Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Sweden accuses Russian hackers of attempting 'destructive' cyber attack on thermal power plant

April 15, 2026

Someone has put a backdoor into dozens of WordPress plugins used by thousands of websites.

April 14, 2026

Anthropic co-founder confirms the company briefed the Trump administration about Mythos

April 14, 2026
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    Google brings Pixel 6 and new devices to Material3 Expressive, along with other features, to the Pixel 6 and new devices

    September 3, 2025

    Google's NoteBookLM now allows you to customize the tone of your AI podcasts

    September 3, 2025

    Roblox expands the use of age estimation techniques and introduces standardized assessments

    September 3, 2025

    Instagram finally launches the iPad app

    September 3, 2025

    Complete the 2025 Confusion Builder Stage Agenda with the Maximum Scaling Voice

    September 3, 2025
  • Crypto

    Last 2 days to save up to $500 on Disrupt 2026 tickets

    April 9, 2026

    British cryptologist Adam Back denies NYT report that he is Bitcoin founder Satoshi Nakamoto

    April 8, 2026

    4 days left to save nearly $500 on Disrupt 2026 passes

    April 7, 2026

    Google paid startup Form Energy $1 billion for a high-capacity battery that lasts 100 hours.

    February 26, 2026

    Welcome to the post-hype crypto market

    February 25, 2026
  • Security

    Sweden accuses Russian hackers of attempting 'destructive' cyber attack on thermal power plant

    April 15, 2026

    Someone has put a backdoor into dozens of WordPress plugins used by thousands of websites.

    April 14, 2026

    Anthropic co-founder confirms the company briefed the Trump administration about Mythos

    April 14, 2026

    Adobe fixes zero-day PDF security bug that hackers have been exploiting for months

    April 14, 2026

    FBI announces suspension of phishing operation that targeted thousands of victims

    April 13, 2026
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    Financial risk management platform Pillar raises $20 million in seed round led by a16z

    April 14, 2026

    StrictlyVC San Francisco is less than a month away

    April 14, 2026

    Vercel CEO Guillermo Rauch suggests AI agent is ready for IPO as revenue soars

    April 13, 2026

    Nvidia-backed SiFive open AI chip reaches $3.65 billion valuation

    April 11, 2026

    Last 24 hours: Save up to $500 on Disrupt 2026 passes

    April 10, 2026
TechBrunchTechBrunch

Hacking group targeting Android devices and iCloud backups arrested

TechBrunchBy TechBrunchApril 8, 20264 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


Security researchers announced that they have identified a hacking group targeting journalists, activists, and government officials in the Middle East and North Africa. The hacker used a phishing attack to access the target's iCloud backups and messaging accounts on Signal, and introduced Android spyware that could take over the target's device.

This hacking campaign highlights the growing trend of government agencies outsourcing hacking tasks to private hacking rental companies. Some governments already rely on commercial companies that develop spyware and exploits that police and intelligence agencies use to access data on citizens' cellphones.

Researchers from digital rights organization Access Now documented three incidents of attacks against two Egyptian journalists and one Lebanese journalist between 2023 and 2025, which were also documented by digital rights organization SMEX.

Mobile cybersecurity company Lookout also investigated these attacks. The three organizations collaborated with each other and released separate reports on Wednesday.

According to Lookout, the attacks have gone beyond civil society members in Egypt and Lebanon to include targets in the Bahrain and Egyptian governments, as well as targets in the United Arab Emirates, Saudi Arabia, the United Kingdom, and in some cases, the United States and alumni of American universities.

Lookout concluded that the hackers behind this hacking campaign are working for a hack-for-hire vendor that researchers have codenamed “BITTER,” and that the investigating cybersecurity firm suspects the vendor has ties to the Indian government.

Justin Albrecht, lead researcher at Lookout, told TechCrunch that the company behind BITTER could be called RebSec Solutions, and could be an offshoot of Indian hacking-for-hire startup Appin. In 2022 and 2023, Reuters published an extensive investigation into Appin and other similar India-based companies, exposing how these companies were allegedly hired to hack corporate executives, politicians, military personnel and others.

tech crunch event

San Francisco, CA | October 13-15, 2026

Although Appin appears to have since shut down, Albrecht said the discovery of this new hacking operation shows that it “hasn't disappeared, it's just moved to smaller companies.”

These groups and their customers are subject to “plausible deniability, as they run all operations and infrastructure.” And for customers, Albrecht said, these specialized hacking groups are likely to be cheaper than purchasing commercial spyware.

RebSec has deleted its social media accounts and website and could not be reached for comment.

Contact Us Want more information about RedSec Solutions? Or another specialized hacking company? You can contact Lorenzo Franceschi-Bicchierai securely from your non-work device on Signal (+1 917 257 1382), on Telegram and Keybase @lorenzofb, or by email.

“These operations have become cheaper and allow them to avoid liability, especially since we don't know who the end customer is and the infrastructure does not reveal the entity behind it,” said Mohammed Al Maskati, researcher and director of Access Now's Digital Security Helpline, who worked on these cases.

Groups like BITTER may not have the most advanced hacking and spying tools, but their tactics are still highly effective.

In the attack portion of this campaign, the hackers used several different techniques. When targeting iPhone users, the hackers attempted to trick the targets into relinquishing their Apple ID credentials and hack into their iCloud backups, effectively giving them access to the entire contents of the target's iPhone.

According to Access Now, this “could be a cheaper alternative to using more sophisticated and expensive iOS spyware.”

When targeting Android users, the hackers used spyware called ProSpy to impersonate popular messaging and communication apps such as Signal, WhatsApp, and Zoom, as well as two apps popular in the Middle East: ToTok and Botim.

In some cases, hackers attempted to trick victims into registering and adding new hacker-controlled devices to their Signal accounts. This technique is common among various hacking groups, including Russian spies.

A spokesperson for the Indian embassy in Washington, D.C., did not respond to a request for comment.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Sweden accuses Russian hackers of attempting 'destructive' cyber attack on thermal power plant

April 15, 2026

Someone has put a backdoor into dozens of WordPress plugins used by thousands of websites.

April 14, 2026

Anthropic co-founder confirms the company briefed the Trump administration about Mythos

April 14, 2026

Adobe fixes zero-day PDF security bug that hackers have been exploiting for months

April 14, 2026

FBI announces suspension of phishing operation that targeted thousands of victims

April 13, 2026

Booking.com confirms hackers accessed customer data

April 13, 2026

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

Sweden accuses Russian hackers of attempting 'destructive' cyber attack on thermal power plant

April 15, 2026

Someone has put a backdoor into dozens of WordPress plugins used by thousands of websites.

April 14, 2026

Anthropic co-founder confirms the company briefed the Trump administration about Mythos

April 14, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2026 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.