{"id":80489,"date":"2015-02-23T15:19:08","date_gmt":"2015-02-23T13:19:08","guid":{"rendered":"http:\/\/businesstech.co.za\/news\/?p=80489"},"modified":"2015-02-23T16:54:18","modified_gmt":"2015-02-23T14:54:18","slug":"rogue-sars-unit-used-malware-to-spy-on-south-africans-report","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/trending\/80489\/rogue-sars-unit-used-malware-to-spy-on-south-africans-report\/","title":{"rendered":"Rogue Sars unit used malware to spy on South Africans: report"},"content":{"rendered":"<p>A\u00a0\u201ccovert unit\u201d within the South African Revenue Service used a surveillance software suite known as FinFisher to spy on the computer activities of its targets, Carte Blanche reported on 22 February 2015.<\/p>\n<p>FinFisher can collect screenshots, logs of keystrokes, audio from Skype calls, passwords, and other data, according to\u00a0reports\u00a0<a href=\"http:\/\/mybroadband.co.za\/news\/security\/77110-government-spyware-servers-in-south-africa-telkom-govt-mum.html\">by Citizen Lab<\/a>,\u00a0and WikiLeaks.<\/p>\n<p>News of Sars\u2019 use of spyware comes after the Sunday Times reported towards the end of 2014 that a secret unit inside South Africa\u2019s tax agency called the National Research Group (NRG) became a law unto itself.<\/p>\n<p>Members of this group reportedly worked to infiltrate the ANC, looked into non-tax related matters such as taxi violence, and were used to fight the business battles of friends and relatives of senior Sars officials.<\/p>\n<p>NRG was also allegedly ordered to follow top Sars officials like Leonard Radebe, Nandi Madiba, and Mandisa Mokoena to find information on them and destroy their careers.<\/p>\n<p>Following the Sunday Times report, <a href=\"http:\/\/www.timeslive.co.za\/local\/2015\/01\/23\/sars-suspends-pillay-for-second-time-in-two-months\" target=\"_blank\">Sars suspended<\/a> deputy commissioner Ivan Pillay and strategic planning and risk group executive Peter Richer. Recent media reports also suggest that spokesperson Adrian Lackay has resigned.<\/p>\n<h3 class=\"my-4\">FinFisher in South Africa<\/h3>\n<div id=\"attachment_80491\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"http:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/FinFisher-global-proliferation-April-2013.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-80491\" class=\"wp-image-80491\" src=\"http:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/FinFisher-global-proliferation-April-2013.jpg\" alt=\"FinFisher global proliferation - April 2013\" width=\"600\" height=\"332\" srcset=\"https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/FinFisher-global-proliferation-April-2013.jpg 1500w, https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/FinFisher-global-proliferation-April-2013-300x166.jpg 300w, https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/FinFisher-global-proliferation-April-2013-1024x567.jpg 1024w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><p id=\"caption-attachment-80491\" class=\"wp-caption-text\">FinFisher global proliferation &#8211; April 2013<\/p><\/div>\n<p>The fact that FinFisher spyware was being used in South Africa was first alluded to in April 2013 when Citizen Lab released a report saying that command and control (C&amp;C) servers for the software were\u00a0<a title=\"Government spyware servers in South Africa: Telkom, Govt mum\" href=\"http:\/\/mybroadband.co.za\/news\/security\/77110-government-spyware-servers-in-south-africa-telkom-govt-mum.html\">detected on Telkom\u2019s network<\/a>.<\/p>\n<p>Citizen Lab\u2019s report made headlines around the world because it revealed that one version of FinFisher\u2019s spyware programs masqueraded as Mozilla Firefox.<\/p>\n<p>While FinFisher didn\u2019t infect Firefox, it impersonated it to fool Windows and anti-virus programs into believing it was legitimate software.<\/p>\n<p>Mozilla slapped the company behind FinFisher with a cease-and-desist, demanding that it stop using Mozilla\u2019s trademarks and branding.<\/p>\n<h3 class=\"my-4\">FinFisher on the Telkom network<\/h3>\n<p>When Telkom was asked about the IP addresses where Citizen Lab found the FinFisher C&amp;C servers in South Africa, it said the addresses were part of the dynamic pool allocated to ADSL users.<\/p>\n<p>\u201cThese IP addresses are randomly assigned when ADSL users initiate an Internet session,\u201d a Telkom spokesperson said.