Donncha Ó Cearbhaill Profile Banner
Donncha Ó Cearbhaill Profile
Donncha Ó Cearbhaill

@DonnchaC

5,060
Followers
4,955
Following
95
Media
4,254
Statuses

Head of Security Lab at @AmnestyTech - Hunting spyware and unlawful surveillance targeting civil society (He/Him) - Fedi: @donncha @donncha .is

Berlin
Joined September 2011
Don't wanna be here? Send us removal request.
Pinned Tweet
@DonnchaC
Donncha Ó Cearbhaill
1 year
Our team @AmnestyTech is available to support journalists and activists who are concerned about targeted spyware attacks. Please reach out if concerned and share widely with individuals in your networks who may be at risk.
@AmnestyTech
Amnesty Tech
2 years
The mercenary spyware industry is threatening rights defenders and journalists worldwide. Our experts @AmnestyTech can check devices for signs of spyware 🔍. Contact share @amnesty .tech if you're concerned, or if yourself or a colleague has received an attack notification
2
82
105
3
147
182
@DonnchaC
Donncha Ó Cearbhaill
2 years
Super proud of our team at @AmnestyTech and everyone who helped in this investigation. Today, Apple published an emergency update for all iPhones to patch an exploit chain which we, together with @_clem1 (Google TAG) discovered in the wild.
Tweet media one
Tweet media two
13
163
447
@DonnchaC
Donncha Ó Cearbhaill
2 years
NEW RESEARCH: Watch how NSO Group's zero-click attacks have evolved over recent years. Joint research by @AmnestyTech and @billmarczak ( @citizenlab ) presented at @VirusBtn . Exploit archaeology: A forensic history of in-the-wild NSO Group exploits
6
130
352
@DonnchaC
Donncha Ó Cearbhaill
8 years
Reliably compromising Ubuntu desktops by attacking the crash reporter
Tweet media one
8
237
240
@DonnchaC
Donncha Ó Cearbhaill
2 years
The "Guacamaya" hacktivist collective has leaked terabytes of emails from state-owned and private extractivist companies in Latin America, aiming to expose the environmental damage caused by this industry. 🧵
@Mxynyx
emma best @[email protected] 🏳️‍🌈🏴
2 years
NEW: #DDoSecrets and #EnlaceHacktivista are simultaneously publishing #ExtractivistLeaks , the latest from Guacamaya (who previously exposed #MiningSecrets ), exposing mining and oil companies and their enablers in #Brazil , #Chile , #Colombia , #Ecuador , #Guatemala and #Venezuela
3
80
252
4
57
224
@DonnchaC
Donncha Ó Cearbhaill
2 years
PERSONAL NEWS: After a six-month sabbatical, I'm very excited to re-join @AmnestyTech to lead the incredible researchers at our Security Lab. Over the next months we'll expand our team of technologists to help civil society fight back against the global spyware industry!
12
8
228
@DonnchaC
Donncha Ó Cearbhaill
1 year
🚨BREAKING: “Predator Files” investigation reveals catastrophic failure to regulate surveillance trade. Our team at @amnesty 's Security Lab are technical partners of @EICnetwork (w/ @Mediapart , @derspiegel ) on this global investigation into Intellexa and its Predator spyware
Tweet media one
3
141
229
@DonnchaC
Donncha Ó Cearbhaill
1 year
NEW: #PredatorFiles Day 2 - Technical deep-dive exposing the Intellexa Alliance's secret surveillance capabilities including advanced spyware, mass surveillance platforms, and tactical systems for targeting and intercepting nearby devices with zero-days.
3
116
184
@DonnchaC
Donncha Ó Cearbhaill
2 years
MUST READ: Incredible undercover investigation exposes how hackers-for-hire manipulate elections around the world With @FbdnStories I investigated the hackers behind the attacks. Here's how civil society can help defend against these threats. THREAD
5
106
190
@DonnchaC
Donncha Ó Cearbhaill
2 years
NEW RESEARCH: Today we @DonnchaC ( @AmnestyTech ) and @billmarczak ( @citizenlab ) publish a collaborative technical analysis of NSO Group's zero-click exploit capabilities. New insights into prevalence of zero-click capabilities and countermeasures! Talk later today at @VirusBTN
Tweet media one
5
61
191
@DonnchaC
Donncha Ó Cearbhaill
2 years
New @thewire_in report provides compelling technical confirmation that the email from @Meta 's @andymstone is authentic and unmodified. Big questions about Meta's rush to insinuate that the reporters from @thewire_in were misinformed or even fraudulent..
