Current:Home > FinanceResearchers discover attempt to infect leading Egyptian opposition politician with Predator spyware -FinanceAcademy
Researchers discover attempt to infect leading Egyptian opposition politician with Predator spyware
View
Date:2025-04-21 05:32:35
BOSTON (AP) — A leading Egyptian opposition politician was targeted with spyware after announcing a presidential bid, security researchers reported Friday. They said Egyptian authorities were likely behind the attempted hack.
Discovery of the attempt last week by researchers at Citizen Lab and Google’s Threat Analysis Group prompted Apple to rush out operating system updates for iPhones, iPads, Mac computers and Apple Watches to patch the associated vulnerabilities.
Citizen Lab said in a blog post that recent attempts to hack former Egyptian lawmaker Ahmed Altantawy involved configuring his connection to the Vodaphone Egypt mobile network to automatically infect his devices with the Predator spyware if he visited certain websites not using the secure HTTPS protocol.
Bill Marczak, the researcher involved at the University of Toronto-based internet watchdog, declined to provide more detail on how he and Google researcher Maddie Stone discovered the spyware exploit chain, which he said was sent to Altantawy’s phone via SMS and WhatsApp links from Egyptian soil.
Once infected, the Predator spyware turns a smartphone into a remote eavesdropping device and lets the attacker siphon off data.
“It’s scary the fact that the government can essentially select anyone on Vodafone Egypt’s network and perhaps other networks for infections and they just flip a switch” and select them for targeting, he said. Marczak said “the most likely scenario here is that, yes, there is this cooperation from from Vodafone.”
Altantawy did not immediately respond to a request for comment on being targeted by the alleged spyware, nor did Egyptian officials.
Citizen Lab had previously identified Egypt as a customer of Predator’s maker, Cytrox, and determined that Altantawy’s phone was successfully hacked with it in 2021 in a separate incident.
Citizen Lab also previously documented Predator infections affecting two exiled Egyptians, and in a joint probe with Facebook determined that Cytrox had customers in countries including Armenia, Greece, Indonesia, Madagascar, Oman, Saudi Arabia and Serbia.
Altantawy, a former journalist and lawmaker, announced in March his bid to challenge incumbent President Abdel Fatah el-Sissi in 2024, who has overseen a sharp crackdown on political opposition. Rights groups accuse el-Sissi’s administration of targeting dissent with brutal tactics — forced disappearances, torture and long-term detentions without trial.
Altantawy, family members and supporters have complained of being harrassed, which led him to ask Citizen Lab researchers to analyze his phone for potential spyware infection.
“We didn’t see any evidence of a successful hack, but we did note that he had (the phone) in lockdown mode,” said Marczak.
Apple offers lockdown mode for iPhone users at high risk of being targeted with spyware, who include human rights activists, journalists and opposition politicians in countries like Egypt.
In July, the U.S. added Predator’s maker, Cytrox, to its blacklist for developing surveillance tools deemed to have threatened U.S. national security as well as individuals and organizations worldwide. That makes it illegal for U.S. companies to do business with them. Israel NSO Group, maker of the Pegasus spyware, was similarly sanctions in November 2021. The reported use of Predator in Greece helped precipitate the resignation last year of two top government officials, including the national intelligence director.
The latest discovery brings to five the number of zero-day vulnerabilities to Apple software for which patches have been released this month.
——-
AP reporter Maggie Hyde in Cairo contributed.
veryGood! (52)
Related
- Friday the 13th luck? 13 past Mega Millions jackpot wins in December. See top 10 lottery prizes
- The definitive ranking of all 28 Pixar movies (including 'Inside Out 2')
- 2 men die after falling into manure tanker in upstate New York
- Watch Georgia man's narrow escape before train crashes into his truck
- IRS recovers $4.7 billion in back taxes and braces for cuts with Trump and GOP in power
- See Savannah Guthrie's Son Adorably Crash the Today Show Set With Surprise Visit
- WWE Clash at the Castle 2024: Time, how to watch, match card and more
- Trump has strong views on abortion pill. Could he limit access if he wins 2024 election?
- Jamie Foxx reps say actor was hit in face by a glass at birthday dinner, needed stitches
- Virginia's Lake Anna being tested after swimmers report E. coli infections, hospitalizations
Ranking
- Which apps offer encrypted messaging? How to switch and what to know after feds’ warning
- Move over grizzlies and wolves: Yellowstone visitors hope to catch a glimpse of rare white buffalo
- Kaitlyn Bristowe Says She's Working Through Held On Anger Amid Ex Jason Tartick's New Romance
- Takeaways from Supreme Court ruling: Abortion pill still available but opponents say fight not over
- Why Sean "Diddy" Combs Is Being Given a Laptop in Jail Amid Witness Intimidation Fears
- Kylie Kelce Weighs in on Harrison Butker's Controversial Commencement Speech
- Tom Brady’s Kids Jack, Benjamin and Vivian Look All Grown Up in Family Photos
- U.S. customs officer accused of letting drug-filled cars enter from Mexico, spending bribe money on gifts, strip clubs
Recommendation
New data highlights 'achievement gap' for students in the US
Southwest Airlines Boeing 737 Max goes into Dutch roll during Phoenix-to-Oakland flight
Missing Bonnaroo 2024? See full livestream schedule, where to stream the festival live
Former Nashville officer arrested after allegedly participating in an adult video while on duty
Megan Fox's ex Brian Austin Green tells Machine Gun Kelly to 'grow up'
Starbucks introduces value meals with new 'Pairings Menu'
Deadliest Catch Star Nick Mavar Dead at 59 in Medical Emergency
Deadliest Catch Star Nick Mavar Dead at 59 in Medical Emergency