When Governments Hack Opponents: A Look at Actors and Technology

Repressive nation-states have long monitored telecommunications to keep tabs on political dissent. The Internet and onlinesocial networks, however, pose novel technical challenges tothis practice, even as they open up new domains for surveillance. We analyze an extensive collection of suspicious filesand links targeting activists, opposition members, and non-governmental organizations in the Middle East over the pastseveral years. We find that these artifacts reflect efforts to attack targets’ devices for the purposes of eavesdropping, stealinginformation, and/or unmasking anonymous users. We describeattack campaigns we have observed in Bahrain, Syria, and theUnited Arab Emirates, investigating attackers, tools, and techniques. In addition to off-the-shelf remote access trojans andthe use of third-party IP-tracking services, we identify commercial spyware marketed exclusively to governments, includingGamma’s FinSpy and Hacking Team’s Remote Control System (RCS). We describe their use in Bahrain and the UAE, andmap out the potential broader scope of this activity by conducting global scans of the corresponding command-and-control(C&C) servers. Finally, we frame the real-world consequencesof these campaigns via strong circumstantial evidence linkinghacking to arrests, interrogations, and imprisonment.