8
48
187
@DonnchaC
Donncha Ó Cearbhaill
10 years
So bug, very security http://t.co/jl4tnQ3swX
Tweet media one
14
248
174
@DonnchaC
Donncha Ó Cearbhaill
6 months
NEW REPORT: The @Amnesty Security Lab has uncovered a large murky web of spyware and surveillance exports to Indonesia from entities tied to NSO Group, Intellexa, Candiru, FinFisher and for the first identifying sales of Wintego Helios spyware..
9
104
164
@DonnchaC
Donncha Ó Cearbhaill
3 years
NEW: Today our team @AmnestyTech Security Lab has published new evidence of Pegasus spyware targeting two more individuals linked to Poland's political opposition. New findings in collaboration with #PegasusProject partners @gazeta_wyborcza @DIEZEIT @kaibiermann
1
68
159
@DonnchaC
Donncha Ó Cearbhaill
2 years
NEW: Mercenary spyware on the loose! Our team at @AmnestyTech is today revealing an extensive spyware campaign targeting Android users with zero-day exploits. The zero-days are now patched, keeping billions of Android, Chrome, and Linux users safer: 1/
1
101
157
@DonnchaC
Donncha Ó Cearbhaill
3 years
NEW: @AmnestyTech confirmed that prominent Sahrawi activist @aminatouhaidar was targeted with Pegasus spyware in recent months. NSO Group continues to be recklessly complicit in serious rights violations following #PegasusProject revelations. 🧵
Tweet media one
6
81
146
@DonnchaC
Donncha Ó Cearbhaill
3 months
NEW 🚨: Leaked documents analysed by @FbdnStories and media partners, with support of @AmnestyTech , reveal extensive efforts taken by Israeli authorities to shield spyware-maker NSO Group from accountability efforts in US court.
2
122
152
@DonnchaC
Donncha Ó Cearbhaill
3 years
A never-ending wave of Pegasus abuses in the EU. The out-of-control spyware industry needs to finally be reigned in. Big unanswered question: Who is responsible for these attacks against EU institutions? A fellow EU member state or a foreign customer of NSO Group...
@razhael
Raphael Satter
3 years
New: Senior European Union officials — including the bloc’s top justice official — were targeted using powerful phone hacking tools, @Bing_Chris and I have learned.
6
266
367
5
74
138
@DonnchaC
Donncha Ó Cearbhaill
2 years
Our analysis identifies at least SIX distinct zero-click exploit chains used to install Pegasus on iPhones and Android devices around the world since 2017. Full technical information in our forensic paper:
3
44
107
@DonnchaC
Donncha Ó Cearbhaill
3 years
NEW RESEARCH 📢📢: @AmnestyTech has published a investigation revealing a hacker-for-hire style campaign targeting a prominent activist from Togo in West Africa. Lets dive into this curious case.. THREAD
4
56
86
@DonnchaC
Donncha Ó Cearbhaill
1 year
Bombshell new report today from Haaretz ( @omerbenj ) about the spyware industry’s continued efforts to subvert our collective cyber-security, now by turning already invasive ad networks into spyware infection vectors.
4
62
95
@DonnchaC
Donncha Ó Cearbhaill
11 months
Today @Amnesty has launched a .onion site on the Tor network to make our human rights research safely accessible 🎉🧅 The @torproject is critical infrastructure enabling activists to maintain their rights to privacy and freedom of expression in a digital world.
@AmnestyTech
Amnesty Tech
11 months
Amnesty International has today launched its global website as an onion site on the Tor network. The @torproject enables safe access to @Amnesty 's ground-breaking human rights work in areas where censorship and digital surveillance are rife.
2
64
121
1
45
91
@DonnchaC
Donncha Ó Cearbhaill
1 year
NEW SPYWARE: Researchers at @kaspersky have captured and exposed a new iOS spyware campaign which was used to target **Kaspersky employees**. Kaspersky were able to uncover the attack with @AmnestyTech 's Mobile Verification Tool (MVT).
