Citizen Lab reported that Hacking Team’s Remote Control System (RCS), a commercial spyware platform marketed as “untraceable” and sold to governments, could be mapped through analysis of its proxy-chain infrastructure. The research linked suspected current or former RCS use to 21 governments, including Azerbaijan, Egypt, Ethiopia, Italy, Mexico, Morocco, Saudi Arabia, Sudan, Turkey, the UAE, and Uzbekistan, and showed how traffic passed through intermediary servers before reaching government-operated endpoints. The report also tied exploit-laden documents and shared staging behavior to a likely common commercial exploit supplier, while documenting attacks against dissidents, journalists, and activists such as Mamfakinch in Morocco, Ahmed Mansoor in the UAE, and Ethiopian journalists in Washington, DC.
Separate technical analysis presented by ESET found that Hacking Team’s spyware development continued after the company’s 2015 breach, with post-leak RCS samples compiled between 2015 and 2017 observed in 14 countries. Researchers said the malware preserved Hacking Team’s two-stage Scout and Soldier/Elite architecture and surveillance functions including screenshot capture, password theft, keylogging, camera activation, Skype call recording, and Wi-Fi-based geolocation. Attribution to Hacking Team developers was supported by code continuity, compilation patterns, versioning, and a chain of six signing certificates, including certificates linked to co-founder Valeriano Bedeschi, indicating the company’s spyware ecosystem remained active despite public exposure and source-code leakage.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
ESET concluded with high confidence that post-2015 RCS samples seen in the wild were developed by Hacking Team's own developers rather than unrelated actors reusing leaked code.
The latest post-leak Hacking Team spyware samples analyzed by ESET were compiled in October 2017, extending observed development well beyond the 2015 breach.
Citizen Lab provided ESET with RCS samples used in 2016 and 2017 for analysis of post-leak Hacking Team activity.
Callisto Group reused leaked Hacking Team source code in a campaign in January 2016.
ESET identified post-leak Hacking Team spyware samples that were slightly modified from pre-leak variants, with analyzed samples compiled between September 2015 and October 2017.
After the 2015 breach, Hacking Team asked its customers to suspend use of the Remote Control System.
Hacking Team suffered a major breach that exposed about 400GB of internal data, including spyware source code, exploits, customer information, and internal communications.
Citizen Lab analyzed Hacking Team's Remote Control System and showed that its supposedly untraceable proxy-chain infrastructure could be mapped to suspected government operators. The report identified 21 suspected current or former government users and highlighted targeting linked to countries with serious human rights concerns.
Citizen Lab identified an RCS endpoint in Azerbaijan at 109.235.193.83 hosted by Azertelekom and observed it active between June and November 2013.
Hacking Team, an Italian spyware vendor that sold surveillance tools to governments and government agencies, was founded in 2003.
ESET notified VMProtect's developers and asked them to blacklist the license used to pack the spyware, but no action was taken.
ESET discovered newer Hacking Team spyware samples signed with a previously unseen valid digital certificate and later found six certificates used in succession, including certificates tied to Hacking Team personnel.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.