6:35 AM 7/31/2023 - Trump faces new charges for trying to delete security camera footage in Mar-a-Lago case ... THE SPYWARE SAGA: Who Paid for a Mysterious Spy Tool? The F.B.I., an F.B.I. Inquiry Found posted at 10:26:53 UTC via nytimes.com

Selected Articles - 6:35 AM 7/31/2023

Trump faces new charges for trying to delete security camera footage in Mar-a-Lago case  EL PAÍS USA
Jewel thieves targeting Indians, South Asians in Massachusetts ...  Daijiworld.com
US: ‘Opportunity crimes’ against Indians, South Asians on the rise in Massachusetts  DNA India

After a Times report, the bureau canceled its contract with a government contractor that used the tool on its behalf. But questions remain.

A building displays a sign that reads NSO Group surrounded by palm trees.
A branch of the hacking firm NSO in Sapir, Israel. The Biden administration put the company on a Commerce Department blacklist in 2021.Credit...Amit Elkayam for The New York Times
July 31, 2023, 3:00 a.m. ET

When The New York Times reported in April that a contractor had purchased and deployed a spying tool made by NSO, the contentious Israeli hacking firm, for use by the U.S. government, White House officials said they were unaware of the contract and put the F.B.I. in charge of figuring out who might have been using the technology.

After an investigation, the F.B.I. uncovered at least part of the answer: It was the F.B.I.

The deal for the surveillance tool between the contractor, Riva Networks, and NSO was completed in November 2021. Only days before, the Biden administration had put NSO on a Commerce Department blacklist, which effectively banned U.S. firms from doing business with the company. For years, NSO’s spyware had been abused by governments around the world.

This particular tool, known as Landmark, allowed government officials to track people in Mexico without their knowledge or consent.

The F.B.I. now says that it used the tool unwittingly and that Riva Networks misled the bureau. Once the agency discovered in late April that Riva had used the spying tool on its behalf, Christopher A. Wray, the F.B.I. director, terminated the contract, according to U.S. officials.

But many questions remain. Why did the F.B.I. hire this contractor — which the bureau had previously authorized to purchase a different NSO tool under a cover name — for sensitive information-gathering operations outside the United States? And why was there apparently so little oversight?

It is also unclear which, if any, government agencies besides the F.B.I. might have worked with Riva Networks to deploy the spying tool in Mexico. Two people with direct knowledge of the contract said cellphone numbers in Mexico were targeted throughout 2021, 2022 and into this year — far longer than the F.B.I. says the tool was used.

The episode further illustrates how, even as the White House tries to crack down on foreign spyware firms, NSO continued to find ways to make money off its tools.

Riva Networks and its chief executive, Robin Gamble, did not respond to several requests for comment on the F.B.I.’s accusations. When a Times reporter went to an address the company lists in some public records, a person who answered said he had never heard of Mr. Gamble. He refused to provide his name before closing the door.

The F.B.I., according to several U.S. officials, had hired the New Jersey-based Riva Networks to help track suspected drug smugglers and fugitives in Mexico because the company was able to exploit vulnerabilities in the country’s cellphone networks to covertly track mobile phones.

A senior F.B.I. official said that in early 2021, the bureau gave Riva Networks several phone numbers in Mexico to target as part of its fugitive apprehension program. The official, who like others in this article spoke on the condition of anonymity to discuss sensitive details, said that the bureau thought Riva Networks was using an in-house geolocation tool.

In the investigation that the F.B.I. began after The Times article, the bureau found that at some point in 2021 Riva began using Landmark, the NSO tool, without informing the bureau, the official said. Riva renewed its contract with NSO in November 2021 without telling the F.B.I., the official said.

The bureau told its contractors, including Riva, that they could not use NSO products in 2021, the official said, adding that no data from Landmark ever made it back to the F.B.I. — at least based on what Riva Networks told the agency.

“As part of our mission, the F.B.I. is tasked with locating fugitives around the world who are charged in U.S. courts, including for violent crimes and drug trafficking,” the agency said in a statement. “To accomplish this, the F.B.I. regularly contracts with companies who can provide technological assistance to locate these fugitives who are hiding abroad.”

The statement added: “The F.B.I. has not employed foreign commercial spyware in these or any other operational endeavors. This geolocation tool did not provide the F.B.I. access to an actual device, phone or computer. We will continue to lawfully utilize authorized tools to protect Americans and bring criminals to justice.”