2
41
89
@DonnchaC
Donncha Ó Cearbhaill
6 years
Julian Assange is and always has been pursued by the US government for Wikileaks’s journalistic publishing, not for his personal beliefs. Today’s actions are a fundamental attack on journalism. Punishment for exposing war crimes and challenging power. Extradition must be resisted
3
33
70
@DonnchaC
Donncha Ó Cearbhaill
6 months
NEW: Apple have just notified people in 92 countries who were targeted by highly-invasive spyware. Our experts @AmnestyTech Security Lab can check devices for signs of attack 🔍. Please share widely with any activists or journalists who may have received the latest Apple alert
@AmnestyTech
Amnesty Tech
6 months
🚨Apple has sent threat notifications to iPhone users in 92 countries informing them they "are being targeted by a mercenary spyware attack" If you're a member of civil society + received an alert, you can request forensic support using our Get Help form👇
1
101
128
1
57
80
@DonnchaC
Donncha Ó Cearbhaill
2 years
NSO Group appeared before the European Parliament @EP_PegaInquiry today. NSO had the opportunity to come clean on the abuses of their tools against civil society but persisted with their long refuted denials and persisted in deflecting from accountability🧵
6
41
76
@DonnchaC
Donncha Ó Cearbhaill
11 months
Spyware continues to threaten civil society across Europe 🚨 Today, the @AmnestyTech Security Lab with partners @ShareConference , @accessnow + @citizenlab identify attempts to target two members of Serbian civil society with advanced spyware
@AmnestyTech
Amnesty Tech
11 months
🚨Serbia: civil society threatened by spyware Together with our partners @ShareConference , @accessnow and @citizenlab , @amnesty can reveal evidence that sophisticated spyware is being used to target civil society in Serbia👇
1
54
75
3
49
77
@DonnchaC
Donncha Ó Cearbhaill
6 months
NEW: @haaretzcom and @insidestory_gr reveal a scary new attack techniques offered by spyware-vendor Intellexa. Intellexa's Aladdin product uses malicious web ad's to target and silent infect targets as they simply browse the web.
@avischarf
avi scharf
6 months
Israel tried to keep sensitive spy tech under wraps. It leaked abroad by @omerbenj and @e_triantafillou
4
36
72
2
31
71
@DonnchaC
Donncha Ó Cearbhaill
3 years
The Mobile Verification Tool (MVT) from @AmnestyTech can identify traces of Cytrox Predator infections on Android or iOS. Share widely with activists networks who may be at risk of this spyware (Egypt, Saudi Arabia, Armenia, Serbia and more)
@AmnestyTech
Amnesty Tech
3 years
@Meta @amnesty @citizenlab The Mobile Verification Tool from Amnesty Tech can now also be used by civil society to check mobiles devices for traces of the Cytrox spyware. A full set of Cytrox indicators are available at
1
49
53
2
43
65
@DonnchaC
Donncha Ó Cearbhaill
3 years
More bad news for NSO Group and their investors. Administrator for Novalpina states it is “abundantly clear” that the 400 million euro equity in NSO is “valueless”.
2
23
64
@DonnchaC
Donncha Ó Cearbhaill
5 months
🚨NEW: @Amnesty report exposes how state-backed digital violence including highly-invasive spyware is being used against women and LGBTI activists in #Thailand in order to silence them. 👇
1
39
61
@DonnchaC
Donncha Ó Cearbhaill
1 year
The #PredatorFiles investigation reveals the #Predator spyware attack interface for the first time, with invasive capabilities to steal photos, track the victims location and record their microphone
Tweet media one
1
25
54
@DonnchaC
Donncha Ó Cearbhaill
2 years
Our team @AmnestyTech is available to support journalists and activists who are concerned about targeted spyware attacks. Please reach out if concerned and share widely with individuals in your networks who may be at risk.
@AmnestyTech
Amnesty Tech
2 years
The mercenary spyware industry is threatening rights defenders and journalists worldwide. Our experts @AmnestyTech can check devices for signs of spyware 🔍. Contact share @amnesty .tech if you're concerned, or if yourself or a colleague has received an attack notification
2
82
105
1
20
48
@DonnchaC
Donncha Ó Cearbhaill
2 years
The trouble continues for Novalpina Capital, the private equity firm which bought NSO Group. Berkeley Research Group, the new administrators of the fund behind Novalpina, have now filled a criminal complaint against two of the Novalpina co-founders in a Luxembourg court.
Tweet media one
1
24
52
@DonnchaC
Donncha Ó Cearbhaill
1 year
📢Job: Help us protect activists and journalists from spyware attacks. @AmnestyTech 's Security Lab is hiring a Full Stack Developer to build out our ground-breaking forensic tools and services which protect civil society from digital attacks 1/
3
41
52
@DonnchaC
Donncha Ó Cearbhaill
1 year
Important and well-sourced story today from the New York Times ( @satariano , @Aaron_Krolik , @paulmozur ) about how Russia exploits metadata leaks to track the users of encrypted messengers and services. Lets see how this can be a risk: 1/
@satariano
Adam Satariano
1 year
NEW: The global supply chain for digital surveillance tech is growing thanks to Russian companies building tools to track people online and on phones. One tool logs metadata for calls on encrypted apps like Signal & WhatsApp. w/ @Aaron_Krolik & @paulmozur
25
199
286
1
38
50
@DonnchaC
Donncha Ó Cearbhaill
2 years
Great opportunity to join our team at @AmnestyTech tackling unlawful surveillance. Lots of exciting work coming over the next months!
