Thursday, January 18, 2018

Mobile Cyber-Espionage at a Global Scale


One of the key issues that has stymied the growth of the Mobile Threat Defense (MTD) market is that the mobile threat landscape that MTD protects against doesn't really scare enterprises.

That might be about to change. Enter Dark Caracal, characterized by Lookout and Electronic Frontier Foundation, as "cyber-espionage at a global scale."

Again, like other serious threats. this is attributed to a state actor: the Lebanese General Security Directorate in Beirut. To quote further from the report:
Dark Caracal has been conducting a multi-platform, APT-level surveillance operation targeting individuals and institutions globally.
Although Dark Caracal uses tools across mobile and desktop platforms, including Windows, OSX and Linux, it uses mobile (Android) as its primary attack platform. Of the 81 GB of data exfiltrated, 59% is from Android campaigns. The report outlines the devastating surveillance functionality of a compromised device:

The breadth and quantity of exfiltrated data is significant, and includes:

Compromised devices have been discovered worldwide.

The problem with MTD is that it competes for security budget funds with advanced persistent threat (APT) solutions, largely regarded at the top enterprise threat and the type of attack that breached Sony, OPM, Target, Home Depot and others. It's easy to imagine that enterprises will re-evaluate the priority of an MTD solution as they digest the new threat landscape that includes Dark Caracal.

No comments:

Post a Comment