Hacking Team Hacked: Documents Show Company Sold Exploits And Spyware To UN-Blacklisted Governments
from the I-would-imagine-there-are-plenty-of-new-openings-on-its-appointment-calendar dept
Hacking Team -- purveyor of exploits and spyware to a variety of government agencies all over the world -- has been hacked. Late Sunday night, its Twitter account name was changed to "Hacked Team" and its bio to read:
Whoever's behind this (no group has claimed responsibility yet) has repurposed the official Hacking Team Twitter feed to send out screenshots of incriminating information it/they have uncovered. For those who want to take a look themselves, the liberated documents can be torrented. Here are two places the torrent file can be picked up. (CAUTION: Actual file is 400 GB, so use a robust client and check your drive[s] for free space…) [And, if those go down, I've also stashed the torrent file here.]
Developing ineffective, easy-to-pwn offensive technology to compromise the operations of the worldwide law enforcement and intelligence communities.
What has been exposed so far shows Hacking Team has been lying about its business partners. It claims to only sell to NATO partners and blacklists oppressive governments. But its "Customer" Wiki appears to show that it counts such countries as Kazakhstan, Sudan, Russia, Saudi Arabia, Egypt and Malaysia as partners.
Screenshots of emails accessed by Hacking Team's hackers show the company circumventing local regulations and restrictions on the export of exploits and spyware by using third-party resellers.
If you can't see/read the screenshot, here's the pertinent information. The email subject is "Remote Control Davinci System Into Nigeria." Underneath that is the proposed third-party process for sneaking Hacking Team's "Davinci" past import/export restrictions:
Commissions and meeting:Other screenshots further confirm Hacking Team's efforts in forbidden markets. One shows the company dealing with a "Sudan Citizen Lab request," suggesting its end user(s) are uncomfortable with the investigative activities CL is performing.
Being an Italian company, we are following the guidelines of our exterior ministry.
Understanding that this is an uncommon circumstance, this is what we are proposing:
HackingTeam will sell directly to your company and then TunsmosPetroleum will add its own mark up. The price you will purchase from us will include a discount on the list price as a compensation for the 1st meeting/demo in Milan and the training (in Milan as well) after the sale.
ACLU technologist Chris Soghoian has taken a look at the files and uncovered even more incriminating information, including Hacking Team's stonewalling of a UN investigation into its sales in Sudan. This investigation is the direct result of Citizen Lab's investigative work. According to the files viewed by Soghoian, Hacking Team has denied any "current sales relationship" with Sudan, at least in terms of selling the sort of weaponized software forbidden by multiple treaties and UN resolutions. It claimed the software isn't weaponized tech. The UN disagreed.
Your letter 1029 of 13 March 2015 also stated that the company did not consider the Remote Control Software to be a weapon, and therefore fell outside the parameters of the sanctions regime. The view of the Panel is that as such software is ideally suited to support military electronic intelligence (ELINT) operations it may potentially fall under the category of "military… equipment" or "assistance" related to prohibited items…There's still plenty more to be uncovered in the document dump. Soghoian has already uncovered a spreadsheet listing every government customer, along with revenue to date.
Whatever happens from here on out should prove very interesting. Hacking Team is in for the longest Monday ever.
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Filed Under: citizen lab, governments, hacking team, hacking tools, sudan, un
Companies: hacking team
Reader Comments
Subscribe: RSS
View by: Time | Thread
Oh sweet schadenfreude...
Can't wait for them to start screaming about how 'unfair' it is for their privacy to be violated like this, and how it's completely unacceptable, though I imagine given what's been revealed a little 'violation of privacy' is going to be the least of their worries soon.
[ link to this | view in thread ]
More problems for them
There's a moral here; no matter how smart you think you are, there's always someone smarter. Or maybe just more devious.
[ link to this | view in thread ]
Its just like how the US doesn't engage in economic espionage
[ link to this | view in thread ]
[ link to this | view in thread ]
Corrupted Torrent Files
[ link to this | view in thread ]
Re: Corrupted Torrent Files
[ link to this | view in thread ]
[ link to this | view in thread ]
Re: Oh sweet schadenfreude...
