Skip to main content

NSO has carried out 'unlawful' surveillance to target Amnesty staff members, HRDs


Counterview Desk
Following the exposure that Israeli spyware Pegasus, manufactured by NSO Group, has been used as a surveillance tool on smartphones used by about 1,500 human rights defenders (HRDs), journalists and activists, including in India, the top rights body, Amnesty International India, has appealed to those who have received a notification immediately to get in touch with Amnesty Tech at share@amnesty.tech for support.
An Amnesty release on November 2 said that the rights body could also be contacted “on Signal or WhatsApp at +44 7492 882216”, adding, “We would be keen to provide support to HRDs, who have been targeted, to ensure they take defensive security measures immediately, as well as to understand more about the attacks and investigate possible infections.”
Meanwhile, Amnesty has put out questions and answers for HRDs, activist, or journalist based in India to understand NSO Group’s spyware Pegasus especially the WhatsApp targeting.

Text:

Q: What do we know about the NSO Group and its ‘Pegasus’ Spyware?
A: ‘NSO Group’ is an Israeli spyware manufacturer that claims to sell its surveillance tools – the most well-known being its Pegasus spyware – exclusively to governments and government agencies ‘to combat terror and crime’.
Its products have been misused multiple times to conduct unlawful surveillance against human rights defenders. In the past, it has been used to target an Amnesty International staff member, HRDs, activists, and journalists from Saudi Arabia, UAE, Mexico, Morocco, and Rwanda.
Q: How does Pegasus work?
A: If infected by the Pegasus spyware, the user’s Smartphone is compromised. It can track keystrokes, take control of the phone’s camera and microphone, and access contact lists and encrypted messages.
Until now, Pegasus is known to be delivered through SMS messages carrying malicious links and through exploiting a zero-day vulnerability on WhatsApp. In the latter, intrusive spyware could be delivered on to the target’s mobile device without the targeted person having to click on a malicious link. The targeted person would simply see a missed call on WhatsApp.
In addition to this, Amnesty International has also found evidence of network injection attacks that could also be attributed to NSO Group. Network injection attacks are generally called “man-in-the-middle” attacks. Through this, an attacker with access to a target’s mobile network connection can monitor and opportunistically hijack web traffic and silently re-route the web browser to malicious exploit pages.
Q: How did the targeting via WhatsApp work?
A: NSO Group exploited a security vulnerability in WhatsApp until May 2019. In order to exploit this, the digital attack initiated WhatsApp calls to the target’s device. Attackers may have tried to exploit this issue by making calls multiple times during the night when the target was likely to be asleep and not notice these calls. Successful infection of the target’s device may result in the app crashing. There is a possibility that the attacker may also remotely erase evidence of these calls from the device’s call logs. Evidence of failed attacks may appear as missed calls from unknown numbers in your WhatsApp call log.
Q: If I didn’t receive a notification from WhatsApp, does this mean I wasn’t targeted by NSO Group’s tools?
A: NSO Group’s Pegasus tool is used for targeted attacks and by design, is not meant for mass surveillance. This means that only select individuals would have been targeted. However, if you are a high risk user, i.e., an activist, journalist, or HRD involved in politically sensitive activism, you cannot presume that you have not been targeted simply because you haven’t received a notification from WhatsApp.
The attack was delivered by exploiting a vulnerability in WhatsApp. However, NSO Pegasus infections can also be delivered through other means. Based on information revealed by our own investigations, an Amnesty International staffer was targeted using SMS messages. One HRD in Morocco was targeted both before and after the attacks using the WhatsApp exploit, but not with the WhatsApp exploit itself. Both of them were targeted using SMS messages containing malicious links and network injection attacks that could also be attributed to NSO Group’s tools. This indicates that NSO Group has the documented capability to deliver infections through means other than WhatsApp.
Q: If WhatsApp was targeted, can’t I just switch to another encrypted platform?
A: No. A vulnerability in the WhatsApp software was exploited to deliver the spyware. All complex software can have these types of vulnerabilities. This vulnerability was not a flaw in WhatsApp’s end-to-end encryption protocol.
This also does not mean that only the Whatsapp data of the target was compromised. If the attack attempt was successful, the spyware would gain full access to the device. Any other data on the device including encrypted platforms such as Signal or Telegram could then also have been accessed.
Q: Can Pegasus plant data into my devices?
A: Based on publicly available information, planting data is not a feature of NSO Group’s Pegasus spyware.
Q: What steps can I take to protect myself?
A: None of the security best practices offer complete and foolproof protection. However, it is a good practice to install the latest software updates of operating systems and encrypted messaging applications on your mobile device.
Pegasus remains a relatively uncommon threat and standard digital hygiene steps are still important. Keep your devices software up-to-date. Use a unique password for each service that you use and store these passwords in a secure password manager. Enable two-factor authentication on all accounts where it is available.