A senior White House official told The Times that because Landmark is an NSO product, its use by the government is banned under a new executive order that restricts federal agencies from using spying tools made by some foreign hacking companies. But U.S. officials say that government use of geolocation tools in general does not violate the executive order.

It is not unusual for the F.B.I., as well as other law enforcement agencies, to use contractors that provide technologies such as breaking into phones after a terrorist attack. The intelligence community also relies on contractors for certain abilities.

The Times has sued the F.B.I. under the Freedom of Information Act for documents related to the bureau’s purchase of NSO tools and has also sought documents about the bureau’s relationship with Riva Networks. In a court filing this week, government lawyers argued that the F.B.I. should not have to turn over information about Riva Networks because “the vendors at issue either already do, or may in the future, offer other products that are or can be used for investigative purposes.”

The Biden administration blacklisted NSO after years of scandal associated with its primary hacking tool, Pegasus, which authoritarian governments and democracies alike have used to spy on journalists, human rights activists and political dissidents.

The White House declined to comment on whether it would push for penalties against Riva Networks.

Government databases show that Riva Networks has had numerous lucrative contracts with government agencies, including the Defense Department, the F.B.I. and the Drug Enforcement Administration. As recently as October, the company was awarded a contract for work with the Air Force Research Laboratory.

Marc DeNofio, a spokesman for the laboratory, said the work had largely been completed, but “Riva is still active as there are still some support hours remaining on their effort.”

The F.B.I.’s relationship with the company also goes back several years. In fact, the bureau used Riva Networks to purchase Pegasus, which penetrates phones and extracts their contents without users’ knowledge. The bureau paid more than $5 million to test the spyware from 2019 to 2021, and officials discussed using it as part of their investigations before ultimately deciding against it.

The testing took place at one of Riva’s facilities in New Jersey, where the Pegasus system remains. The F.B.I. official said Pegasus was inactive because the bureau did not renew a license for its software.

When it purchased Pegasus, the bureau used a cover name for Riva Networks, Cleopatra Holdings, according to two people familiar with the contract. That name was also used in the November 2021 contract between Riva Networks and NSO for the purchase of Landmark, according to a copy reviewed by The Times.

Mr. Gamble, Riva’s chief executive, even signed the contract for Landmark under a pseudonym, William Malone, according to those people.

Unlike Pegasus, Landmark does not penetrate and extract data from cellphones. Instead, it tracks the location of individual people based on which cell tower their phone is communicating with.

Tracking a single person can result in hundreds or thousands of individual Landmark queries, or attempts to determine location at any given time.

In 2017, Saud al-Qahtani, a senior adviser to Saudi Arabia’s crown prince, used Landmark to track dissidents as part of the kingdom’s brutal campaign to crack down on its perceived enemies. Mr. Qahtani has also been identified as the person who orchestrated the killing of the Washington Post columnist Jamal Khashoggi in 2018.

In March, the White House issued an executive order restricting federal agencies from using spyware tools that have been abused by governments. Days later, a group of countries at the Summit for Democracy signed a joint statement of their commitment to reining in the abuses of hacking tools.

Then, weeks ago, the Biden administration blacklisted two companies that are at the center of a political scandal in Athens over the use of spyware against politicians and journalists. Both companies are controlled by an Israeli former general who has promoted them as competitors to NSO.

Despite growing attention by governments in the West to the dangers of commercial spyware, the tools continue to proliferate with new firms — which employ Israeli cyberintelligence veterans, some of whom worked for NSO — stepping in to fill the void from NSO’s blacklisting .

An investigation by Microsoft and Citizen Lab, a research organization based at the University of Toronto, recently linked malware produced by QuaDream, an Israeli firm, to hackings in numerous countries of journalists, political opposition figures and at least one worker for a nongovernmental organization.

QuaDream, like NSO and other commercial spyware firms, “employs complicated and opaque corporate practices that may be designed to evade public scrutiny and accountability,” the investigation found.

