Company:DarkMatter (Emirati company)
Type | Private |
---|---|
Industry | cybersecurity |
Founded | 2014 |
Headquarters | Abu Dhabi, United Arab Emirates |
Area served | U.A.E., Finland, Canada |
Key people |
|
Website | www |
DarkMatter Group, founded in the United Arab Emirates (UAE) in 2014[1][2] or 2015,[3] is a cybersecurity company.[4][5][1]
The company describes itself as a purely defensive company, but several whistleblowers have alleged that it is involved in offensive cybersecurity ("cracking" or, colloquially, "hacking"), including on behalf of the Emirati government.[4][1]
Company history
DarkMatter was founded in either 2014[1][2] or 2015[3] by Faisal al-Bannai, the founder of mobile phone vendor Axiom Telecom and the son of a major general in the Dubai Police Force.[3][1][5]
Around 2014, Zeline 1, a wholly owned subsidiary of DarkMatter, became active in Finland.[2]
DarkMatter's public launch came in 2015, at the 2nd Annual Arab Future Cities Summit.[4] At this time, the company advertised capabilities including network security and bug sweeping, and promised to create a new, "secure" mobile phone handset.[4] It promoted itself as a "digital defense and intelligence service" for the UAE.[4]
In 2016, DarkMatter replaced CyberPoint as a contractor for Project Raven.[1] Also in 2016, DarkMatter sought smartphone development expertise in Oulu, Finland.[2] DarkMatter recruited several Finnish engineers.[2]
By early 2018, DarkMatter's turnover was hundreds of millions of U.S. dollars.[5] Eighty per cent of its work was for the UAE government and related organizations, including the NESA.[5] It had developed a smartphone model called Katim, Arabic for "silence".[3]
DarkMatter is an official provider for the Expo 2020.[6]
Recruitment practices
In addition to recruiting via conventional routes such as personal referrals and stalls at trade shows (e.g. Black Hat),[4] DarkMatter headhunts staff from the U.S. National Security Agency and has "poached" competitors' staff after they were contracted to the UAE government, as happened with some CyberPoint employees.[4][5]
The company has reportedly hired graduates of the Israel Defense Force technology units and is paying them up to $1 million annually.[7]
Allegations of surveillance for UAE government
Project Raven
Project Raven was a confidential initiative to help the UAE surveil other governments, militants, and human rights activists.[1] Its team included former U.S. intelligence agents, who applied their training to hack phones and computers belonging to Project Raven's victims.[1] The operation was based in a converted mansion in Abu Dhabi nicknamed "the Villa."[1]
From around 2014 to 2016, CyberPoint supplied U.S.-trained contractors to Project Raven. In 2016, news reports emerged that CyberPoint had contracted with the Italian spyware company Hacking Team, which damaged CyberPoint's reputation as a defensive cybersecurity firm.[4] Reportedly dissatisfied with relying upon a U.S.-based contractor, the UAE replaced CyberPoint with DarkMatter as its contractor, and DarkMatter induced several CyberPoint staff to move to DarkMatter.[1][8] After this, Project Raven reportedly expanded its surveillance to include the targeting of Americans, potentially implicating its American staff in unlawful behaviour.[1][8][9]
Karma spyware
In 2016, Project Raven bought a tool called Karma.[10] Karma was able to remotely exploit Apple iPhones anywhere in the world, without requiring any interaction on the part of the iPhone's owner.[1] It apparently achieved this by exploiting a zero-day vulnerability in the device's iMessage app.[1] Project Raven operatives were able to view passwords, emails, text messages, photos and location data from the compromised iPhones.[10][1]
People whose mobile phones have been deliberately compromised using Karma reportedly include:
- The Emir of Qatar, Sheikh Tamim bin Hamad Al Thani, plus his brother and several other close associates.[4]
- Nadia Mansoor, wife of imprisoned UAE human rights activist Ahmed Mansoor.[1] (Nadia was nicknamed "Purple Egret" by Project Raven; Ahmed was nicknamed "Egret".)[4]
- British journalist Rori Donaghy.[1] (Donaghy was nicknamed "Gyro" by Project Raven.)[4]
- Hundreds of other targets in Europe and the Middle East, including in the governments of Yemen, Iran and Turkey.[4]
In 2017, Apple patched some of the security vulnerabilities exploited by Karma, reducing the tool's effectiveness.[10]
Certificate authority controversy
In 2016, two DarkMatter whistleblowers and multiple other security researchers expressed concerns that DarkMatter intended to become a certificate authority (CA).[4] This would give it the technical capability to create fraudulent certificates, which would allow fraudulent websites or software updates to convincingly masquerade as legitimate ones.[4] Such capabilities, if misused, would allow DarkMatter to more easily deploy rootkits to targets' devices, and to decrypt HTTPS communications of Firefox users via man-in-the-middle attacks.[4][11][12]
On 28 December 2017, DarkMatter requested that Mozilla include it as a trusted CA in the Firefox web browser.[13] For more than a year, Mozilla's reviewers addressed concerns about DarkMatter's technical practices, eventually questioning on that basis whether DarkMatter met the baseline requirements for inclusion.[13][14]
On 30 January 2019, Reuters published investigations describing DarkMatter's Project Raven.[1][11] Mozilla's reviewers noted the investigation's findings.[14] Subsequently, the Electronic Frontier Foundation (EFF) and others asked Mozilla to deny DarkMatter's request, on the basis that the investigation showed DarkMatter to be untrustworthy and therefore liable to misuse its capabilities.[11][12][14][13] (As of March 2019), Mozilla's public consultation and deliberations are ongoing.[14][13]
In July 2019, Mozilla prohibited the government of United Arab Emirates from operating as one of its internet security gatekeepers, following reports on the cyber-espionage program, which was run by Abu Dhabi-based DarkMatter staff for leading a clandestine hacking operation.[15]
In August 2019, Google blocked websites approved by DarkMatter, after Reuters reported the firm's involvement in a hacking operation led by the United Arab Emirates. Google, previously, said that all websites certified by DarkMatter would be marked as unsafe by its Chrome and Android browsers.[16]
See also
- NSO Group
- Stealth Falcon
References
- ↑ 1.00 1.01 1.02 1.03 1.04 1.05 1.06 1.07 1.08 1.09 1.10 1.11 1.12 1.13 1.14 1.15 1.16 "Exclusive: Ex-NSA cyberspies reveal how they helped hack foes of UAE". https://www.reuters.com/investigates/special-report/usa-spying-raven/.
