstETH $3049.2407
SUI $2.9952
BCH $442.1612
USDS $1.0001
LINK $13.1567
LEO $9.2512
XLM $0.2570
AVAX $18.9878
ONDO $0.7875
TON $2.9631
BTCB $105423.0450
WBT $39.7857
WETH $2528.1581
weETH $2705.3830
LTC $85.5616
HBAR $0.1536
BSC-USD $1.0000
DOT $3.7774
USDE $0.9997
XMR $317.5867
BGB $4.5244
PEPE $0.0000
PI $0.6166
AAVE $273.0608
UNI $7.2286
sUSDe $1.1783
DAI $0.9996
TAO $366.4956
OKB $51.7681
CBBTC $105503.2238
APT $4.4845
ICP $5.3394
NEAR $2.2407
CRO $0.0908
ETC $16.6283
JITOSOL $176.5502
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • SEKOIA Reveals Lycantrox Spy Campaign Infrastructure

    Which nations have been discovered snooping on their citizens without authorization?

     

    Researchers from Citizen Lab released a report last month detailing how former Egyptian lawmaker Ahmed Eltantawi's iPhone was targeted by hackers using Cytrox's Predator spyware.

    Eltantawi was the target of a redirect attack to malicious websites in August and September of this year that installed the Predator spyware by using iOS zero-day vulnerabilities (CVE-2023-41991, CVE-2023-41992, and CVE-2023-41993). This attack, as anticipated, was motivated by politics.

    In the past, Cytrox has drawn attention for using Predator to target celebrities. The activities of Cytrox and its parent company Intellexa were being investigated at the time by Citizen Lab and the now-banned Meta*.

    A report from SEKOIA that was published in December 2021 looked at potential connections between Operation Lycantrox-tracked Cytrox clients and Operation Karkadann-tracked Candiru clients. Both spy operations compromised their targets using a similar infrastructure.

    Most recently, SEKOIA experts discovered numerous domains connected to this group while analyzing the infrastructure used by Lycantrox. Examples include "elwatnanews[.]com," which poses as a news source, and "bitshort[.]info," which poses as a link shortening service.

    The researchers identified 121 distinct domain names that were highly confidently connected to the Lycantrox infrastructure. Many of these domains are somehow connected to cybercrime and have connections to servers that accept cryptocurrency payments.

    The servers connected to the identified domains are located in Madagascar, Indonesia, Kazakhstan, and Angola, according to a thorough analysis of the threat. Researchers think local government agencies use them to spy online on different politicians, activists, and journalists.

    The experts promised to keep an eye on the actions of cyber mercenaries from Cytrox and Intellexa while exposing their infrastructure and providing all identified indicators of compromise of the Lycantrox espionage campaign in their report.

    Author reign3d
    Israel is under siege online by Hamas, which has launched numerous cyberattacks against it
    Rhysida ransomware takes government services of Portugal and the Dominican Republic offline

    Comments 0

    Add comment