@AmnestyTech
Amnesty Tech
2 years
🚨 JOB OPPORTUNITY 🚨 Do you want to lead our research and advocacy on unlawful targeted surveillance and digital repression? We're looking for a (one year sabbatical cover) Researcher/Adviser in the team behind the Pegasus Project technical investigation
3
62
68
1
23
43
@DonnchaC
Donncha Ó Cearbhaill
11 years
Private mail server ☑ - Auto PGP encryption of incoming mail ☑ - Keys on OpenPGP smartcard ☑ - OpenVPN tunnel ☑ - #NSA #PRISM come at me bro
8
32
42
@DonnchaC
Donncha Ó Cearbhaill
3 months
Our team at the @AmnestyTech Security Lab is available to support human rights defenders and others in civil society who may have received the recent spyware notification from Apple.
@AmnestyTech
Amnesty Tech
3 months
🚨Apple has sent another round of notifications to iPhone users to inform them that they are being targeted by "mercenary spyware attacks". Here's what this means and what you can do if you're a member of civil society + received an alert 👇
1
95
112
0
31
43
@DonnchaC
Donncha Ó Cearbhaill
1 year
The Security Lab at @AmnestyTech will publish a number of #PREDATORFILES reports in the coming days including a technical deep-dive and an comprehensive report on abuses with Intellexa spyware tools. More from partners
@EICnetwork
EICnetwork
1 year
How European companies supplied dictators cyber-surveillance tools for more than a decade #PREDATORFILES
Tweet media one
5
96
125
2
28
42
@DonnchaC
Donncha Ó Cearbhaill
8 months
Great report from Google TAG ( @maddiestone , @_clem1 @ShaneHuntley ) on the range of commercial spyware actors they are tracking and finding deploying zero-day exploits in the wild
@maddiestone
Maddie Stone
8 months
We're naming names 🔥 because the harm is not hypothetical. Today we share "Buying Spying", our new report diving into the commercial surveillance/spyware industry. We dive into the players, the campaigns, the spyware, & the harm it perpetuates.
Tweet media one
13
311
655
1
11
40
@DonnchaC
Donncha Ó Cearbhaill
1 year
How is spyware attacking civil society? Join us ( @AmnestyTech , @amnesty_de ) and experts ( @HNeumannMEP , @mnbeeko , @anncathrin87 ) for a deep-dive into how Pegasus and other spyware enable a global surveillance crisis. Thursday 6th, hosted with @JanAlbrecht and @BoellStiftung !
@amnesty_de
Amnesty Deutschland
1 year
Veranstaltungstipp: Zwei Jahre nach dem Bekanntwerden des #Pegasus -Skandals möchten wir am 6. Juli in der @BoellStiftung an die Enthüllungen anknüpfen. Mit dabei: @mnbeeko , @JanAlbrecht , @PetizaGavarrete , @HNeumannMEP , @anncathrin87 . Kommt vorbei!
0
18
22
1
25
37
@DonnchaC
Donncha Ó Cearbhaill
1 year
Job opportunity 📢: Help us protect activists and journalists from spyware and targeted surveillance. My team at @AmnestyTech 's Security Lab is hiring two Technologists to expand our work exposing unlawful surveillance from companies and governments. 1/
1
36
37
@DonnchaC
Donncha Ó Cearbhaill
3 months
The revelations call into question Israel's commitment to impartially regulate NSO Group and casts doubt on its ability to provide justice, truth and reparation to those affected by Pegasus spyware. Read the findings from the @FbdnStories
1
14
34
@DonnchaC
Donncha Ó Cearbhaill
3 years
@runasand MVT from @AmnestyTech now also supports detecting additional behavior and traces linked to the Cytrox Predator spyware
@AmnestyTech
Amnesty Tech
3 years
@Meta @amnesty @citizenlab The Mobile Verification Tool from Amnesty Tech can now also be used by civil society to check mobiles devices for traces of the Cytrox spyware. A full set of Cytrox indicators are available at
1
49
53
2
8
32
@DonnchaC
Donncha Ó Cearbhaill
2 years
Incredible news this week as Carine Kanimba is reunited with her father. Many congrats to Carine and her family for their extraordinary campaign for the release of her father, unjustly detained by Rwandan authorities
@ckanimba
Carine Kanimba
2 years
PAUL RUSESABAGINA IS FREE 🤩🤩🥳🥳❤️❤️🛬🛬🛬 Dad has just arrived in San Antonio, Texas🛬🛬🛬 Thank you to EVERYONE who worked soooo hard to bring him home. 🙏❤️🙏 Our Family is finally reunited today. 💞💞 #FreeRusesabagina @freethehero #TheHeroIsFree #FreedHero #HotelRwanda
Tweet media one
93
694
3K
1
5
31
@DonnchaC
Donncha Ó Cearbhaill
2 years
MUST READ: Incredible undercover investigation exposes how hackers-for-hire manipulate elections around the world With @FbdnStories I investigated the hackers behind the attacks. Here's how civil society can help defend against these threats. THREAD
1
18
30
@DonnchaC
Donncha Ó Cearbhaill
7 years
People attending a state security meeting should not have their phones in the room, and especially not have them sitting on the table!
