Thursday, December 7, 2017

EVIDENCE THAT ETHIOPIA IS SPYING ON JOURNALISTS SHOWS COMMERCIAL SPYWARE IS OUT OF CONTROL

THROUGHOUT 2016 AND 2017, individuals in Canada, United States, Germany, Norway, United Kingdom, and numerous other countries began to receive suspicious emails. It wasn’t just common spam. These people were chosen.
The emails were specifically designed to entice each individual to click a malicious link. Had the targets done so, their internet connections would have been hijacked and surreptitiously directed to servers laden with malware designed by a surveillance company in Israel. The spies who contracted the Israeli company’s services would have been able to monitor everything those targets did on their devices, including remotely activating the camera and microphone.
Who was behind this global cyber espionage campaign? Was it the National Security Agency? Or one of its “five eyes” partners, like the GCHQ or Canada’s CSE? Given that it was done using Israeli-made technology, perhaps it was Israel’s elite signals intelligence agency, Unit 8200?
In fact, it was none of them. Behind this sophisticated international spying operation was one of the poorest countries in the world; a country where less than 5 percentof the population has access to the internet; a country run by an autocratic government routinely flagged for human rights abuses and corruption. Behind this operation was… Ethiopia.
The details of this remarkable clandestine activity are outlined in a new Citizen Lab report published today entitled “Champing at the Cyberbit." In our report my co-authors and I detail how we monitored the command and control servers used in the campaign and in doing so discovered a public log file that the operators mistakenly left open. That log file provided us with a window, for roughly a year, into the attackers’ activities, infrastructure, and operations. Strong circumstantial evidence points to one or more government agencies in Ethiopia as the responsible party.
We were also able to identify the IP addresses of those who were targeted and successfully infected: a group that includes journalists, a lawyer, activists, and academics. Our access also allowed us enumerate the countries in which the targets were located. Many of the countries in which the targets live—the United States, Canada, and Germany, among others—have strict wiretapping laws that make it illegal to eavesdrop without a warrant. It seems individuals in Ethiopia broke those laws.
If a government wants to collect evidence on a person in another country, it is customary for it to make a formal legal request to other governments through a process like the Mutual Legal Assistance Treaties. Ethiopia appears to have sidestepped all of that. International norms would suggest a formal démarche to Ethiopia from the governments whose citizens it monitored without permission, but that may happen quietly if at all.
Our team reverse-engineered the malware used in this instance, and over time this allowed us to positively identify the company whose spyware was being employed by Ethiopia: Cyberbit Solutions, a subsidiary of the Israel-based homeland security company Elbit Systems. Notably, Cyberbit is the fourth company we have identified, alongside Hacking TeamFinfisher, and NSO Group, whose products and services have been abused by autocratic regimes to target dissidents, journalists, and others. Along with NSO Group, it’s the second Israel-based company whose technology has been used in this way.
Israel does regulate the export of commercial spyware abroad, although apparently not very well from a human-rights perspective. Cyberbit was able to sell its services to Ethiopia—a country with not only a well-documented history of governance and human rights problems, but also a track record of abusing spyware. When considered alongside the extensive reporting we have done about UAE and Mexican government misuse of NSO Group’s services, it’s safe to conclude Israel has a commercial spyware control problem.
