Hack-for-hire group caught targeting Android devices and iCloud backups

A sophisticated hack-for-hire group with suspected ties to Indian commercial spyware vendors is actively targeting high-value individuals across the Middle East, North Africa, and beyond through phishing attacks on iCloud backups and Android spyware deployment, representing a significant shift in how state-sponsored cyberattacks are being outsourced to private contractors for plausible deniability. This trend creates substantial risk for organizations whose executives, board members, and sensitive personnel may be targeted, while highlighting the inadequacy of traditional security controls against coordinated, well-resourced adversaries leveraging both social engineering and mobile exploitation. CIOs must treat mobile device security and cloud backup protection as critical infrastructure vulnerabilities and implement zero-trust principles for high-risk user populations, as traditional endpoint security may prove insufficient against this emerging threat model.

TechCrunch2 min read
Read full article
Hack-for-hire group caught targeting Android devices and iCloud backups
Security researchers exposed a spying campaign by a hack-for-hire group that used Android spyware and phishing to steal iCloud credentials and hack victims’ devices.