@LeoVaradkar
Leo Varadkar
7 years
Cabinet Committee F meeting for the second time today: bringing together heads of Irish security to discuss ongoing work in national security
Tweet media one
31
12
75
4
14
28
@DonnchaC
Donncha Ó Cearbhaill
3 years
Some messages sent to Ryszard Brejza included a fake message about a political party meeting and a fake message about discount offers for his HTC phone
1
14
28
@DonnchaC
Donncha Ó Cearbhaill
2 years
Free expert tip for the Modi government on avoiding the “PR problem” from forensic discovery of Pegasus abuses… ⛔️Stop hacking journalists, lawyers, and human rights activists
@muradahmed
Murad Ahmed
2 years
NEW 🚨India is hunting for alternatives to Pegasus spyware, in response to the “PR problem” caused by revelations about its maker NSO. Around a dozen rival firms circle contract worth up to $120mn. Super reporting in @FT by @MehulAtLarge @kayewiggins
0
11
19
1
10
26
@DonnchaC
Donncha Ó Cearbhaill
3 years
Both were targeted with malicious SMS messages on their Android devices. The customer used tailored social engineering messages to entice the targets into opening the suspected Pegasus links.
Tweet media one
1
7
27
@DonnchaC
Donncha Ó Cearbhaill
3 years
We have not seen many Pegasus social engineering messages in recent years. These new messages give an insight into how customers use detailed and personal information about the target to make the messages more convincing.
Tweet media one
2
10
27
@DonnchaC
Donncha Ó Cearbhaill
9 years
Delighted to have been accepted for Tor's summer of privacy. Thank you to very much @TorProject
5
20
24
@DonnchaC
Donncha Ó Cearbhaill
1 year
Meet Andreas Fink, a key enabler of the telecom surveillance industry. His company provided SS7 attack services to Rayzone Group and governments around the world. Scoop from a killer team of journalists @omerbenj , @cr0ft0n , @m_hoppenstedt ( @LHreports , @derspiegel , @haaretzcom )
@omerbenj
Omer Benjakob
1 year
Massive shoutout to @DonnchaC of @AmnestyTech -who helped link #TeamJorge to one of Fink's systems - and to @FbdnStories - who helped link many of us together for that investigation #StoryKillers
1
5
22
0
15
24
@DonnchaC
Donncha Ó Cearbhaill
2 years
The @Europarl_EN Security Team found that a Greek opposition MEP was targeted with the Cytrox Predator spyware in 2021. This case shows the value of public indicators and usable forensic tools such as @AmnestyTech 's MVT to help investigators researching targeted attacks.
@nytimesworld
New York Times World
2 years
As the number of politicians, activists and journalists hacked with spyware grew to include prime ministers and dissidents in the E.U., the European Parliament started checking its members’ phones. About 200 devices in, it hit its first positive.
0
45
50
1
11
23
@DonnchaC
Donncha Ó Cearbhaill
1 year
Google Project Zero has posted an insightful technical deep-dive into an Android exploit chain used in a mercenary spyware campaign uncovered earlier this year by @AmnestyTech with @_clem1 of Google TAG.
@__sethJenkins
Seth Jenkins
1 year
I just released a blog post on an Android ITW exploit chain: A big thanks to Google TAG and the other members of Project Zero who participated in the creation of this blog post and analysis of the chain!
7
105
291
0
8
24
@DonnchaC
Donncha Ó Cearbhaill
7 years
@pwnallthethings Also the US has been organising election disinformation all over the world for decades. The Snowden docs outlined an efforts to influence Iranian protest movements with Twitter sock puppets.