How big of a problem? Remarkably, by analyzing the command and control servers of the cyber espionage campaign, we were also able to monitor Cyberbit employees as they traveled the world with infected laptops that checked in to those servers, apparently demonstrating Cyberbit’s products to prospective clients. Those clients include the Royal Thai Army, Uzbekistan's National Security Service, Zambia's Financial Intelligence Centre, and the Philippine president's Malacañang Palace. Outlining the human rights abuses associated with those government entities would fill volumes.
Cyberbit, for its part, has responded to Citizen Lab’s findings: “Cyberbit Solutions offers its products only to sovereign governmental authorities and law enforcement agencies,” the company wrote me on November 29. “Such governmental authorities and law enforcement agencies are responsible to ensure that they are legally authorized to use the products in their jurisdictions.“ The company declined to confirm or deny that the government of Ethiopia is a client, but did note that “Cyberbit Solutions can confirm that any transaction made by it was approved by the competent authorities.”
Governments like Ethiopia no longer depend on their own in-country advanced computer science, engineering, and mathematical capacity in order to build a globe-spanning cyber espionage operation. They can simply buy it off the shelf from a company like Cyberbit. Thanks to companies like these, an autocrat whose country has poor national infrastructure but whose regime has billions of dollars can order up their own NSA. To wit: Elbit Systems, the parent company of Cyberbit, says it has a backlog of orders valuing $7 billion. An investment firm recently sought to acquire a partial stake in NSO Group for a reported $400 million before eventually withdrawing its offer.
Of course, these companies insist that spyware they sell to governments is used exclusively to fight terrorists and investigate crime. Sounds reasonable, and no doubt many do just that. But the problem is when journalists, academics, or NGOs seek to expose corrupt dictators or hold them accountable, those truth tellers may then be labelled criminals or terrorists. And our research has shown that makes those individuals and groups vulnerable to this type of state surveillance, even if they live abroad.
Indeed, we discovered the second-largest concentration of successful infections of this Ethiopian operation are located in Canada. Among the targets whose identities we were able to verify and name in the report, what unites them all is their peaceful political opposition to the Ethiopian government. Except one. Astoundingly, Citizen Lab researcher Bill Marczak, who led our technical investigation, was himself targeted at one point by the espionage operators.
Countries sliding into authoritarianism and corruption. A booming and largely unregulated market for sophisticated surveillance. Civilians not equipped to defend themselves. Add these ingredients together, and you have a serious crisis of democracy brewing. Companies like Cyberbit market themselves as part of a solution to cyber security. But it is evident that commercial spyware is actually contributing to a very deep insecurity instead.
Remedying this problem will not be easy. It will require legal and policy efforts across multiple jurisdictions and involving governments, civil society, and the private sector. A companion piece to the report outlines some measures that could hopefully begin that process, including application of relevant criminal laws. If the international community does not act swiftly, journalists, activists, lawyers, and human rights defenders will be increasingly infiltrated and neutralized. It’s time to address the commercial spyware industry for what it has become: one of the most dangerous cyber security problems of our day. Read more here

