New campaigns featuring FinFisher are underway with new infection enablers: internet service providers (ISPs), researchers at ESET warned. FinFisher, sometimes called FinSpy, is a well-known spyware program that has been used by nation-states to spy on citizens.

Spying Automatically via ISPs

FinFisher is a tool specifically designed to have the stealthy spy capabilities that George Orwell might understand. According to ESET’s blog, We Live Security, the spyware can perform live subject surveillance through the use of a computer’s webcam and microphone, keylogging of typed input and exfiltration of files. While FinFisher has been marketed as a way for authorities to monitor the bad guys, certain regimes have used it to gather information about people of interest to them.

ESET said that its security experts found FinFisher variants present in seven countries. It did not say in which countries they were found, however.

Along with this, the researchers were alarmed to see that a previously undetected method was used for infection in two of these countries: a man-in-the-middle (MitM) attack that involved ISPs. If a specific user requests certain apps — typically WhatsApp, Skype, Avast, WinRAR and VLC Player — the link request is replaced with an HTTP 307 Temporary Redirect status response code.

Replacing the normal link with a malicious one is something that would be relatively simple for an ISP to do if it was given a list of targets by authorities. The use of an HTTP 307 call is also invisible to the user, making it difficult to detect.

Suspicious Similarities

SecurityWeek recalled that leaked documents regarding Finfisher’s initial purveyor, Gamma Group, showed the existence of a tool called FinFly ISP that was designed for deployment on ISP networks. This tool had the ability to perform these kinds of MitM attacks.

ESET further noted that all of the affected targets in this campaign that were within a particular country were found to use the same ISP. Not only that, but the same redirection method and format had been previously used by other ISPs to modify internet content in at least one of the countries involved in this attack.

Using ISPs to infect and spy on users has never been revealed until now. These kinds of campaigns would represent what ESET called a “sophisticated and stealthy surveillance project unprecedented in its combination of methods and reach.”

More from

More School Closings Coast-to-Coast Due to Ransomware

Instead of snow days, students now get cyber days off. Cyberattacks are affecting school districts of all sizes from coast-to-coast. Some schools even completely shut down due to the attacks. The federal government recently warned that K-12 schools face a growing threat from cyber groups. According to the FBI, school districts often have limited cybersecurity protections, which makes them even more vulnerable. The FBI also says it anticipates the number of threats to increase. In a recent warning, the nation’s…

The Role of Human Resources in Cybersecurity

The human resources (HR) department is an integral part of an organization. They work with all departments with a wider reach than even IT. As a highly visible department, HR can support and improve an organization’s security posture through employee training. Their access to employees at the start of employment is an opportunity to lay a foundation for a culture of risk awareness. HR departments do not typically include cybersecurity risk awareness training with new hire onboarding, but it’s something…

New Attack Targets Online Customer Service Channels

An unknown attacker group is targeting customer service agents at gambling and gaming companies with a new malware effort. Known as IceBreaker, the code is capable of stealing passwords and cookies, exfiltrating files, taking screenshots and running custom VBS scripts. While these are fairly standard functions, what sets IceBreaker apart is its infection vector. Malicious actors are leveraging the helpful nature of customer service agents to deliver their payload and drive the infection process. Here’s a look at how IceBreaker…

Operational Technology: The evolving threats that might shift regulatory policy

Listen to this podcast on Apple Podcasts, Spotify or wherever you find your favorite audio content. Attacks on Operational Technology (OT) and Industrial Control Systems (ICS) grabbed the headlines more often in 2022 — a direct result of Russia’s invasion of Ukraine sparking a growing willingness on behalf of criminals to target the ICS of critical infrastructure. Conversations about what could happen if these kinds of systems were compromised were once relegated to “what ifs” and disaster movie scripts. But those days are…