US blacklists Israeli hacking tool vendor NSO Group
The US Commerce Department added Israel's NSO Group and Candiru to its trade blacklist on Wednesday, saying they sold spyware to foreign governments that used the equipment to target government officials, journalists and others.
Positive Technologies of Russia, and Computer Security Initiative Consultancy PTE. LTD, from Singapore, were also listed. The Department said they trafficked in cyber tools used to gain unauthorised access to computer networks.
The companies' addition to the list, for engaging in activities contrary to US national security or foreign policy interests, means that exports to them from U.S counterparts are restricted. It for instance makes it far harder for US security researchers to sell them information about computer vulnerabilities.
Read more: Hackers threaten to out Israeli LGBTQ dating site users
"We are not taking action against countries or governments where these entities are located," said a spokesperson for the US State Department.
Suppliers will need to apply for a license before selling to them, which are likely to be denied.
In the past, the NSO Group and Candiru have been accused of selling hacking tools to authoritarian regimes. NSO says it only sells its products to law enforcement and intelligence agencies and takes steps to curb abuse.
'Dismayed'
An NSO spokesperson said the company was "dismayed" by the decision since its technologies "support US national security interests and policies by preventing terrorism and crime, and thus we will advocate for this decision to be reversed".
NSO will present information regarding its rigorous compliance and human rights programs, "which already resulted in multiple terminations of contacts with government agencies that misused our products," the spokesperson said in an e-mailed statement to Reuters.
Also read: Top military official blames US, Israel for Iran cyberattack
The Israeli defence ministry, which grants export licenses to NSO, declined to comment on the matter.
Contact information for Candiru was not available.
The Biden administration imposed sanctions on Positive Technologies, a Russian cybersecurity firm, this year for providing support to Russian security services. The company denies any wrongdoing.
Spokespeople for Positive Technologies and Computer Security Initiative Consultancy PTE. LTD, also known as COSEINC, did not immediately respond to requests for comment.
A former US official familiar with Positive Technologies, who spoke on condition of anonymity, said the firm had helped establish computer infrastructure used in Russian cyberattacks on US organisations.
Export control experts say the designation could have a far broader impact on the listed companies than simply limiting their access to US technology.
"Many companies choose to avoid doing business with listed entities completely in order to eliminate the risk of an inadvertent violation and the costs of conducting complex legal analyses," said Kevin Wolf, former Assistant Secretary of Commerce for Export Administration during the Obama Administration.
The entity list was increasingly used for national security and foreign policy aims during the Trump administration. Chinese telecom company Huawei was added in 2019, cutting it off from some key US suppliers and making it difficult for them to produce mobile handsets.