No comments:

Post a Comment

Related Posts Plugin for WordPress, Blogger...

Recent Articles

  • Ethiopian Health Professionals Association Urges Govt to Promptly Respond to Health Workers' Demands Amid Pre-Strike Demonstrations
     Dagmawi Melnilik Hospital, which was later upgraded to a referral hospital, is the nation’s first hospital, built in 1909.Addis Standard (Addis Ababa)As health professionals across Ethiopia stage pre-strike demonstrations demanding improved salaries, benefits, and working conditions, the...
    May-13 - 2025 | More »
  • Commentary: Why Ethiopian university lecturers' strike failed: A cautionary tale for health professionals
     The moment of release of the detained teachers’ coordinators, greeted by fellow teachers awaiting their return. Photo: Provided by the writerIn 2022, Ethiopian university lecturers launched a year-long social media campaign  and subsequent threat for indefinite...
    May-13 - 2025 | More »
  • ሰባት ኢትዮጵያውያን ስደተኞችን ወደ ባሕሩ ጣሏቸው'፡ ትኩረት ያላገኘው የስደት መንገድ
     መሐመድ አብዱላሂ ሞሐሙድ 35 ዓመቱ ነው።ከጂቡቲ ወደ የመን በጀልባ ያደረገውን የስደት ጉዞ አይረሳውም። በ20ዎቹ ዕድሜ ሳለ ነበር የተሰደደው።ሶማሊያን ጥሎ የወጣው የተሻለ ሕይወት ፍለጋ ነበር።ከአፍሪካ ወደ የመን የሚደረገው ስደተኞች የሚጓዙበት መንገድ 'ምሥራቃዊው ኮሪደር' በሚል ይታወቃል።በብዛት ስደተኞች ከሚጓዙባቸው መንገዶች አንደኛው ነው። እምብዛም ግን ትኩረት አላገኘም።ይህ መንገድ በጣም አደገኛው እንደሆነም መሐመድ ይናገራል።"መንገድ ጀምረን 30 ደቂቃ...
    May-08 - 2025 | More »
  • ሐኪም በመሆኔ ያተረፍኩት ድኅነትን ነው" የኢትዮጵያ ጤና ባለሙያዎች እሮሮ እና ጥያቄ
     የደሞዝ እና የጥቅማ ጥቅም ጥያቄ ያነሱ የጤና ባለሙያዎች መንግሥት ለጥያቄዎቻቸው ምላሽ የማይሰጥ ከሆነ የሥራ ማቆም አድማ እንደሚመቱ ተናገሩ።ባለሙያዎቹ ጥያቄዎቻቸውን ለመንግሥት ማቅረባቸውን የተናገሩ ሲሆን፤ ምላሽ እንዲሰጣቸውም የ30 ቀናት ቀነ ገደብ ከሰጡ ሳምንታት ተቆጥረዋል።የጤና ባለሙያዎቹ "መኖር አቅቶናል" ያሉ ሲሆን፤ በተለያዩ መንገዶች ድምፃቸውን እያሰሙ ነው።ሐኪም ለመሆን 23 ዓመታትን በትምህርት እንዳሳለፉ ለቢቢሲ የተናገሩት ዶ/ር ይማም እንድሪስ...
    May-08 - 2025 | More »
  • በአዳማ ከተማ እየተካሄደ ነው ስለሚባለው 'አፈሳ' የነዋሪዎች ስጋት
     ከሁለት ሳምንት በፊት ጀምሮ በኦሮሚያ የተለያዩ አካባቢዎች ወጣቶች ከመንገድ እየታፈሱመሆናቸውን ወላጆች፣ ወጣቶች እና ፖለቲከኞች በተለያዩ ማኅበራዊ ሚዲያዎች ላይ እየገለፁ ነው።ቢቢሲ ያነጋገራቸው የከተማ ነዋሪዎችም በግዳጅ የታፈሱ ወጣቶችን እንደሚያውቁ እና እነርሱም ባለባቸው ስጋት የተነሳ ድንገት ከተያዝን በሚል "ገንዘብ ይዘው እንደሚንቀሳቀሱ" ተናግረዋል።ቢቢሲ ከአዲስ አበባ አንድ መቶ ኪሎ ሜትር ያህል ርቃ በምትገኘው በአዳማ ከተማ የሚገኝ እና ከመንገድ ላይ...
    May-05 - 2025 | More »
  • ሰባት ኢትዮጵያውያን ስደተኞችን ወደ ባሕሩ ጣሏቸው'፡ ትኩረት ያላገኘው የስደት መንገድ
     መሐመድ አብዱላሂ ሞሐሙድ 35 ዓመቱ ነው።ከጂቡቲ ወደ የመን በጀልባ ያደረገውን የስደት ጉዞ አይረሳውም። በ20ዎቹ ዕድሜ ሳለ ነበር የተሰደደው።ሶማሊያን ጥሎ የወጣው የተሻለ ሕይወት ፍለጋ ነበር።ከአፍሪካ ወደ የመን የሚደረገው ስደተኞች የሚጓዙበት መንገድ 'ምሥራቃዊው ኮሪደር' በሚል ይታወቃል።በብዛት ስደተኞች ከሚጓዙባቸው መንገዶች አንደኛው ነው። እምብዛም ግን ትኩረት አላገኘም።ይህ መንገድ በጣም አደገኛው እንደሆነም መሐመድ ይናገራል።"መንገድ ጀምረን 30 ደቂቃ...
    May-05 - 2025 | More »
  • Ethiopia’s civil war: what’s behind the Amhara rebellion?
     Ethiopia is in the grip of a civil war between federal government forces and the Fano, a loose alliance of ethnic-based militia in the Amhara region.This conflict in Ethiopia’s north erupted less than a year after the devastating Tigray war, which ended in...