1
12
19
@DonnchaC
Donncha Ó Cearbhaill
10 years
Tweet media one
2
22
22
@DonnchaC
Donncha Ó Cearbhaill
1 year
📢 We're hiring a Full Stack Developer Last chance to join a unique role with @AmnestyTech . Help us build forensic tools and services to expose unlawful government surveillance and protect journalists, activists and civil society. Applications close tomorrow! ⏳
@DonnchaC
Donncha Ó Cearbhaill
1 year
📢Job: Help us protect activists and journalists from spyware attacks. @AmnestyTech 's Security Lab is hiring a Full Stack Developer to build out our ground-breaking forensic tools and services which protect civil society from digital attacks 1/
3
41
52
1
17
23
@DonnchaC
Donncha Ó Cearbhaill
8 years
WikiLeaks has released a major dump of technical documentation from the CIA's computer hacking section
14
22
18
@DonnchaC
Donncha Ó Cearbhaill
3 years
FT's @kayewiggins reports that NSO has received no new customers since @FbdnStories and @AmnestyTech exposed scale of abuse with the #PegasusProject Investors should consider these risks before investing in the toxic spyware industry. Terrible for human rights and bad business.
Tweet media one
1
6
21
@DonnchaC
Donncha Ó Cearbhaill
2 years
The @AmnestyTech Security Lab has peer-review a sample of cases identified by @CitizenLab and confirmed targeted and infection with Pegasus in all cases analysed.
1
24
23
@DonnchaC
Donncha Ó Cearbhaill
3 years
These cases add to growing concerns that Pegasus spyware may have been misused for political purposes in Poland. This is not only a threat for politicians, but for the whole of Poland’s civil society in general.
1
5
21
@DonnchaC
Donncha Ó Cearbhaill
2 years
Amnesty is not naming the company behind these attacks while we continue to investigate the activity. Researchers at Google TAG found links between the new exploits and exploit pages previously developed by Spanish cyber-surveillance company Variston. 4/
2
8
22
@DonnchaC
Donncha Ó Cearbhaill
1 year
Shocking revelations today that Intellexa sold their highly-invasive Predator spyware to al-Sissi's Egypt, and even pitched surveillance tools to Haftar's militia in Libya in violation of a UN weapon embargo. A company and industry totally out-of-control
2
15
22
@DonnchaC
Donncha Ó Cearbhaill
2 years
@Joey_Galvin @thewire_in @Meta @andymstone Verifying the DKIM signature is the correct way to authenticate an email. It can prove that signed headers (From;Date;Subject; etc) and message body were unmodified and sent through the FB mail server.
1
4
22
@DonnchaC
Donncha Ó Cearbhaill
2 years
@Joey_Galvin @thewire_in @Meta @andymstone It's understandable that they can't share the full email for security and source protection reasons. They seem to have been as open as possible in the approach here, including getting independent confirmation from experts.
1
3
21
@DonnchaC
Donncha Ó Cearbhaill
2 years
The @citizenlab found additional evidence about a Apple Photos zero-click attack previously described by @AmnestyTech as part of the #PegasusProject . The Security Lab found this vulnerability used to compromise a human-rights lawyer in France and a journalist in Hungary.
Tweet media one
0
13
21
@DonnchaC
Donncha Ó Cearbhaill
1 year
I want to thank the dream team at @AmnestyTech without whom this project would have been impossible @ruairin , @Rasha_Abdul @lipstickkranti @beckacita @Elina_Castillo @cyrmeister @DrWhax , Marianne and Raed Labassi are off Twitter since before it was cool
2
2
19
@DonnchaC
Donncha Ó Cearbhaill
2 years
Excellent investigation exposes more Pegasus abuses targeting civil society in the EU from @elies , @jsrailton and the team @citizenlab .
@jsrailton
John Scott-Railton
2 years
🚨MAJOR NEW INVESTIGATION: #CatalanGate state-run hacking operation. Stunning range of #Pegasus & #Candiru infections in the EU. Many political & civil society targets got infected. Multiple 🇪🇺 MEPs. THREAD 1/
43
1K
2K
2
10
21
@DonnchaC
Donncha Ó Cearbhaill
10 months
Great presentation from @jbesendorf and @schluevik from #37c3 providing an overview on approaches to smartphone spyware forensics.
