Beware of Fake Amnesty International 'Anti Pegasus' Software

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,190
In yet another indicator of how hacking groups are quick to capitalize on world events and improvise their attack campaigns for maximum impact, threat actors have been discovered impersonating Amnesty International to distribute malware that purports to be security software designed to safeguard against NSO Group's Pegasus surveillanceware.

"Adversaries have set up a phony website that looks like Amnesty International's — a human rights-focused non-governmental organization — and points to a promised antivirus tool to protect against the NSO Group's Pegasus tool," Cisco Talos researchers said. "However, the download actually installs the little-known Sarwent malware."

The countries most affected by the campaign include the U.K., the U.S., Russia, India, Ukraine, Czech Republic, Romania, and Colombia. While it's unclear as to how the victims are lured into visiting the fake Amnesty International website, the cybersecurity firm surmised the attacks could be aimed at users who may be specifically searching for protection against this threat.
AVvXsEjLfaq7SYsxSFMBrV_CQqBCwWDR69zBytSO1J8BJzVvVVctP5tZk-ix1FUqViGxNRuzDMprZ3lDcLBeDiRIk0FaF9uEQ0POLvXfKr6lLIGKg8KhywxA7RtAKvadwb-tABbFq2FXEkYBgLRf5KrFldYWldXdtdAZS-9qYxGculFx9eRuSF5_hxTpJL_5


image1.png
Fake AntiPegasus software User interface (Source: Cisco Talos)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top