    Apr-28 - 2025 | More »
  • በቀን ከ14 ሺህ ቶን በላይ የዓሣ ምርት ከታላቁ የኢትዮጵያ ሕዳሴ ግድብ እየተመረተ ነው!
     በቀን ከ14 ሺህ ቶን በላይ የዓሣ ምርት ከታላቁ የኢትዮጵያ ሕዳሴ ግድብ እየተመረተ ነው!ከታላቁ የኢትዮጵያ ሕዳሴ ግድብ በቀን ከ14 ሺህ ቶን በላይ የዓሣ ምርት የሚገኝበት አቅም መፈጠሩን በግብርና ሚኒስቴር ዓሣ ሀብት ልማት ዴስክ ሃላፊ ዶክተር ፋሲል ዳዊት ገለጹ። ኢትዮጵያ እምቅ የዓሣ ሀብት ቢኖራትም በተለያዩ ተግዳሮቶች ምክንያት በዘርፉ ተጠቃሚ ሳትሆን መቆየቷን በግብርና ሚኒስቴር ዓሣ ሀብት ልማት ዴስክ ሃላፊ ዶክተር ፋሲል ዳዊት ተናግረዋል። በሀገር ደረጃ...
    Mar-26 - 2025 | More »
  • የአፍሪካ ህብረት ኮሚሽን ሊቀመንበር ደፋር ማሻሻያዎችን እና አፍሪካን የሚመሩ መፍትሄዎችን ከፒአርሲ ጋር የመጀመሪያ ስብሰባ ላይ አሳሰቡ!
     የአፍሪካ ህብረት ኮሚሽን ሊቀመንበር ደፋር ማሻሻያዎችን እና አፍሪካን የሚመሩ መፍትሄዎችን ከፒአርሲ ጋር የመጀመሪያ ስብሰባ ላይ አሳሰቡ!የመጀመርያው የቋሚ ተወካዮች ኮሚቴ (PRC) እና አዲስ የተሾሙት የአፍሪካ ህብረት ኮሚሽን አመራር አባላት ዛሬ በአዲስ አበባ ተካሂደዋል። ስብሰባውን በኤች.ኢ. ማህሙድ አሊ የሱፍ፣ የAUC ሊቀመንበር እና ኤች.ኢ. በአፍሪካ ህብረት የአንጎላ ሪፐብሊክ ቋሚ ተወካይ እና የፒአርሲ ሊቀመንበር አምባሳደር ፕሮፌሰር ሚጌል ሴሳር...
    Mar-18 - 2025 | More »
  • ፀሐይ ባለበት የቫይታሚን D እጥረት ለምን?
     ለሰውነታችን ጠቃሚ የሆነው ቫይታሚን ዲ የሚገኘው በፀሐይ ጨረር አማካኝነት በተፈጥሮ ሂደት ነው። ኢትዮጵያ ዓመቱን ሙሉ የፀሐይ ብርሃንና ሙቀት የምታገኝ ሀገር ብትሆንም በቅርቡ የወጣ መረጃ ብዙዎች የቫይታሚን ዲ እጥረት እንዳለባቸው  ያመለክታል። ለምን ይሆን?ቫይታሚን ዲየቫይታሚን ዲ እጥረት በመላው ዓለም ሰዎች ላይ ስለሚታይ አሳሳቢ መሆኑ ይነገራል። በተለይ በዓመት ውስጥ የፀሐይ ብርሃንም ሆነ ሙቀቷን በውስን ወራት ብቻ በሚያገኙ የሰሜኑ ንፍቀ ክበብ...
    Mar-18 - 2025 | More »
  • "እንደ አሮጌ ምንጣፍ የተጣለ" - የቻይና መንግሥት ጋዜጣ የቪኦኤ በጀት እንዲቋረጥ መወሰኑን አወደሰ!
     የቻይና መንግሥት ጋዜጣ የአሜሪካው ፕሬዝንት ዶናልድ ትራምፕ የአሜሪካ ድምፅ (ቪኦኤ) በጀት እንዲቋረጥ መወሰናቸውን አወደሰ።የአሜሪካ ድምፅ (ቪኦኤ) እና ራድዮ ፍሪ እስያ (አርኤፍኤ) በቻይና መንግሥት ዙሪያ ለዓመታት ሲዘግቡ የቆዩ ሲሆን ትራምፕ የጣቢያዎቹ በጀት እንዲቀነስ ወስነዋል።ውሳኔው የተላለፈው ባለፈው አርብ ነው። 1300 የቪኦኤ ሠራተኞች በግዴታ እረፍት እንዲወጡ ተነግሯቸዋል።ተቺዎች ውሳኔው ዲሞክራሲን ወደኋላ የሚጎትት ነው ቢሉም ግሎባል ታይምስ...
    Mar-18 - 2025 | More »
  • Killings, abductions, funding shortfalls stifle WFP relief efforts across Ethiopia!
     Killings, abductions, funding shortfalls stifle WFP relief efforts across Ethiopia!Eight personnel dead as org. takes USD 30mln loan to sustain operationsThe World Food Program says security concerns are straining its ability to deliver crucial aid assistance in Ethiopia as no less than eight...
    Sept-15 - 2024 | More »
  • Ethiopia : Dialogue Commission wants gov’t to create “enabling condition
     Professor Mesfin Araya, Chief of the Dialogue Commission (Photo credit : DW Amharic)The National Dialogue Commission on Thursday presented its performance report to the parliament. Unusual about it was that this meeting took place in a hotel, not at the parliament building. The practice...
    June-30 - 2024 | More »
  • Struggles of High-Rise Living
     Located on the western outskirts of AddisAbaba, the Asko 40/60 condominium towers stand tall, promising a modern lifestyle but delivering a daily ordeal for its residents. Among them is Melat Kasa, a pregnant mother of two young children aged 4 and 6, who lives on the 13th floor. “I’ve been...
