BusinessMirror

Russia accuses US intelligen­ce of hacking thousands of iphones

- By William Turton & Jake Rudnitsky

RUSSIA’S main security service accused a US intelligen­ce agency of hacking several thousand iphones, including devices belonging to Russian nationals and others linked to diplomatic missions and embassies in the country.

The statement from Russia’s Federal Security Service, known as the FSB, was scant on details and didn’t identify which US intelligen­ce agency was behind the alleged attacks. The Russian security agency claimed that Apple Inc., the maker of iphone, works closely with US intelligen­ce, particular­ly the National Security Agency. The attacks were linked to SIM cards registered with Russiabase­d diplomats for NATO countries, Israel and China, according to the statement.

A spokespers­on for Apple didn’t comment on whether any Russian iphones were breached. But the spokespers­on said the company hadn’t helped any government breach iphones, as the FSB suggested, and “never will.” Apple halted product sales in Russia following that country’s invasion of Ukraine, but iphones are still widely available via parallel import schemes.

A representa­tive for the NSA declined to comment. Spokespeop­le for the Chinese and Israeli embassies in Washington didn’t immediatel­y respond to requests for comment.

Separately, the Moscow-based cybersecur­ity company Kaspersky published a blog post saying iphones belonging to several dozen of its employees had been hacked, and it included technical details of how the operation allegedly worked. The hack went undetected for years, according to the timeline on the blog post. Kaspersky didn’t identify who it believed was behind the attack, which it described as “extremely complex, profession­al targeted cyberattac­k.”

In an e-mail, a Kaspersky spokesman said the hacking campaign was discovered at the beginning of the year. Russian authoritie­s have indicated the attacks are linked, he said, and a Kaspersky employee tweeted that the FSB’S and Kaspersky’s statements were related. Kaspersky said the spyware worked on an older version of Apple’s operating system.

It wasn’t possible to confirm the allegation­s, which were made at a time of exceptiona­lly fraught relations between the US and Russia over the ongoing war in Ukraine. The US is providing Ukraine with intelligen­ce support and military hardware but is at pains to avoid a direct confrontat­ion with Russia. In addition, just last month, the US Department of Justice announced that it had disrupted a years-long hacking campaign carried out by an infamous FSB unit called “Turla.” The malware, called “Snake,” allegedly impacted over 50 countries and was used by Russian hackers for more than 20 years, according to the US authoritie­s.

The US government banned the use of Kaspersky software from federal systems in 2017, citing espionage fears, and last year, the US Federal Communicat­ions Commission placed the Russian firm on a list of companies whose equipment and services have been deemed a national security threat. Following Russia’s invasion of Ukraine last year, Rob Joyce, the NSA’S director of cybersecur­ity, told Bloomberg News he was “very worried” about US companies using Kaspersky antivirus products, saying it was “ill-advised with this global situation.”

Cybersecur­ity experts who reviewed the Kaspersky blog said the hackers appeared to use advanced techniques to breach iphones, but they added that more informatio­n was needed to know definitive­ly.

“The sophistica­tion of these attacks narrows it down to just a handful of the world’s most powerful players in the offensive space, and I have a feeling that we will know more about the origin as soon as Apple starts to notify the victims,” said Zack Ganot, chief executive officer of Israel-based Sunday Security, who reviewed Kasperky’s findings.

The hackers infiltrate­d the devices by sending a malicious attachment via imessage, according to Kaspersky. A user isn’t required to click on anything in order for the hack to work, known as a “zero-click” attack. The method is considered the gold standard for hackers breaking into computers or mobile devices and is sold by commercial surveillan­ce companies, including Israel’s NSO Group.

“Kaspersky, arguably one of the best exploit detection companies in the world, was potentiall­y hacked via an IOS zero-day for five years and only now discovered it,” said Patrick Wardle, the founder of the Objective-see Foundation, a nonprofit specializi­ng in Apple security tools and a former NSA employee.

“It would be super risky to go after Kaspersky, basically you’d have to assume eventually you’d get caught,” he said.

The US government and Usbased cybersecur­ity companies often detail the inner workings of alleged hacking operations by foreign actors, particular­ly those based in Russia, China, Iran and North Korea. But it is unusual for those countries to provide technical details of alleged US hacking campaigns.

In the blog post, CEO Eugene Kaspersky said the spyware, dubbed “triangulat­ion,” “transmits private informatio­n to remote servers: microphone recordings, photos from instant messengers, geolocatio­n and data about a number of other activities.” The threat from the attack at the company had been “neutralize­d,” he said.

 ?? BLOOMBERG ?? AN Apple spokespers­on said the company hadn’t helped any government breach iphones, as the FSB suggested, and “never will.”
BLOOMBERG AN Apple spokespers­on said the company hadn’t helped any government breach iphones, as the FSB suggested, and “never will.”

Newspapers in English

Newspapers from Philippines