Contd. Infecting Users with Malware TSG’s in-path injection capability system allows for sophisticated targeting of this malicious code for the specific user, facilitating on-the-fly modifications across a variety of file formats, including HTML, CSS, and JavaScript, in addition to Android APK files, Windows EXE files, macOS DMG disk images and Linux RPM packages. Furthermore, TSG can alter several image formats such as JPG, GIF, PNG and SVG, and various archive formats such as ZIP and RAR, along with office documents, PDF, JSON, and XML files. This is also complemented by Cyber Narrator, which possesses analytical functionalities that can identify the most appropriate URLs to hijack in order to infect specific individuals. For instance, it can target a person’s frequently visited websites that do not utilize Transport Layer Security (TLS). As an example of this capability, instead of just trying to guess how to target a user, Geedge’s government clients can go back in time to look at an internet user’s activities to see if they have previously done something that would make them vulnerable to having their device hacked, with the intention to infect them in the future by exploiting this vulnerability. DDoS As A Service The functionality described above can be used to infect users with mercenary spyware offered by any other company. However, it is notable that Geedge networks has attempted to weaponize this functionality themselves. One of the most bewildering offerings from Geedge Networks identified in the leaked dataset is DLL Active Defence, a product you might usually find in cybercrime black markets. At first glance, it appears to be a system designed to protect against Distributed Denial of Service (DDoS) attacks; however, a closer examination reveals that it is actually a platform for launching DDoS attacks against websites and other internet services deemed politically undesirable. This would appear to be Geedge's own implementation of China's Great Cannon, as described in a 2015 Citizen Lab report .13 This functionality means that, while the national firewall can block websites for citizens within a country, the DLL Active Defense function can make the website inaccessible for every internet user in the world, not just within the bounds of the national firewall. DLL accomplishes this by utilizing internet scanning to identify traffic amplification points, such as recursive DNS servers, which can serve as launch pads for reflective denial of service attacks. It uses the in-path injection capability in TSG to effectively recruit unsuspecting users' computers to participate in the attack, thereby creating a botnet. This marks the first confirmed instance of a cybersecurity company offering what is essentially a “booter” DDoS-for-hire solution to its clients.

Select target paragraph3