The Jerusalem Post

Export controls strangling cyberattac­k industry

- • By ASSAF GILEAD

In the past few days, a small, little-known Israeli cyberattac­k company called Nemesis shut down. The company, which tried to compete with NSO Group with spyware that takes control of smartphone­s, was never exposed by the media and did not even have a company website.

Its closure marks for many in the Israeli cyberattac­k sector a new era in relations between the Defense Ministry and the Israeli industry.

Several senior figures in the sector told Globes Nemesis shut down after the Israel Defense Exports Control Agency (DECA) refused to grant a license to export its intelligen­ce software to countries in South America and Africa. In several other instances, the approval process was continuall­y extended with no further response. Eventually, the company collapsed under the weight of its employees’ salaries – most of whom were highly skilled cyber coders, who expect the highest of salaries.

US pressure

Many senior executives in Israel’s cyberattac­k industry have complained in recent weeks of an abrupt change in policy by the Defense Ministry toward Israeli companies exporting spyware for intelligen­ce use. Since January, the Defense Ministry has limited the number of countries with an exemption for marketing licenses for spyware to 38 countries in Western Europe and North America, as well as Asia-Oceania countries such as Australia and New Zealand, South Korea and Japan.

Israeli defense exports totaled $11.3 billion in 2021, of which about 4% was in intelligen­ce and cyber systems worth about $450 million.

When new measures were announced last November, the widespread assumption in the industry was that cyberattac­k exports would not be banned to countries that were not blackliste­d, such as India, Poland, Chile, Mexico and the UAE. The expectatio­n was that individual export permits would be needed from the Defense Ministry for the sales process of each individual deal.

However, in the past few months, it has become clear that the Defense Ministry has been issuing few, if any, marketing or export permits to countries outside the aforementi­oned list of exempted countries. This is likely following US pressure exerted on Israel.

Last November, the Biden administra­tion declared that war on harmful spyware was part of US foreign policy, which, among other things, was intended for tracking opposition figures or human-rights activists around the world. The US struggle on the matter focused on Israeli companies NSO and Candiru, which were put on the Department of Commerce’s blacklist, while a range of Greek, French, German and Chinese companies were not blackliste­d.

A starved industry

The closure of Nemesis is a portend of future difficulti­es for other companies in Israel’s cyberattac­k industry, senior sources told Globes. Companies such as NSO itself – as well as

Cognyte, Quadream, and Wintego – are among those who have suffered in recent months from lack of approvals for new deals and cancellati­on of export permits. Some have claimed that their permits were canceled just before they expired; in more extreme cases, some were canceled long before they expired.

The Defense Ministry, in cooperatio­n with the Foreign Ministry, IDF and other organizati­ons, examine every deal in which a cyberattac­k company is interested; this procedure takes about 45 days. In recent months, senior sources have reported that DECA personnel have repeatedly required an extension of the examinatio­n process so that requesting a marketing license will take longer. Ultimately, most of the requests are not approved.

“An entire industry is being starved,” a senior executive at one company told Globes. “They leave us in the dark, and they don’t tell us where our request stands, and if it has not been approved, they don’t explain why. It seems as if the state has given up on the cyberattac­k industry without actually saying so. but if that is the policy, then why not say so upfront? They are chewing things over until the entire industry bleeds to death.”

Another senior executive in the industry said: “The state is trying to tell us that we should forget about markets in South America, Africa and some of the countries in Asia. But it’s simply not possible to close down complete markets for an entire industry, while also asking it to rely on just Europe and North

America. It’s a crowded and unprofitab­le market that cannot support Israel’s industry as it is today.”

Many countries that were once seen as viable export markets for Israeli products have undergone dramatic changes. South America, for example, has seen a wave of progressiv­e socialist government­s come to power in some of its countries, and they are not terribly fond of Israel.

Eastern Europe fills the vacuum

Foreign companies have naturally stepped into the vacuum that has been created by DECA, including the European countries that have been operating in the cyberattac­k market since its formation. Although three veteran European cyberattac­ks companies – German company FinFisher, French company Emsys and Italian company Memento Labs (formerly Hacking Team) – are no longer active due to stricter EU regulation, other companies from Eastern and Southern Europe have become active exporters of spyware.

One of them is Intellexa, founded by Col. (ret.) Tal Dilian, who formerly headed a technologi­cal unit in the IDF Intelligen­ce Corps and currently lives in Greece. Research by the University of Toronto’s Citizen Lab said Intellexa markets Cytrox Predator spyware, which obtains software from cellphones and competes with NSO’s Pegasus.

Intellexa reportedly undertakes its sales operations from North Macedonia, which is not an EU member and not subject

to its supervisio­n; instead, North Macedonia is subject to the Wassenaar Arrangemen­t on cyberattac­k exports.

Among Intellexa’s customers are countries that DECA no longer provides permits for, including Bangladesh, Turkey, Egypt, Indonesia, Saudi Arabia and Oman. In addition, the company is conducting talks with the UAE, a country in which many other Israeli cyberattac­k companies operate.

Another issue that DECA must cope with is the export of intellectu­al property (IP) of cyberattac­k companies. Cyberattac­k companies divide their IP into two categories. The first is cyber vulnerabil­ities; in other words, informatio­n about breaches that can affect operating systems or apps on various smartphone devices. The second category is attack systems

– hacking tools that exploit security vulnerabil­ities to enter and draw out content from the user’s device.

Companies supervised by DECA cannot export vulnerabil­ities or attack tools without an explicit permit. However, supervisio­n in recent months might encourage Israelis to set up companies specializi­ng in the developmen­t of cyber vulnerabil­ities that can theoretica­lly be sold overseas without supervisio­n by the Defense Ministry.

Alternativ­ely, some Israelis could shut down their companies and reopen them abroad, although this would require foregoing IP developed in Israel.

“We live in a global world, and within five minutes, you can open a company abroad and do things no less sophistica­ted in the US and Europe,” said a senior executive. “And if they make it difficult to live here and do the things that we are good at doing, we won’t fight over something that we cannot win.”

The Defense Ministry said: “The Ministry, in cooperatio­n with the Ministry of Foreign Affairs, has tightened supervisio­n over the past year on cyber exports and, among other things, has published a revised formulatio­n for the ‘end user declaratio­n’ that every country is required to sign as a condition for receiving licenses, for the export of cyber gathering systems and or intelligen­ce systems. Alongside this, the State of Israel is examining special assistance for the cyber industry, which will protect their capabiliti­es, even in a reality of stricter global regulation.” (Globes/TNS)

 ?? (Amir Cohen/Reuters) ?? ONE OF cyber firm NSO Group’s branches in the Arava Desert.
(Amir Cohen/Reuters) ONE OF cyber firm NSO Group’s branches in the Arava Desert.

Newspapers in English

Newspapers from Israel