@jbesendorf
Janik Besendorf ([email protected])
10 months
Beim #37C3 haben @schluevik und ich darüber gesprochen wie man Malware wie Staatstrojaner oder Stalkerware auf iOS und Android finden kann. Hier zum nachschauen auf
1
4
20
0
5
20
@DonnchaC
Donncha Ó Cearbhaill
4 years
@AmnestyTech discovered that Qatar made critical mistakes in the implementation of their contact tracing app. Potentially the entire citizen database (with name, GPS location, citizen ID, health status) was left exposed
2
17
19
@DonnchaC
Donncha Ó Cearbhaill
2 years
Great new reporting from @PhineasJFR on the OSINT surveillance market and a player named S2T Unlocking Cyberspace featuring contributions from OCCRP's @DrWhax and our own @tenacioustek
@PhineasJFR
Phineas James
2 years
SCOOP #StoryKillers : @FbdnStories obtained a brochure for an open-source intelligence ( #OSINT ) tool that can also be used for phishing, social engineering and geolocation of targets. We tied the brochure to Singapore-based firm S2T Unlocking Cyberspace:
2
23
53
1
9
18
@DonnchaC
Donncha Ó Cearbhaill
8 months
The report documents some of the lesser known players such as Cy4Gate and RCS, with a deep dive into their exploits. We don’t know where they acquire their exploits, but Google suggests Cy4Gate has access to multiple exploit frameworks named “YodaRoot” and “DF1” 🤔
Tweet media one
2
11
20
@DonnchaC
Donncha Ó Cearbhaill
1 year
Insightful thread from @billmarczak about the #Triangulation campaign from @kaspersky . Our own hunting has found related domains back to 2018, including in English, Spanish, Portuguese and Chinese. Likely many more targets out there.. Will we see more targets come public?
@billmarczak
Bill Marczak
1 year
NEW: I've come out of self-imposed retirement from my @Medium blog to write some thoughts about the FSB and Kaspersky's discovery of the #Triangulation attack:
7
77
264
1
6
19
@DonnchaC
Donncha Ó Cearbhaill
3 months
Israeli officials seized documents from NSO Group's offices, in an effort to prevent the company from being forced to comply with legal discovery in it's long-running court battle with @WhatsApp , over the targeting of 1400 it's users with Pegasus
1
7
19
@DonnchaC
Donncha Ó Cearbhaill
3 years
#MiningSecrets exposes tactics used my mining conglomerate to target environmental defenders in Guatamala seeking to protect their communities and their land. Powerful new reporting by @FbdnStories and their partners organizations. A must read:
1
12
19
@DonnchaC
Donncha Ó Cearbhaill
5 months
Welcome to all the hackers in Berlin this week for @offensive_con . DMs are open for anyone who’d like to get a coffee! I’d love to talk about the offensive industry and what we can to do to reduce potential harms for activists and journalists. #offensivecon
1
4
18
@DonnchaC
Donncha Ó Cearbhaill
2 years
So proud of the Amnesty Tech team's amazing work on the #PegasusProject , captured in "Pegasus", a new book giving a behind-the-scenes account of the high-stakes investigation from our partners at @FbdnStories .
@AmnestyTech
Amnesty Tech
2 years
Exciting week for us with the publication of “Pegasus”, the inside story of one of @amnesty most ground-breaking investigations of recent years: the #PegasusProject
Tweet media one
16
476
1K
0
3
18
@DonnchaC
Donncha Ó Cearbhaill
1 year
Welcome Jurre! We're delighted to have you join the team and continue the fight against abuses enabled by the spyware industry
@DrWhax
Jurre van Bergen
1 year
I'm very excited to announce I started as a Technologist at @AmnestyTech . I've been a long time admirer of the Security Lab's work and I can't wait to hold power to account in this new role. Different ways to reach me securely here:
13
3
78
0
0
17
@DonnchaC
Donncha Ó Cearbhaill
7 months
Incredible article from @mer__edith outlining the great danger of conceding and concentrating more power to an increasingly authoritarian United States in the name of controlling TikTok which currently lies outside of the US hegemonic consensus.
@Caffar3Cristina
Cristina Caffarra
7 months
So good @mer__edith . Incredible essay. The final SO, WHAT? section is a whole manifesto. - "The world would be better if these platforms were dismantled and their revenues shared with the people, professions, and communities whose livelihoods and public spaces they’ve worked
1
21
68
0
3
17
@DonnchaC
Donncha Ó Cearbhaill
11 months
The Amnesty .onion website is a special Tor only "onion" website which can be accessed through @torproject 's Tor Browser software. The long random-looking .onion domain ensure that you are safely accessing the authentic website and not an imposter site.
