Share

Lebanon 'source' of new spy software

San Francisco - A security company has discovered a computer spying campaign that it said "likely" originated with a government agency or political group in Lebanon, underscoring how far the capability for sophisticated computer espionage is spreading beyond the world's top powers.

Israeli-based computer security firm Check Point Software Technologies said its researchers ruled out any financial motive for the effort that targeted telecommunications and networking companies, military contractors, media organisations and other institutions in Lebanon, Israel, Turkey and seven other countries.

Researchers also found computers infected with spyware in the US, UK and Canada.

The campaign, which Check Point dubbed Volatile Cedar, dates back at least three years and deploys hand-crafted software with some of the hallmarks of state-sponsored computer espionage.

Twice, after software elements were detected as malicious by anti-virus programs, the campaign paused and then began distributing newer versions that escaped scrutiny, said Check Point researcher Shahar Tal.

Unusual hacking

While the chief aims of the software were to steal data and spread, the programs could also delete files and take other actions at the direction of control computers elsewhere.

The distributors relied on an unusual method for installation, Tal said. Instead of emailing tainted links or infected attachments, the people behind Volatile Cedar broke down the front door, hacking into public-facing websites and then moving from those host computers to others in the organisation that contained more valuable information.

"They are not 'script kiddies'," as low-skill hackers are called, Tal said. "But we have to say in terms of technical advancement, this is not NSA-grade. They are not replacing hard-drive firmware," as did a nearly undetectable strain of spy software found recently by Kaspersky Lab.

Tal declined to say what sort of data had been stolen but said he found the successful infiltration of a defence contractor to be "alarming".

He said Check Point had notified authorities in all 10 countries where the hundreds of infections had been detected. The company also passed along technical information to other security companies so that their anti-virus programs would find more instances.

Tal said he was not aware of any other major spying campaign attributed to the Lebanese government or major factions.

Researchers consider the US, China and Russia to be the most advanced and prolific electronic spies, while other major cyber espionage efforts have been traced to Israel, the UK, France and Spain.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.01
+1.1%
Rand - Pound
23.79
+0.7%
Rand - Euro
20.40
+0.8%
Rand - Aus dollar
12.40
+0.7%
Rand - Yen
0.12
+1.2%
Platinum
925.50
+1.5%
Palladium
989.50
-1.5%
Gold
2,331.85
+0.7%
Silver
27.41
+0.9%
Brent-ruolie
88.02
-0.5%
Top 40
68,437
-0.2%
All Share
74,329
-0.3%
Resource 10
62,119
+2.7%
Industrial 25
102,531
-1.5%
Financial 15
15,802
-0.2%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders