Threat actor
Verint
Last fetched
Verint is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
U.S.-Israeli company Verint provides sophisticated eavesdropping equipment, including "monitoring centers" that allow for the interception, monitoring, and analysis of both targeted and mass communications across various networks. These systems are integrated into a country's communication infrastructure and are capable of intercepting phone calls and emails from millions of citizens, storing the data for analysis. Verint's technology is employed in over 75 countries and can be used for nationwide mass interception, voice identification, and data mining to build detailed profiles of individuals. Verint sold their technology to repressive regimes worldwide, including in Azerbaijan, Indonesia, South Sudan, Uzbekistan and Kazakhstan. The technology sold to Azerbaijan was reportedly used to identify the sexual orientations of individuals through social media, leading to the targeting and arrest of LGBTQ+ individuals. In Bahrain, Verint products have been used to gather data from social networks, contributing to the repression of dissidents for their online activities. Additionally, in Indonesia, Verint's technology has been employed to compile databases of LGBTQ+ rights activists and monitor religious minorities. Verint has also been linked to surveillance operations in South Sudan, where it provided communications interception equipment and support services to the government. This arrangement required the telecommunications company Vivacell to pay Verint over $762,000 to facilitate the interception of citizens' communications, as reported by Amnesty International.
Techniques by tactic
No ATT&CK techniques are recorded for Verint in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Verint today — this states the absence of a published link, not that Verint has no infrastructure.
References
- https://www.haaretz.com/israel-news/security-aviation/2023-02-28/ty-article/fake-friends-leak-reveals-israeli-firms-turning-social-media-into-spy-tech/00000186-7f75-d079-ade7-ff7507970000
- https://www.newsweek.com/israeli-companies-sell-surveillance-tech-and-knowledge-used-persecuting-1178084
- https://indianexpress.com/article/express-exclusive/us-surveillance-giants-network-of-operations-has-subsidiaries-in-india-9080622/
- https://cyberscoop.com/south-sudan-government-surveillance-verint-amnesty-international/
- https://www.forbes.com/sites/thomasbrewster/2020/12/11/exclusive-israeli-surveillance-companies-are-siphoning-masses-of-location-data-from-smartphone-apps/
- https://slate.com/technology/2013/01/verint-the-american-company-helping-governments-spy-on-billions-of-communications.html
- https://defensetalks.com/defence-intelligence-agency-procures-equipment-from-israeli-nso-group-rival-report/
- https://www.haaretz.com/israel-news/2018-10-20/ty-article-magazine/.premium/israels-cyber-spy-industry-aids-dictators-hunt-dissidents-and-gays/0000017f-e9a9-dc91-a17f-fdadde240000
- https://www.accessnow.org/wp-content/uploads/2021/08/Surveillance-Tech-Latam-Report.pdf
- https://www.privacyinternational.org/sites/default/files/2017-12/ShadowState_Espanol.pdf
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Verint into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.