FinFisher
   HOME

TheInfoList



OR:

FinFisher, also known as FinSpy, is
surveillance Surveillance is the monitoring of behavior, many activities, or information for the purpose of information gathering, influencing, managing or directing. This can include observation from a distance by means of electronic equipment, such as ...
software marketed by Lench IT Solutions plc, which markets the
spyware Spyware (a portmanteau for spying software) is software with malicious behaviour that aims to gather information about a person or organization and send it to another entity in a way that harms the user—for example, by violating their priv ...
through law enforcement channels. FinFisher can be covertly installed on targets' computers by exploiting security lapses in the update procedures of non-suspect software. The company has been criticized by human rights organizations for selling these capabilities to repressive or non-democratic states known for monitoring and imprisoning political dissidents.
Egypt Egypt ( ar, مصر , ), officially the Arab Republic of Egypt, is a List of transcontinental countries, transcontinental country spanning the North Africa, northeast corner of Africa and Western Asia, southwest corner of Asia via a land bridg ...
ian dissidents who ransacked the offices of Egypt's secret police following the overthrow of Egyptian President
Hosni Mubarak Muhammad Hosni El Sayed Mubarak, (; 4 May 1928 – 25 February 2020) was an Egyptian politician and military officer who served as the fourth president of Egypt from 1981 to 2011. Before he entered politics, Mubarak was a career officer in ...
reported that they had discovered a contract with Gamma International for €287,000 for a license to run the FinFisher software. In 2014, an American citizen sued the Ethiopian government for surreptitiously installing FinSpy onto his computer in America and using it to wiretap his private Skype calls and monitor his entire family's every use of the computer for a period of months. Lench IT Solutions plc has a UK-based branch, Gamma International Ltd in
Andover Andover may refer to: Places Australia *Andover, Tasmania Canada * Andover Parish, New Brunswick * Perth-Andover, New Brunswick United Kingdom * Andover, Hampshire, England ** RAF Andover, a former Royal Air Force station United States * Andov ...
, England, and a Germany-based branch, Gamma International GmbH in
Munich Munich ( ; german: München ; bar, Minga ) is the capital and most populous city of the German state of Bavaria. With a population of 1,558,395 inhabitants as of 31 July 2020, it is the third-largest city in Germany, after Berlin and ...
."Corporate Enemies: Gamma International"
, ''The Enemies of the Internet, Special Edition: Surveillance'', Reporters Without Borders, 12 March 2013.
Gamma International is a subsidiary of the
Gamma Group Gamma Group is an Anglo-German technology company that sells surveillance software to governments and police forces around the world. The company has been strongly criticised by human rights organisations for selling its FinFisher software to u ...
, specializing in surveillance and monitoring, including equipment, software, and training services. It was reportedly owned by William Louthean Nelson through a shell corporation in the
British Virgin Islands ) , anthem = "God Save the King" , song_type = Territorial song , song = "Oh, Beautiful Virgin Islands" , image_map = File:British Virgin Islands on the globe (Americas centered).svg , map_caption = , mapsize = 290px , image_map2 = Brit ...
. The shell corporation was signed by a nominee director in order to withhold the identity of the ultimate beneficiary, which was Nelson, a common system for companies that are established offshore. On August 6, 2014, FinFisher source code, pricing, support history, and other related data were retrieved from the Gamma International internal network and made available on the Internet. The FinFisher GmbH opened insolvency proceedings at the Munich Local Court on 02.12.2021, however this is only a restructuring and the company is to continue as Vilicius Holding GmbH.


Elements of the FinFisher suite

In addition to
spyware Spyware (a portmanteau for spying software) is software with malicious behaviour that aims to gather information about a person or organization and send it to another entity in a way that harms the user—for example, by violating their priv ...
, the FinFisher suite offered by Gamma to the intelligence community includes monitoring of ongoing developments and updating of solutions and techniques which complement those developed by intelligence agencies. The software suite, which the company calls "Remote Monitoring and Deployment Solutions", has the ability to take control of target computers and to capture even encrypted data and communications. Using "enhanced remote deployment methods" it can install software on target computers. An "IT Intrusion Training Program" is offered which includes training in methods and techniques and in the use of the company-supplied software. The suite is marketed in Arabic, English, German, French, Portuguese, and Russian and offered worldwide at trade shows offering an intelligence support system, ISS, training, and products to law enforcement and intelligence agencies.


