PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Pay No Attention to the Server Behind the Proxy: Mapping FinFisher’s Continuing Proliferation

Posted on October 19, 2015June 26, 2025 by Dissent

From the good folks at CitizenLab:

This post describes the results of Internet scanning we recently conducted to identify the users of FinFisher, a sophisticated and user-friendly spyware suite sold exclusively to governments.  We devise a method for querying FinFisher’s “anonymizing proxies” to unmask the true location of the spyware’s master servers.  Since the master servers are installed on the premises of FinFisher customers, tracing the servers allows us to identify which governments are likely using FinFisher.  In some cases, we can trace the servers to specific entities inside a government by correlating our scan results with publicly available sources.  Our results indicate 32 countries where at least one government entity is likely using the spyware suite, and we are further able to identify 10 entities by name.  Despite the 2014 FinFisher breach, and subsequent disclosure of sensitive customer data, our scanning has detected more servers in more countries than ever before.

Read the full report on CitizenLab.

Thanks to Joe Cadillic for this link.

No related posts.

Category: Featured NewsSurveillance

Post navigation

← Federal regulators to require registration of recreational drones
Irish Data Protection Commissioner to investigate Max Schrems’ claims →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map

RSS Recent Posts at DataBreaches.net

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
©2025 PogoWasRight.org. All rights reserved.