>[NSO Group] claims to sell its spyware only to law enforcement agencies to track terrorists, criminals and drug lords
>An NSO spokesman reiterated those restrictions in a statement Thursday, and said the company had no knowledge of the tracking of health researchers and advocates inside Mexico
>NSO executives point to technical safeguards that prevent clients from sharing its spy tools.
LE says to NSO that this infection will be used on a track terrorists, criminals and drug lords by ticking the "We will only send this to infect terrorists, criminals and drug lords" checkbox, NSO gen's the unique link that needs to be visited to infect the device and then either LE or NSO send the target the text.
In other discovered 0days the servers the links where pointing to were in control of the group selling the hacks and no LE. My bet is a part of the "controls" they have inplace is not actually handing over the exploits, but offering an "exploit as a service".
Ofcause that doesn't stop LE saying "Gen link for number X, number X belongs to a bad guy..." and number X being a device belonging to their own tech teams to reverse the exploit and then they create their own.
>[NSO Group] claims to sell its spyware only to law enforcement agencies to track terrorists, criminals and drug lords
>An NSO spokesman reiterated those restrictions in a statement Thursday, and said the company had no knowledge of the tracking of health researchers and advocates inside Mexico
>NSO executives point to technical safeguards that prevent clients from sharing its spy tools.
LE says to NSO that this infection will be used on a track terrorists, criminals and drug lords by ticking the "We will only send this to infect terrorists, criminals and drug lords" checkbox, NSO gen's the unique link that needs to be visited to infect the device and then either LE or NSO send the target the text.
In other discovered 0days the servers the links where pointing to were in control of the group selling the hacks and no LE. My bet is a part of the "controls" they have inplace is not actually handing over the exploits, but offering an "exploit as a service".
Ofcause that doesn't stop LE saying "Gen link for number X, number X belongs to a bad guy..." and number X being a device belonging to their own tech teams to reverse the exploit and then they create their own.