Did you know that one way configurations are pushed to the #ForcedMDM CarrierConfig process can CHANGE the running processes so as to maintain persistence?

Persistence is the GOAL for #ForcedMDM

Disrupt that process & no persistence for the #malware , fact.

#infosec by #infosec_jcp

One of the key attributes of #StateSponsoredMalwareโ„ข from #GammaGroup's #FinFisher #FinSpy #Finsky is understanding that it is a shim based mish mash of resident files that point to different parts of the other background services running.

Some are replaced stock system files modified to look like and are named the same as the original but are supplemented with additional API's that call the mutiple shims that has as it's main goal of getting complete persistence on your systems if it has not done so already.

๐Ÿšฉ๐Ÿšฉ๐Ÿšฉ๐ŸšฉOne first sign is the battery drain this software uses. It has a weird side effect of NOT logging in this battery usage like normal applications and system. ๐Ÿšฉ๐Ÿšฉ๐Ÿšฉ๐Ÿšฉ

โš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจ
This BATTERY DRAIN is a HUGE
first indicator of compromise.
โš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจโš ๏ธ๐Ÿšจ

Second is checking the BACKGROUND programs running list. There are SEVERAL background programs that indicates you have been compromised by GammaGroup's software, especially on #Android , #IOS, #MacOS, #Windows, & #Linux.

There are attaccc features also which spread, from a library of PNGs with URL arrays embedded to their #malware services that launch attaccc's based on certain PSTN calls, web browsing & also MMS & SMS interactions.

For example, receiving an SMS or MMS can activate things on your computer or wireless device to do things like start a running process shim like start or restart specific services.

There is also a #MITM #ForcedMDM & #proxying ability to use your end point as an attaccc node completely behind the scenes without your intervention or knowledge unless you are logging your traffic which also could be bypassed also as has been seen previously. That is on purpose.

Continued..... #infosec #GreyMarket #CALEA #malware #investigations #RTDNA โ˜ฃ๏ธ๐Ÿ”๐Ÿง

@sambowne

Sam, this reads like some malware on your mobile phone manipulating your app. Check your handset. SrsLY

Put a firewall ๐Ÿ”ฅ on your handset full LogginG ON.

โœ“ Check if out have #ForcedMDM installed. โ˜ฃ๏ธ

โœ“ Check for a list of Proxies used as this could be a MITM thing.

@clive @mmasnick @charliejane

They _already_ do this for DECADES without oversight.... but are using #StateSponsoredMalwareโ„ข from #GammaGroup's #FinFisher #FinSpy #Finsky product line using #ForcedMDM and forced proxies for easy fisher price #MITM #malware exploitation for #civilrights & #humanrights #abuse.

The History of this is just #cointelpro๐Ÿค#COPSProgram๐Ÿค#FusionCenters๐Ÿค#Meta with even WORSE #ChurchCommittee findings since the technology has progressed. Worse. Abuses. Ever.

Domestic TORTURE programs โœ“

Whitelisted Financial Crimes โœ“

Whitelisted Felons attacking targets & the LEOs and the NGOs ignore it โœ“

Coordinated #GangStalking using homeless to attack people in their own home โœ“

Coordinated Break INS, same as was the case of #Watergate โœ“

Same Corruption but just more Pedophiles โœ“

Same generational pedophile families โœ“

#BadApples protecting the #BadApples โœ“

Same Players running it until they are caught, again โœ“

History Repeating โœ“

Dumb Cult doing Dumb Cult shit โœ“

Gaslighting, baby DARVO types โœ“

Fascists gonna Fash to lose that fashcash โœ“

This isn't new just ignored and getting worse because of their sociopathy & confidence that that can do it without recourse....

Until... ไน| ๏ฝฅ ใ€ฐ ๏ฝฅ |ใ„

Wait, isn't the order pass the House _first_ legislation wise THEN the Senate. Hmmm. Odd.

Weekly reminder about the slavery software for #HumanRightsAbuse used by IA's & the PDs & the coordinated #GangStalkers at #Meta & ignored by #CitizenLab, #EFF & the #ACLU also used in conjunction with domestic physical nightly torture sessions of tap, tap, tap, tap, tap borrowed from Chinese Torture techniques.