Method of infection

FinFisher malware is installed in various ways, including fake software updates,
email Electronic mail (email or e-mail) is a method of exchanging messages ("mail") between people using electronic devices. Email was thus conceived as the electronic ( digital) version of, or counterpart to, mail, at a time when "mail" mean ...
s with fake attachments, and security flaws in popular software. Sometimes the surveillance suite is installed after the target accepts installation of a fake update to commonly used software. Code which will install the
malware Malware (a portmanteau for ''malicious software'') is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, depr ...
has also been detected in emails. The software, which is designed to evade detection by antivirus software, has versions which work on mobile phones of all major brands. A security flaw in
Apple An apple is an edible fruit produced by an apple tree (''Malus domestica''). Apple trees are cultivated worldwide and are the most widely grown species in the genus '' Malus''. The tree originated in Central Asia, where its wild ancest ...
's
iTunes iTunes () is a software program that acts as a media player, media library, mobile device management utility, and the client app for the iTunes Store. Developed by Apple Inc., it is used to purchase, play, download, and organize digital mu ...
allowed unauthorized third parties to use iTunes online update procedures to install unauthorized programs. Gamma International offered presentations to government security officials at security software trade shows where they described how to covertly install the FinFisher spy software on suspects' computers using iTunes' update procedures. The security flaw in iTunes that FinFisher is reported to have exploited was first described in 2008 by security software commentator
Brian Krebs Brian Krebs (born 1972) is an American journalist and investigative reporter. He is best known for his coverage of profit-seeking cybercriminals.Perlroth, Nicole.Reporting From the Web's Underbelly. ''The New York Times''. Retrieved February 28, ...
. Apple did not patch the security flaw for more than three years, until November 2011. Apple officials have not offered an explanation as to why the flaw took so long to patch. Promotional videos used by the firm at trade shows which illustrate how to infect a computer with the surveillance suite were released by
WikiLeaks WikiLeaks () is an international non-profit organisation that published news leaks and classified media provided by anonymous sources. Julian Assange, an Australian Internet activist, is generally described as its founder and director and ...
in December, 2011. In 2014, the Ethiopian government was found to have installed FinSpy on the computer of an American citizen via a fake email attachment that appeared to be a Microsoft Word document. FinFisher has also been found to engage in politically motivated targeting. In Ethiopia, for instance, photos of a political opposition group are used to "bait" and infect users. Technical analysis of the malware, methods of infection and its persistence techniques has been published in Code And Security blog in four parts.


Use by repressive regimes

* FinFisher's wide use by governments facing political resistance was reported in March 2011 after Egyptian protesters raided
State Security Investigations Service The State Security Investigations Service ( arz, مباحث أمن الدولة ) was the highest national internal security authority in Egypt. Estimated to employ 100,000 personnel, the SSI was the main security and intelligence apparatus of Eg ...
and found letters from Gamma International UK Ltd., confirming that SSI had been using a trial version for five months. * A similar report in August 2012 concerned e-mails received by Bahraini activists and passed on (via a
Bloomberg News Bloomberg News (originally Bloomberg Business News) is an international news agency headquartered in New York City and a division of Bloomberg L.P. Content produced by Bloomberg News is disseminated through Bloomberg Terminals, Bloomberg T ...
reporter) to University of Toronto computer researchers Bill Marczak and Morgan Marquis-Boire in May 2012. Analysis of the e-mails revealed code (FinSpy) designed to install spyware on the recipient's computer. A spokesman for Gamma claims no software was sold to Bahrain and that the software detected by the researchers was not a legitimate copy but perhaps a stolen, reverse-engineered or modified demonstration copy. In August 2014 Bahrain Watch claimed that the leak of FinFisher data contained evidence suggesting that the Bahraini government was using the software to spy on opposition figures, highlighting communications between Gamma International support staff and a customer in Bahrain, and identifying a number of human rights lawyers, politicians, activists and journalists who had apparently been targeted. * According to a document dated 7 December 2012 from the Federal Ministry of the Interior to members of the Finance Committee of the German Parliament, the German "Bundesnachrichtendienst", the Federal Surveillance Agency, have licensed FinFisher/FinSpy, even though its legality in Germany is uncertain. * In 2014, an America citizen sued the Ethiopian government for installing and using FinSpy to record a vast array of activities conducted by users of the machine, all whilst in America. Traces of the spyware inadvertently left on his computer show that information – including recordings of dozens of Skype phone calls – was surreptitiously sent to a secret control server located in Ethiopia and controlled by the Ethiopian government. FinSpy was downloaded on the plaintiff's computer when he opened an email with a Microsoft Word document attached. The attachment contained hidden malware that infected his computer. In March 2017, the United States Court of Appeals for the District of Columbia Circuit found that the Ethiopian government's conduct was protected from liability by the Foreign Sovereign Immunities Act. * In 2015, FinFisher was reported to have been in use since 2012 for the 'Fungua Macho' surveillance programme of
Uganda }), is a landlocked country in East Africa. The country is bordered to the east by Kenya, to the north by South Sudan, to the west by the Democratic Republic of the Congo, to the south-west by Rwanda, and to the south by Tanzania. The ...
's
President Museveni Yoweri Kaguta Museveni Tibuhaburwa (born 15 September 1944) is a Ugandan politician and retired senior military officer who has been the 9th and current President of Uganda since 26 January 1986. Museveni spearheaded rebellions with aid of then ...
, spying upon the Ugandan opposition party, the Forum for Democratic Change.


