Fake Pegasus spyware's misuse surges on Dark Web: Researchers

by IANS |

New Delhi, May 23 (IANS) Cyber-security researchers on Thursday warned about the widespread misuse of fake Pegasus spyware on the Dark Web where hackers are leveraging the name of Pegasus for financial gains.


Following Apple's recent notification to users in 92 countries about a ‘mercenary spyware’ attack, homegrown cybersecurity firm CloudSEK carried out an in-depth investigation.


They found a widespread misuse of Israel-based company NSO’s Pegasus spyware's name.


The findings serve “as an advisory against scammers and threat actors who are exploiting the growing recognition of NSO Group's renowned product, Pegasus, for their fraudulent purposes,” the researchers noted.


The researchers analysed approximately 25,000 posts on Telegram, many of which claimed to sell authentic Pegasus source code.


“These posts followed a common template offering illicit services, with Pegasus and NSO tools frequently mentioned,” the team mentioned.


By interacting with over 150 potential sellers, CloudSEK gained insights into various samples and indicators shared by these actors.


This included purported Pegasus source code, live demonstrations, file structures, and snapshots.


“Similar misuse was observed on surface web code-sharing platforms, where actors disseminated randomly generated source codes falsely associated with Pegasus,” said researchers.


After analysing 15 samples and over 30 indicators from human intelligence (HUMINT), deep, and dark web sources, the team discovered that nearly all samples were “fraudulent and ineffective”.


Threat actors created their own tools and scripts, distributing them under Pegasus' name to capitalise on its notoriety for financial gain, the report said.

Latest News
Youth jumps off 3rd floor of Hyderabad hotel to escape dog, dies Tue, Oct 22, 2024, 11:02 AM
Israel, US begin implementing 5.2 billion USD air defence aid package Tue, Oct 22, 2024, 10:59 AM
Two killed, three injured in Israeli airstrike in Syrian capital Tue, Oct 22, 2024, 10:58 AM
Did Rahul Gandhi Make a Mistake by Calling BJP Anti-Tribal? Mon, Oct 21, 2024, 06:28 PM
Assam bypolls: BJP's ally AGP fields MP’s wife from Bongaigaon seat Mon, Oct 21, 2024, 05:01 PM
Myanmar: 8 dead, 18 missing in ferry accident Mon, Oct 21, 2024, 04:59 PM
J&K LG directs immediate financial aid for Gagangir terror attack victims Mon, Oct 21, 2024, 04:37 PM
Zepto CEO credits Modi govt for mushrooming of start-ups Mon, Oct 21, 2024, 04:36 PM
Robber lynched in Bihar's Gopalganj Mon, Oct 21, 2024, 04:11 PM
Sensex and Nifty drop lower, Tata Consumer and Kotak Mahindra Bank top losers Mon, Oct 21, 2024, 04:09 PM
Dynasty, legacy, and family ties continue to dominate electoral landscape of Jharkhand Mon, Oct 21, 2024, 04:06 PM
India now a global destination for local production, exports: Sunil Bharti Mittal Mon, Oct 21, 2024, 01:57 PM
Women’s T20 WC: Victory over India set tone for winning the title, says Devine Mon, Oct 21, 2024, 01:50 PM
Complete cooperation for Karnataka police to work independently: CM Siddaramaiah Mon, Oct 21, 2024, 01:44 PM
PM Modi and Spanish PM Pedro Sanchez to inaugurate C-295 aircraft plant in Vadodara Mon, Oct 21, 2024, 01:44 PM