Whitelisted felons like homeless #ZachariahCrocker & child groomer #AprilPage have been documented using this software at Meta for financial crimes, physical break INS & coordinated harassment over 19+yrs now using fake accounts claiming to be their targets that they control as has been documented on camera during the pandemic.

They were also documented stealing #USPS mail ( open cases with the US Postmaster General ) as well as #FedEx & local Police Department who did nothing even with video evidence of the theft.

Home invasion case reported & covered up in case #21-144-0690 w/ #SJPD & get my RealID one month before it expired for fraud usage also & financial crimes on #Meta & Google Chat coordinated by Zachariah Crocker & April Page from Cisco Systems from 04/2020 - 11/2020 while I worked for #CiscoSystems HQ in Milpitas, CA. #AprilPage was my managers manager. She shared the same landlord as I did I found out, from their #BankOfAmerica monthly transactions to #ZhiZhang & #RenWaiYanZhang whom they coordinated the break INS with.

Multiple open cases with multiple agencies. Zero resolution.

#GammaGroup's #FinFisher #FinSpy #Finsky

#StateSponsoredMalwareโ„ข #ForcedMDM #SlaverySoftware #RTDNA #news #infosec

The ripple effect is just #ForcedMDM๐Ÿค๐Ÿค–๐Ÿค#FreeWebHostingCulture๐Ÿค#investigations wrapping up with a #news blurb posting about more arrests at #Meta. ๐Ÿ”๐Ÿง

@joxean @SwiftOnSecurity

The US version is

MarkovChain๐Ÿค#ForcedMDM๐Ÿค๐Ÿค–๐Ÿค๐ŸงŸโ€โ™‚๏ธ๐Ÿ”๐Ÿง

One common thing #StateSponsoredMalwareโ„ข from #GammaGroup . Com's #FinFisher #FinSpy #Finsky does is a downgrade attack on your encryption by using older protocols that are already compromised and also using port 80 over port 443 on web browsers at logins as well as replacing and utilizing different certificates with lower bits and easily broken ciphers so that you still have a green lock on your browser.

Libraries of overlay icons have also been found to overlay and replace icons on each os also mimicking icons that make you think you are using ' secure ' settings also for common programs for communications.

This software is commonly used for investigation purposes but it's been see also primarily used as a financial crime tool in the South Eastern United States in Red States attacking Blue States since 2015 when it's source code was hacked.

#infosec #SSMโ„ข #GammaGroup #FinFisher #FinSpy #Finsky #CALEA #CALEAmalwareโ„ข #greymarket #financialcrimes #investigations #ForcedMDM #MITM

Here's the #standalonecomplex version

I have a comic #shark themed #meme update from the trend analysis I have been working on for the past 4+yrs now that explains the behavior, literally, in #infosec terminology ๐Ÿคญ

๐Ÿฆˆโ˜ฃ๏ธ๐Ÿ‘‰โ˜ฃ๏ธ๐Ÿ“ณ
#GammaGroup #FinFisher #FinSpy #Finsky #ForcedMDM
๐Ÿฆˆโ˜ฃ๏ธ๐Ÿฆˆโ˜ฃ๏ธ๐Ÿ‘‰๐Ÿฆˆ๐Ÿ‘‰โ˜ฃ๏ธ๐Ÿ“ณ

@SmudgeTheInsultCat

I have a comic #shark themed #meme update from the trend analysis I have been working on for the past 4+yrs now that explains the behavior, literally, in #infosec terminology ๐Ÿคญ

๐Ÿฆˆโ˜ฃ๏ธ๐Ÿ‘‰โ˜ฃ๏ธ๐Ÿ“ณ
#GammaGroup #FinFisher #FinSpy #Finsky #ForcedMDM
๐Ÿฆˆโ˜ฃ๏ธ๐Ÿฆˆโ˜ฃ๏ธ๐Ÿ‘‰๐Ÿฆˆ๐Ÿ‘‰โ˜ฃ๏ธ๐Ÿ“ณ