<\/p>\n<p>\u201cThe ADSL customers need not be direct customers either. They could be accessing the Internet via ADSL services acquired through other licensed operators that retail ADSL.\u201d<\/p>\n<p>The South African Police Service, State Security Agency, and Department of Communications weren\u2019t able to confirm who was\u00a0running the FinFisher servers.<\/p>\n<h3 class=\"my-4\">South Africa and the WikiLeaks SpyFiles: the plot thickens<\/h3>\n<p><a  data-lightbox=\"post-image\" href=\"http:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/ZAR-FinFisher-client.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-80493\" src=\"http:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/ZAR-FinFisher-client.jpg\" alt=\"ZAR FinFisher client\" width=\"600\" height=\"375\" srcset=\"https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/ZAR-FinFisher-client.jpg 1920w, https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/ZAR-FinFisher-client-300x188.jpg 300w, https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2015\/02\/ZAR-FinFisher-client-1024x640.jpg 1024w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>Over the course of 2013 and 2014, WikiLeaks released additional information on the sale and use of FinFisher in South Africa.<\/p>\n<p>Initially WikiLeaks only revealed that employees of the suppliers of <a href=\"http:\/\/mybroadband.co.za\/news\/security\/86437-spyware-servers-in-sa-more-details-emerge.html\">FinFisher visited South Africa<\/a>during 2012 and 2013.<\/p>\n<p>Then, in September 2014, WikiLeaks released new documents asserting that the South African government spent over \u20ac2 million on FinFisher between 2009 and 2012.<\/p>\n<p>Sars was asked to confirm that its recently exposed covert unit had procured FinFisher, and whether the figures released by WikiLeaks were accurate.<\/p>\n<p>A spokesperson for the tax agency said\u00a0Sars was not prepared to comment on media speculation.<\/p>\n<p>\u201cWe have internal processes underway as regards the allegations of rogue behaviour by a small group of Sars staff, and will not jeopardise those processes by responding to each and every allegation as it is made to the media.\u201d<\/p>\n<p>This article was republished <a title=\"http:\/\/mybroadband.co.za\/news\/security\/119370-how-secret-sars-unit-spied-on-south-africans-report.html\" href=\"http:\/\/mybroadband.co.za\/news\/security\/119370-how-secret-sars-unit-spied-on-south-africans-report.html\" target=\"_blank\">with permission from MyBroadband<\/a>.<\/p>\n<h3 class=\"my-4\">More on\u00a0Sars<\/h3>\n<p><strong><a title=\"Permalink to FinFisher spyware servers in South Africa\" href=\"http:\/\/businesstech.co.za\/news\/general\/37268\/finfisher-spyware-servers-in-south-africa\/\" rel=\"bookmark\">FinFisher spyware servers in South Africa<\/a><\/strong><\/p>\n<p><strong><a title=\"Permalink to 5.32 million tax returns submitted: SARS\" href=\"http:\/\/businesstech.co.za\/news\/general\/75126\/5-32-million-tax-returns-submitted-sars\/\" rel=\"bookmark\">5.32 million tax returns submitted: SARS<\/a><\/strong><\/p>\n<p><strong><a title=\"Permalink to SARS reports 3.8 million tax returns\" href=\"http:\/\/businesstech.co.za\/news\/general\/73804\/sars-reports-3-8-million-tax-returns\/\" rel=\"bookmark\">SARS reports 3.8 million tax returns<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A &#8220;covert unit&#8221; within the South African Revenue Service used a surveillance software suite known as FinFisher to spy on the computer activities of its targets, Carte Blanche reported.<\/p>\n","protected":false},"author":12,"featured_media":80497,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[5781,26,3246,5785],"class_list":["post-80489","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trending","tag-finfisher","tag-headline","tag-sars","tag-spyware"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/80489","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=80489"}],"version-history":[{"count":5,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/80489\/revisions"}],"predecessor-version":[{"id":80545,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/80489\/revisions\/80545"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/80497"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=80489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=80489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=80489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}