Armour Comms launches industry leading secure Grou... » London: In direct response to customer demand, Armour Communications has announced the availability ... TDSi Supports Education Programme at IFSEC Inter... » Poole: Integrated security manufacturer TDSi will be sponsoring the Tavcom Training Theatre at IFSEC... 'POWER PLAYERS' INITIATIVE OPENS TO ENTRIES » Leading younger people from across the engineering services sector have a new opportunity to be reco... Multitone launches comprehensive EkoCare Communi... » Multitone Electronics plc has announced the launch of its new EkoCare range for healthcare facilitie... Momentum builds as Critical Communications World d... » Critical Communications World (May 16-18, Hong Kong) is the leading and most influential congress an... New initiative shows increasing importance of CSR » A major new survey on corporate social responsibility (CSR) is now open to electrotechnical busine... OF FOOLS OF THE MIDDLE BELT, ONE NORTH AND PASTORA... » SERIES: BUHARISM AND THE FIERCE URGENCY OF NOW A treatise on pastoral jihadism, islamism, arabism a... Commvault partners with Pure Storage » Cisco Live, Melbourne, AU and Tinton Falls, NJ: Commvault has announced the integration of its Commv... OF FOOLS OF THE MIDDLE BELT, ONE NORTH AND PASTOR... » A treatise on pastoral jihadism, islamism, arabism and cultural imperialism in Nigeria (Ephesians ... Where was Aisha Buhari when idiot Kumapayi flagr... » "Clip-clip..clip-clip...Did you not hear when BABA DAURA say women's place is in the kitchen?" ...



Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.


Case Studies

LONDON, UK: RiskIQ has revealed that its intelligence and external threat investigation system, RiskIQ PassiveTotal™, was a critical tool used by the interdisciplinary research group, The Citizen Lab, in the discovery of commercial spyware linked to NSO Group that targeted the mobile phones of United Arab Emirates (UAE) human rights activists.

“When we joined RiskIQ in 2015, we did so with the intent to improve critical research so analysts could more efficiently hunt digital threats and proactively defend their organisations,” said Brandon Dixon, vice president of product at RiskIQ and co-creator of PassiveTotal. “We design our products for situations exactly like this, but it is extremely rewarding to hear that we’ve influenced positive change in the fight for privacy and human rights.”

In an operation named “Stealth Falcon,” The Citizen Lab leveraged PassiveTotal’s broad array of internet data sets and advanced correlation technologies, querying a series of IP addresses used by threat actors targeting UAE human rights activists. A query returned a related domain, as well as an email address that differed from known Stealth Falcon infrastructure. Pivoting across relevant PassiveTotal data sets, The Citizen Lab connected the email and domain to a domain that was registered to NSO Group. Suspecting that these domains were part of an exploit delivery infrastructure, they began seeking evidence of messages containing links to the network.

Months later, renowned human rights defender, Ahmed Mansoor, one of the UAE Five, shared two text messages with The Citizen Lab containing links identified as part of the exploit infrastructure. The Citizen Lab was able to successfully trigger the exploit infrastructure to fire against a device and captured the payload. This led to the discovery of a remote jailbreak using a string of zero-days prompting worldwide attention and an iOS security update from Apple. Ultimately, using PassiveTotal, The Citizen Lab connected the domain registration information from an initial phishing e-mail to a range of other malicious and fake news websites.

"Analysts at The Citizen Lab have been using PassiveTotal in investigations since the very first beta of the platform in 2014. Tools like PassiveTotal help us punch above our weight. Its ease of use, rich data set, and ongoing evolution of its features make it an excellent tool for our research, and a benchmark that we compare other options against," said Masashi Crete-Nishihata, research manager, The Citizen Lab.