Loading…
Loading…
BIS published a final rule on November 4, 2021 adding four commercial surveillance and offensive cyber-tools companies to the Entity List under the Export Administration Regulations (EAR). The listing imposes a license requirement — under a policy of denial — for any export, re-export, or in-country transfer of items subject to the EAR to these entities, effectively cutting them off from US-origin technology.
NSO Group Technologies and Candiru (Israel): Both firms develop and sell commercial spyware to state clients. NSO Group's flagship product, Pegasus, was documented by researchers (Citizen Lab, Amnesty International) as having been deployed against journalists, human-rights activists, diplomats, and heads of government in multiple countries. Candiru markets similar implant tooling under different branding. BIS designated both for "developing and supplying spyware to foreign governments in order to maliciously target government officials, embassy workers, businesspeople, journalists, activists, and academics."
Positive Technologies (Russia): A Moscow-based cybersecurity firm that also stages conferences frequented by Russian intelligence contractors. It was previously designated by OFAC in April 2021 for supporting FSB cyber operations; BIS followed suit with an entity list designation covering EAR-controlled hardware and software exports. The designation reflects the Biden administration's linkage between commercial security research and state-backed offensive operations.
Computer Security Initiative Consultancy PTE (Singapore): Listed for "trafficking of cyber tools used to gain unauthorized access to information systems," consistent with activity as a broker or reseller of offensive intrusion tooling.