Comments

TRENDING

Whither space for the marginalised in Kerala's privately-driven townships after landslides?

By Ipshita Basu, Sudheesh R.C.  In the early hours of July 30 2024, a landslide in the Wayanad district of Kerala state, India, killed 400 people. The Punjirimattom, Mundakkai, Vellarimala and Chooralmala villages in the Western Ghats mountain range turned into a dystopian rubble of uprooted trees and debris.

Election bells ringing in Nepal: Can ousted premier Oli return to power?

By Nava Thakuria*  Nepal is preparing for a national election necessitated by the collapse of KP Sharma Oli’s government at the height of a Gen Z rebellion (youth uprising) in September 2025. The polls are scheduled for 5 March. The Himalayan nation last conducted a general election in 2022, with the next polls originally due in 2027.  However, following the dissolution of Nepal’s lower house of Parliament last year by President Ram Chandra Poudel, the electoral process began under the patronage of an interim government installed on 12 September under the leadership of retired Supreme Court judge Sushila Karki. The Hindu-majority nation of over 29 million people will witness more than 3,400 electoral candidates, including 390 women, representing 68 political parties as well as independents, vying for 165 seats in the 275-member House of Representatives.

Jayanthi Natarajan "never stood by tribals' rights" in MNC Vedanta's move to mine Niyamigiri Hills in Odisha

By A Representative The Odisha Chapter of the Campaign for Survival and Dignity (CSD), which played a vital role in the struggle for the enactment of historic Forest Rights Act, 2006 has blamed former Union environment minister Jaynaynthi Natarjan for failing to play any vital role to defend the tribals' rights in the forest areas during her tenure under the former UPA government. Countering her recent statement that she rejected environmental clearance to Vendanta, the top UK-based NMC, despite tremendous pressure from her colleagues in Cabinet and huge criticism from industry, and the claim that her decision was “upheld by the Supreme Court”, the CSD said this is simply not true, and actually she "disrespected" FRA.

Gig workers hold online strike on republic day; nationwide protests planned on February 3

By A Representative   Gig and platform service workers across the country observed a nationwide online strike on Republic Day, responding to a call given by the Gig & Platform Service Workers Union (GIPSWU) to protest what it described as exploitation, insecurity and denial of basic worker rights in the platform economy. The union said women gig workers led the January 26 action by switching off their work apps as a mark of protest.

'Condonation of war crimes against women and children’: IPSN on Trump’s Gaza Board

By A Representative   The India-Palestine Solidarity Network (IPSN) has strongly condemned the announcement of a proposed “Board of Peace” for Gaza and Palestine by former US President Donald J. Trump, calling it an initiative that “condones war crimes against children and women” and “rubs salt in Palestinian wounds.”

With infant mortality rate of 5, better than US, guarantee to live is 'alive' in Kerala

By Nabil Abdul Majeed, Nitheesh Narayanan   In 1945, two years prior to India's independence, the current Chief Minister of Kerala, Pinarayi Vijayan, was born into a working-class family in northern Kerala. He was his mother’s fourteenth child; of the thirteen siblings born before him, only two survived. His mother was an agricultural labourer and his father a toddy tapper. They belonged to a downtrodden caste, deemed untouchable under the Indian caste system.

Stands 'exposed': Cavalier attitude towards rushed construction of Char Dham project

By Bharat Dogra*  The nation heaved a big sigh of relief when the 41 workers trapped in the under-construction Silkyara-Barkot tunnel (Uttarkashi district of Uttarakhand) were finally rescued on November 28 after a 17-day rescue effort. All those involved in the rescue effort deserve a big thanks of the entire country. The government deserves appreciation for providing all-round support.

MGNREGA: How caste and power hollowed out India’s largest welfare law

By Sudhir Katiyar, Mallica Patel*  The sudden dismantling of MGNREGA once again exposes the limits of progressive legislation in the absence of transformation of a casteist, semi-feudal rural society. Over two days in the winter session, the Modi government dismantled one of the most progressive legislations of the UPA regime—the Mahatma Gandhi National Rural Employment Guarantee Act (MGNREGA).

MGNREGA’s limits and the case for a new rural employment framework

By Dr Jayant Kumar*  Rural employment programmes have played a pivotal role in shaping India’s socio-economic landscape . Beyond providing income security to vulnerable households, they have contributed to asset creation, village development, and social stability. However, persistent challenges—such as seasonal unemployment, income volatility, administrative inefficiencies, and corruption—have limited the transformative potential of earlier schemes.