A report by Canadian researchersย that repressive regimes are spying on dissidents with network intrusion software that masquerades as the Firefox browser has prompted Mozilla to fire off a cease and desist letter to the U.K. maker of the software.

โWe had identified instances where FinSpy makes use of Mozillaโs trademark and code,โ according to report by Citizen Lab researchers Morgan Marquis-Boire, Bill Marczak, Claudio Guarnieri and John Scott-Railton titled For Their Eyes Only: The Commercialization of Digital Spying. โThe latest Malay-language sample masquerades as Mozilla Firefox in both file properties and in manifest.โ
RELATED CONTENT
Whoโs using my spyware on Toronto servers?
5 nations, 5 firms named as โenemies of the Internetโ
FinSpy is a component in FinFisher.
The report said FinFisher command and control servers were recently found in Hungary, Turkey, Romania, Panama, Lithuania, Macedonia, South Africa, Pakistan, Nigeria, Bulgaria and Austria. Taking previous Citizen Lab research this places the total number of countries where FinFisher command and control centres have been located to 36.
โWe cannot abide a software company using our name to disguise software surveillance toll that can be โ and in several cases actually have been โ used by Gammaโs customers to violate citizensโ human rights and online privacy,โ according to Alex Fowler, the lead of Mozillaโs privacy and public policy group. โWeโve sent Gamma a cease and desist letter today demanding that these illegal practices stop immediately.โ
In a blog post yesterday, Fowler also assured browser users that Firefox itself is not affected by the spyware.
โIt is important to note that the spyware does not affect Firefox itself, either during the installation process or when it is operating covertly on a personโs computer or mobile device,โ Fowler said. โGammaโs software is entirely separate, and only uses our brand and trademark to lie and mislead as one of its methods of avoiding detection and deletion.โ
Citizen Lab said Gammaโs surveillance tools were used in a spyware attack in Bahrain aimed at pro-democracy activists as well as the upcoming general elections in Malaysia.
โEach sample demonstrates the exact same pattern of falsely designating spyware as originating from Mozilla,โ said Fowler. โGammaโs brochures and promotional video tout one of the essential features of its surveillance software is that it can be covertly deployed on the personโs system and remain undetected.โ
The Citizen Lab researchers also lamented the lack of controls on how such technologies are exported.
There is extremely limited candor from companies about the nature and scope of the due-diligence performed when sales are contemplated,โ according to the Citizen Lab report. โIn what has been referred to as a โpermissiveโ standard,ย companies have sometimes stated that they will only sell to states that are not on official blacklists established by the European Union or the United States.โ
However, companies have been โopaqueโ about what actions are being taken about cases in countries such as Morocoo, Bahrain, and the United Arab Emirates where there are cases of the technologies being abused, the report said .
Sponsor: SAS
Improving the State of Affairs With Analytics
Download this case study-rich white paper to learn why data management and analytics are so crucial in the public sector, and how to put it to work in your organization.
Register Now