Mark Mazzetti is a Washington investigative correspondent, and a two-time Pulitzer Prize winner. He is the author of "The Way of the Knife: the C.I.A, a Secret Army, and a War at the Ends of the Earth."  More about Mark Mazzetti

Ronen Bergman is a staff writer for The New York Times Magazine, based in Tel Aviv. His latest book is “Rise and Kill First: The Secret History of Israel’s Targeted Assassinations,” published by Random House. More about Ronen Bergman

Adam Goldman reports on the F.B.I. and national security from Washington, D.C., and is a two-time Pulitzer Prize winner. He is the coauthor of “Enemies Within: Inside the NYPD's Secret Spying Unit and bin Laden's Final Plot Against America.”  More about Adam Goldman

A version of this article appears in print on  , Section A, Page 1 of the New York edition with the headline: F.B.I. Financed Use of Spy Tool U.S. Outlawed. Order Reprints | Today’s Paper | Subscribe
Who Paid for a Mysterious Spy Tool? The F.B.I., an F.B.I. Inquiry Found  The New York Times
Capitol riot suspect arrested near Obama's home will remain jailed until trial, judge rules  Yahoo News
Oppenheimer: The secrets he protected and the suspicions that ...  National Geographic
FBI director boasts that applications are 'up over 100%' in Florida after Matt Gaetz says people trusted the FBI 'more when J. Edgar Hoover was running the place'  Yahoo News
Think like a hacker to stay ahead of cyber threats  IT-Online
The Best True Crime to Stream Now  The New York Times
Russia's Urals crude hits $60/b price cap as OPEC+ output cuts bite  S&P Global
Donald Trump Calls Jack Smith 'Deranged,' Denies Security Tape Tampering Claims  Yahoo Finance UK
Pornography blackmail a growing online crime, police allege  MetroWest Daily News
The Rising Threat of Cyber Attacks on Global Critical Infrastructure ...  Fagen wasanni
Mar-a-Lago property manager to be arraigned in special counsel's classified documents probe  Yahoo! Voices
After His Mother Asked for Help, FBI Terrorism Sting Targets ...  The Intercept
Republicans Lose Their Minds Over Secret Service’s Findings on White House Coke Baggie  Yahoo News
Ray McGovern: Russia’s ‘Coup’ Is Actually Biden’s Disaster  Scheerpost.com

 

The News And Times Information Network - Blogs By Michael Novakhov - thenewsandtimes.blogspot.com
Phishing, Ransomware & Beyond: Seven types of Cyberattacks you should know  The Economic Times

Comments

Popular Posts

8:07 AM 9/5/2020 - Crossfire Hurricane Investigation: It was just a GAS! FBI is dead. The new Service is needed (they are always needed), with the completely different outlooks and mentality than in those present days Pinkertons but without their skills, acumen, and efficiency.

9:30 AM 9/11/2020 - Transverse Myelitis, Possible Adverse Reaction to COVID-19 Vaccine, Explained | Coronavirus Infects, Hijacks Brain - How Does It Work? | How Russia Updated Its Disinformation Playbook for 2020

7:09 AM 9/5/2020 - fbi surveillance Google News: Peter Strzok, Notorious Ex-G-Man, Explains Himself And Takes Aim At Trump

Audio Post - The Tip Of An Iceberg: Sexual Misconduct Within The FBI Is Exposed by AP! Investigate The Investigators who are nothing more and nothing less than a bunch of psychopaths, perverts, and child abusers. Abolish the FBI and put the criminal FBI agents in prison where they belong! The present crisis in America is the direct result of the FBI stupidity, treacherous incompetence and malfeasance.

11:16 AM 4/1/2020 - Look at the Coronavirus map of New York City, it speaks for itself: This is the real Collusion: Trump + Russian Mafia! They conspired to bring to reality the old dream of Trump's: to get rid of the NYC eyesore, its public housing projects, and to build the luxury housing instead, making themselves the tens of billions of bloody $$$.

7:26 AM 9/2/2020 - "That truncated FBI investigation that needs to be resumed immediately." (!!! - M.N.) | There Was No Russia Investigation.

10:06 AM 9/1/2020 - Trump to Visit Kenosha After Sparring with Biden Over Security

5:56 PM 3/29/2020 - Coronavirus Deaths in Germany: Is there a different, less virulent strain of the virus?! Did we do the comparison studies?

8:42 PM 4/1/2020 - Michael Novakhov – SharedNewsLinks℠: Coronavirus Could Spread Through Pipes in Buildings, Officials Fear

8:51 AM 8/30/2020 - "ванька встанька" - ("Teflon effect"): "Putin’s approval rating has jumped to one of its highest levels since February as Russia continues its recovery from the coronavirus outbreak".