    June-30 - 2024 | More »
  • TPLF regains political legitimacy with Justice Ministry’s blessing
     NewsTPLF regains political legitimacy with Justice Ministry’s blessingThe Ministry of Justice has granted the Tigray People’s Liberation Front (TPLF) the green light to register with the National Election Board of Ethiopia (NEBE) as a political party.Heads of the NEBE were informed of the...
    June-29 - 2024 | More »
  • A father who lost 2 sons in a Boeing Max crash waits to hear if the US will prosecute the company
     Ike Riffel fears that instead of putting Boeing on trial, the government will offer the company another shot at corporate probationPhoto by: Jim Young/APProtesters hold photographs of victims of the 2019 Boeing Ethiopian Airlines crash, including Melvin Riffel, left.By: AP via Scripps...
    June-29 - 2024 | More »
  • Ethiopia’s dam fills threaten Egypt’s lifeline: Calls for international intervention
     Adel Sadawi, a member of the Egyptian Council for Foreign Affairs and former Dean of the Institute for Research and Strategic Studies on Nile Basin Countries, commented on Ethiopia’s announcement of its readiness to carry out the fifth filling of the Grand Ethiopian Renaissance...
    June-29 - 2024 | More »
  • Fashion event brings Kanu, others to Ethiopia
     Former Nigerian national football team striker Nwankwo Kanu and other African former football players are in Addis Ababa to participate in the Shenen Africa Fashion Festival Week 2024Upon arrival at the Addis Ababa Bole International Airport, on Thursday Kanu was welcomed by Ethiopia’s...
    June-29 - 2024 | More »
  • Economic, conflict spurring human trafficking in Ethiopia: US State Department
     NewsEconomic, conflict spurring human trafficking in Ethiopia: US State DepartmentYemeni Houthis forcing Ethiopian migrants into military serviceThe US Department of State commends the Ethiopian government’s efforts to combat human trafficking but urges that more needs to be done to eliminate...
    June-29 - 2024 | More »
  • Ethiopian gov’t forces killed 27 civilians in the Amhara region
     Ethiopian gov’t forces killed 27 civilians in the Amhara regionEthiopian government forces this week reportedly killed 27 civilians, in two separate incidents,  in a latest string of extrajudicial killings in the Amhara region of Ethiopia.  The forces allegedly carried it out in a...
    June-29 - 2024 | More »

Recent Video Uploads

Subscribe Ethiopia Today Videos and Watch on You Tube

Ethiopia Today

  • Active a minute ago with many
  •  
  •  videos
Ethiopia Today bringing you recent information about Ethiopia. It bring you, news, Amharic movies,  Musics and many clips. subscribe and get many Videos on time