1
3
17
@DonnchaC
Donncha Ó Cearbhaill
2 years
Key points from the paper: NSO Group customers deployed at least 6 distinct iOS zero-click chains from iOS 10 (July 2017) until iOS 14 in 2021. An Android zero-click in WhatsApp has also been exploited much more extensively than previously understood..
Tweet media one
1
7
17
@DonnchaC
Donncha Ó Cearbhaill
2 years
Netzpolitik has publish a letter from the European Commission which confirms that multiple individuals at the Commission where compromised with Pegasus spyware..
@andre_meister
Andre Meister
2 years
Die EU-Kommission hat "indicators of compromise" auf mehreren Geräten ihrer Mitarbeiter:innen gefunden. Apple sagte Kommissar @dreynders , er könnte mit dem Staatstrojaner NSO Pegasus gehackt sein. Wir veröffentlichen seinen Brief an @SophieintVeld .
0
18
23
1
6
14
@DonnchaC
Donncha Ó Cearbhaill
2 years
Much respect to the undercover team ( @omerbenj , @GurMegiddo , @FredMetzo ) who pulled of this jaw-dropping infiltration and partners who's digging confirmed many of Team Jorge’s wildest claims @m_hoppenstedt , @Damien_Leloup , @flornrnd !
Tweet media one
0
5
16
@DonnchaC
Donncha Ó Cearbhaill
2 years
The Security Lab @AmnestyTech proactively investigates mercenary spyware companies and other actors who threaten civil society. From this work we uncovered a previously unknown mercenary spyware company operating thousands of domains to deliver exploits and hack devices 2/
1
1
16
@DonnchaC
Donncha Ó Cearbhaill
5 months
Important story from @samfbiddle highlighting the underappreciated threat of traffic correlation attacks which can reveal metadata about who is communicating with each other even over encrypted messaging apps like WhatsApp and Signal.
Tweet media one
@samfbiddle
Sam Biddle
5 months
NEW: In an internal Meta threat assessment I obtained, WhatsApp engineers warned users are vulnerable to government spying that unmasks who's talking to who. Employees later speculated Israel may be exploiting this to target and kill across the Gaza Strip
22
754
1K
1
7
16
@DonnchaC
Donncha Ó Cearbhaill
3 years
Numerous credible reports of misuse and subsequent inaction have proven this industry cannot be trusted to regulate itself. We urgently need global action to stop the human rights crisis enabled by the out-of-control cyber-surveillance industry.
1
2
12
@DonnchaC
Donncha Ó Cearbhaill
3 months
Important story and kudos to all involved @PhineasJFR @KarinePfenniger ( @guardian , @paper_trail_m , @InvestigationRF , @DIEZEIT , @derspiegel ) and the many @Amnesty / @AmnestyTech colleagues who supported on this investigation
@AmnestyTech
Amnesty Tech
3 months
An investigation led by @FbdnStories and supported by @Amnesty ’s Security Lab has revealed that Israel’s government has attempted to sway an ongoing US lawsuit filed by WhatsApp against spyware firm NSO Group 🧵 👇
10
89
115
1
6
16
@DonnchaC
Donncha Ó Cearbhaill
2 years
NSO legal consul discloses around 12,000 annual targets by their government customers. This shows the huge scale of attack from just a single company and tallies with the 50,000 potential targets identified by the Pegasus Project over a number of years.
2
12
14
@DonnchaC
Donncha Ó Cearbhaill
1 year
@kaspersky @AmnestyTech Brave (and foolish) decision by a threat actor to target a group of ATP hunters! We have added the latest indicators for this campaign to MVT for use by the civil society community to detect these attacks.
0
3
15
@DonnchaC
Donncha Ó Cearbhaill
2 years
We shared technical indicators about the suspected targeting of Android users with Google’s Threat Analysis Group allowing TAG ( @_clem1 , @ShaneHuntley ) to capture a zero-day exploit chain being used in the wild to hack Android devices. 3/
2
1
15
@DonnchaC
Donncha Ó Cearbhaill
8 years
@DonnchaC CIA have been bugging embedded devices and the Internet of Things. Can covertly listen to Samsung SmartTVs
1
20
9
@DonnchaC
Donncha Ó Cearbhaill
8 years
New: researchers link tools in the CIA/Vault 7 dump to 40 hacks around the world. Education, energy, finance, more
@DonnchaC
Donncha Ó Cearbhaill
8 years
@DonnchaC This dump and technical documentation will lead the the undeniable attribution of some CIA cyber operations, significant impact
0
1
2
1
8
14