[ link to this | view in thread ]
Re:
[ link to this | view in thread ]
Re: Re: Corrupted Torrent Files
If one was motivated one could find a magnet link which will work.
There are reports that the Transmission client can handle the .torrent file.
[ link to this | view in thread ]
Re: Re: Oh sweet schadenfreude...
[ link to this | view in thread ]
Re:
Because those agencies have bought the same software from the same shady company.
[ link to this | view in thread ]
Governments who respect their citizens' rights should outright refuse to buy them and demand that such information be released to the public to have the flaws fixed.
[ link to this | view in thread ]
Re:
[ link to this | view in thread ]
Re:
[ link to this | view in thread ]
Re: Corrupted Torrent Files
[ link to this | view in thread ]
Re: Re:
Even though the US is a sure example of being better than most it never respected the citizens rights.
Liberty requires ETERNAL VIGILANCE! We have lost so many of them because those warning of the loss of liberty as freaks and tin foil hatters.
The slippery slope is not only very real, it is a zero day exploit!
[ link to this | view in thread ]
Re: Re: Re: Corrupted Torrent Files
...if I remember correctly.
[ link to this | view in thread ]
And the moral is...
[ link to this | view in thread ]
Re: Re:
My bad
[ link to this | view in thread ]
Obviously...
[ link to this | view in thread ]
Re: Oh sweet schadenfreude...
[ link to this | view in thread ]
Arresto!
There's no realistic chance “Hacking Team” will find themselves arrested, is there?
[ link to this | view in thread ]
magnet:?xt=urn:btih:51603bff88e 0a1b3bad3962614978929c9d26955&dn=Hacked%20Team&tr=udp%3A%2F%2Fcoppersurfer.tk%3A6969%2Fannou nce&tr=udp%3A%2F%2F9.rarbg.me%3A2710%2Fannounce&tr=http%3A%2F%2Fmgtracker.org%3A2710%2Fannou nce&tr=http%3A%2F%2Fbt.careland.com.cn%3A6969%2Fannounce&tr=udp%3A%2F%2Fopen.demonii.com%3A1 337&tr=udp%3A%2F%2Fexodus.desync.com%3A6969&tr=udp%3A%2F%2Ftracker.leechers-paradise.org%3A6 969&tr=udp%3A%2F%2Ftracker.pomf.se&tr=udp%3A%2F%2Ftracker.blackunicorn.xyz%3A6969
[ link to this | view in thread ]
You know the maxim
[ link to this | view in thread ]
Re: Working torrent file
[ link to this | view in thread ]
Re: You know the maxim
I don't have a good "pen only" maxim, but I do know that there's a kindly anonymous hacker out there whose pen is much bigger than Hacking Team's pen is.
[ link to this | view in thread ]
https://github.com/hackedteam
Yes they contain working 0days, this one came with a nice readme!
https://twitter.com/w3bd3vil/status/618168863708962816
https://github.com/hackedteam/vector-ex ploit/blob/master/src/flash-0day-vitaly2/read%20me.txt
[ link to this | view in thread ]
Re:
[ link to this | view in thread ]
[ link to this | view in thread ]
[ link to this | view in thread ]
Re: Re: You know the maxim
[ link to this | view in thread ]
Predictions are fun
Hacking Team has friends in almost every government on earth, since they've been assisting almost every government on earth in the process of spying on almost everyone else on earth.
They have just been exposed (by an unknown party), of working for everyone, while pretending to work only for the "designated good guys" on both sides of the line at once.
How does a company deal with such a dilemma?
Answer: Name Change!
"Hacking Team" becomes - oh I dunno - "Sunfallow Excursions" and carries on as usual from its shiny new offices in the Bahamas, without missing a beat.
After all, what government wants to charge such a group with a punishable crime and become the only government on earth not being serviced by that company and its wonderful surveillance toys?
Answer: None of them.
Thus, Hacking Team will be given a large sum of money by a large number of governments, to relocate and change their name and carry on with business as usual, with an even bigger budget and a better location.
Just a guess. :)
---
[ link to this | view in thread ]
Re: Arresto!
Arrested as in Incarcerated. No.
Remember who these people work for.
Almost every government on earth.
That some serious friends in high places.
---
[ link to this | view in thread ]