- ↑ 2.0 2.1 2.2 2.3 2.4 "Revealed: Secretive UAE cybersecurity firm with a history of spying on dissidents is operating in Finland". http://www.helsinkitimes.fi/finland/finland-news/domestic/16165-revealed-secretive-uae-cybersecurity-firm-with-a-history-of-spying-on-dissidents-is-operating-in-finland.html.
- ↑ 3.0 3.1 3.2 3.3 "UAE cyber firm DarkMatter slowly steps out of the shadows". https://phys.org/news/2018-02-uae-cyber-firm-darkmatter-slowly.html.
- ↑ 4.00 4.01 4.02 4.03 4.04 4.05 4.06 4.07 4.08 4.09 4.10 4.11 4.12 4.13 4.14 McLaughlin, Jenna (24 October 2016). "Featured News: Spies for Hire". https://theintercept.com/2016/10/24/darkmatter-united-arab-emirates-spies-for-hire/.
- ↑ 5.0 5.1 5.2 5.3 5.4 "Emerging Gulf State cyber security powerhouse growing rapidly in...". 2 February 2018. https://www.reuters.com/article/us-emirates-cyber-darkmatter-idUSKBN1FL451.
- ↑ https://www.expo2020dubai.com/en/business/partners
- ↑ Ziv, Amitai (16 October 2019). "Mysterious UAE Cyber Firm Luring ex-Israeli Intel Officers With Astronomical Salaries". https://www.haaretz.com/israel-news/.premium-mysterious-uae-cyber-firm-luring-ex-israeli-intel-officers-with-astronomical-salaries-1.7991274.
- ↑ 8.0 8.1 "A New Age of Warfare: How Internet Mercenaries Do Battle for Authoritarian Governments". 2019-03-21. https://www.nytimes.com/2019/03/21/us/politics/government-hackers-nso-darkmatter.html.
- ↑ "Takeaways From The Times’s Investigation Into Hackers for Hire". 2019-03-21. https://www.nytimes.com/2019/03/21/us/politics/nso-darkmatter-government-spies.html.
- ↑ 10.0 10.1 10.2 Reuters. "A top secret UAE spy operation staffed by former NSA cyber-agents hacked into the iPhones of dissidents and rivals". https://www.businessinsider.com/r-exclusive-uae-used-cyber-super-weapon-to-spy-on-iphones-of-foes-2019-1.
- ↑ 11.0 11.1 11.2 "CyberSecurity Firm Darkmatter Request to be Trusted Root CA Raises Concerns". https://www.bleepingcomputer.com/news/security/cybersecurity-firm-darkmatter-request-to-be-trusted-root-ca-raises-concerns/.
- ↑ 12.0 12.1 Quintin, Cooper (22 February 2019). "Cyber-Mercenary Groups Shouldn't be Trusted in Your Browser or Anywhere Else". https://www.eff.org/deeplinks/2019/02/cyber-mercenary-groups-shouldnt-be-trusted-your-browser-or-anywhere-else.
- ↑ 13.0 13.1 13.2 13.3 "1427262 - Add DarkMatter Root Certificates". https://bugzilla.mozilla.org/show_bug.cgi?id=1427262.
- ↑ 14.0 14.1 14.2 14.3 "DarkMatter Concerns". https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/nnLVNfqgz7g.
- ↑ "Mozilla blocks UAE bid to become an internet security guardian after hacking reports". Reuters. https://www.reuters.com/article/us-usa-cyber-mozilla/mozilla-blocks-uae-bid-to-become-an-internet-security-guardian-after-hacking-reports-idUSKCN1U42CA. Retrieved 9 June 2019.
- ↑ "Google blocks websites certified by DarkMatter, after Reuters reports". Reuters. https://www.reuters.com/article/us-usa-cyber-alphabet-google/google-blocks-websites-certified-by-darkmatter-after-reuters-reports-idUSKCN1UR5JD. Retrieved 1 August 2019.
External links