Skip to content

Threat actor

Insanet

Last fetched

Insanet is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Insanet is an Israeli company that uses advertising technology to infiltrate devices and surveil users. Insanet reportedly collaborated with Candiru, an Israeli spyware manufacturer sanctioned in the US, to market their surveillance software, Sherlock, alongside Candiru's own spyware products. Unlike traditional spyware that exploits system vulnerabilities or requires user interaction, Sherlock embeds spyware into targeted advertisements. When these ads are displayed on a webpage viewed by the target, the spyware is silently installed on their device, including Windows computers, Android phones, and iPhones. Sherlock's capabilities include monitoring, data capture, and transmission, Insanet also worked with Israeli cyber-intelligence, cloud infiltration specialist Paragon, which claimed to have the power to remotely break into encrypted instant messaging communications through its tool Graphite. According to Haaretz, "the company is owned by former ranking members of the defense establishment, including a past head of the National Security Council, Dani Arditi." The same report by Haaretz also notes that "Insanet has succeeded in obtaining authorization from the Defense Ministry to sell their technology globally. It has already sold the capability to one country that is not a democracy."

Techniques by tactic

No ATT&CK techniques are recorded for Insanet in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Insanet today — this states the absence of a published link, not that Insanet has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Insanet into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.