Reporters Without Borders

On 12 March 2013
Reporters Without Borders Reporters Without Borders (RWB; french: Reporters sans frontières; RSF) is an international non-profit and non-governmental organization with the stated aim of safeguarding the right to freedom of information. It describes its advocacy as found ...
named Gamma International as one of five "Corporate Enemies of the Internet" and “digital era mercenaries” for selling products that have been or are being used by governments to violate human rights and freedom of information. FinFisher technology was used in
Bahrain Bahrain ( ; ; ar, البحرين, al-Bahrayn, locally ), officially the Kingdom of Bahrain, ' is an island country in Western Asia. It is situated on the Persian Gulf, and comprises a small archipelago made up of 50 natural islands and a ...
and Reporters Without Borders, together with
Privacy International Privacy International (PI) is a UK-based registered charity that defends and promotes the right to privacy across the world. First formed in 1990, registered as a non-profit company in 2002 and as a charity in 2012, PI is based in London. Its ...
, the European Center for Constitutional and Human Rights (ECCHR), the
Bahrain Centre for Human Rights The Bahrain Centre for Human Rights (BCHR; ar, مركز البحرين لحقوق الإنسان) was a Bahraini non-profit non-governmental organisation which works to promote human rights in Bahrain,
, and Bahrain Watch filed an
Organisation for Economic Co-operation and Development The Organisation for Economic Co-operation and Development (OECD; french: Organisation de coopération et de développement économiques, ''OCDE'') is an intergovernmental organisation with 38 member countries, founded in 1961 to stimulate ...
(OECD) complaint, asking the National Contact Point in the United Kingdom to further investigate Gamma's possible involvement in Bahrain. Since then research has shown that FinFisher technology was used in Australia, Austria, Bahrain, Bangladesh, Britain, Brunei, Bulgaria, Canada, the Czech Republic, Estonia, Ethiopia, Germany, Hungary, India, Indonesia, Japan, Latvia, Lithuania, North Macedonia, Malaysia, Mexico, Mongolia, Netherlands, Nigeria, Pakistan, Panama, Qatar, Romania, Serbia, Singapore, South Africa, Turkey, Turkmenistan, the United Arab Emirates, the United States, Venezuela and Vietnam.


Firefox masquerading

FinFisher is capable of masquerading as other more legitimate programs, such as
Mozilla Firefox Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. It uses the Gecko rendering engine to display web pages, which implements current an ...
. On April 30, 2013,
Mozilla Mozilla (stylized as moz://a) is a free software community founded in 1998 by members of Netscape. The Mozilla community uses, develops, spreads and supports Mozilla products, thereby promoting exclusively free software and open standards, ...
announced that they had sent Gamma a cease-and-desist letter for trademark infringement. Gamma had created an espionage program that was entitled firefox.exe and even provided a version number and trademark claims to appear to be legitimate Firefox software.


Detection

In an article of ''
PC Magazine ''PC Magazine'' (shortened as ''PCMag'') is an American computer magazine published by Ziff Davis. A print edition was published from 1982 to January 2009. Publication of online editions started in late 1994 and have continued to the presen ...
'', Bill Marczak (member of Bahrain Watch and computer science PhD student at
University of California, Berkeley The University of California, Berkeley (UC Berkeley, Berkeley, Cal, or California) is a public land-grant research university in Berkeley, California. Established in 1868 as the University of California, it is the state's first land-grant un ...
doing research into FinFisher) said of FinSpy Mobile (Gamma's mobile spyware): "As we saw with respect to the desktop version of FinFisher, antivirus alone isn't enough, as it bypassed antivirus scans". The article's author Sara Yin, an analyst at ''PC Magazine'', predicted that antivirus providers are likely to have updated their signatures to detect FinSpy Mobile. According to announcements from ESET, FinFisher and FinSpy are detected by ESET antivirus software as "Win32/Belesak.D" trojan. Other security vendors claim that their products will block any spyware they know about and can detect (regardless of who may have launched it), and Eugene Kaspersky, head of IT security company
Kaspersky Lab Kaspersky Lab (; Russian: Лаборатория Касперского, tr. ''Laboratoriya Kasperskogo'') is a Russian multinational cybersecurity and anti-virus provider headquartered in Moscow, Russia, and operated by a holding company i ...
, stated, "We detect all malware regardless its purpose and origin". Two years after that statement by Eugene Kaspersky in 2012 a description of the technique used by FinFisher to evade Kaspersky protection was published in Part 2 of the relevant blog at Code And Security. FinFisher has also made headlines in the past because its products were found to be used by authoritarian regimes against opponents in several Middle Eastern countries.


See also


References


External links

* {{Malware Computer security software Spyware Computer surveillance Trojan horses Espionage techniques Espionage devices Malware toolkits 2012 in computing Computer access control Cyberwarfare Espionage scandals and incidents Content-control software