Threat actor
Dataflow Security
Last fetched
Dataflow Security is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
Dataflow Security is an Italian firm that sells exploits to European and Middle Eastern intelligence agencies. The company is a regular presence at industry events like ISS World and has recruited talent from NSO Group. The firm was founded in 2019 and is headed by Italian national Luca Todesco, a prominent zero-day tracker. In 2020, one of Todesco's iPhone attack techniques, which he shared publicly with Chinese contacts, was reportedly used by China to spy on the Uyghur community, as documented by Forbes.
Techniques by tactic
No ATT&CK techniques are recorded for Dataflow Security in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Dataflow Security today — this states the absence of a published link, not that Dataflow Security has no infrastructure.
References
- https://www.intelligenceonline.com/surveillance--interception/2022/06/30/dataflow-security-tracks-down-vulnerabilities-for-europe-s-cyber-intelligence-companies%2C109796117-art?
- https://www.forbes.com/sites/thomasbrewster/2021/09/17/exodus-american-tech-helped-india-spy-on-china/
- https://www.atlanticcouncil.org/in-depth-research-reports/report/mythical-beasts-and-where-to-find-them-mapping-the-global-spyware-market-and-its-threats-to-national-security-and-human-rights/
- https://www.intelligenceonline.com/surveillance--interception/2022/10/27/dataflow-security-sets-up-new-forensics-company-in-new-york,109839003-art
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Dataflow Security into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.