Skip to main content

NSO has carried out 'unlawful' surveillance to target Amnesty staff members, HRDs


Counterview Desk
Following the exposure that Israeli spyware Pegasus, manufactured by NSO Group, has been used as a surveillance tool on smartphones used by about 1,500 human rights defenders (HRDs), journalists and activists, including in India, the top rights body, Amnesty International India, has appealed to those who have received a notification immediately to get in touch with Amnesty Tech at share@amnesty.tech for support.
An Amnesty release on November 2 said that the rights body could also be contacted “on Signal or WhatsApp at +44 7492 882216”, adding, “We would be keen to provide support to HRDs, who have been targeted, to ensure they take defensive security measures immediately, as well as to understand more about the attacks and investigate possible infections.”
Meanwhile, Amnesty has put out questions and answers for HRDs, activist, or journalist based in India to understand NSO Group’s spyware Pegasus especially the WhatsApp targeting.

Text:

Q: What do we know about the NSO Group and its ‘Pegasus’ Spyware?
A: ‘NSO Group’ is an Israeli spyware manufacturer that claims to sell its surveillance tools – the most well-known being its Pegasus spyware – exclusively to governments and government agencies ‘to combat terror and crime’.
Its products have been misused multiple times to conduct unlawful surveillance against human rights defenders. In the past, it has been used to target an Amnesty International staff member, HRDs, activists, and journalists from Saudi Arabia, UAE, Mexico, Morocco, and Rwanda.
Q: How does Pegasus work?
A: If infected by the Pegasus spyware, the user’s Smartphone is compromised. It can track keystrokes, take control of the phone’s camera and microphone, and access contact lists and encrypted messages.
Until now, Pegasus is known to be delivered through SMS messages carrying malicious links and through exploiting a zero-day vulnerability on WhatsApp. In the latter, intrusive spyware could be delivered on to the target’s mobile device without the targeted person having to click on a malicious link. The targeted person would simply see a missed call on WhatsApp.
In addition to this, Amnesty International has also found evidence of network injection attacks that could also be attributed to NSO Group. Network injection attacks are generally called “man-in-the-middle” attacks. Through this, an attacker with access to a target’s mobile network connection can monitor and opportunistically hijack web traffic and silently re-route the web browser to malicious exploit pages.
Q: How did the targeting via WhatsApp work?
A: NSO Group exploited a security vulnerability in WhatsApp until May 2019. In order to exploit this, the digital attack initiated WhatsApp calls to the target’s device. Attackers may have tried to exploit this issue by making calls multiple times during the night when the target was likely to be asleep and not notice these calls. Successful infection of the target’s device may result in the app crashing. There is a possibility that the attacker may also remotely erase evidence of these calls from the device’s call logs. Evidence of failed attacks may appear as missed calls from unknown numbers in your WhatsApp call log.
Q: If I didn’t receive a notification from WhatsApp, does this mean I wasn’t targeted by NSO Group’s tools?
A: NSO Group’s Pegasus tool is used for targeted attacks and by design, is not meant for mass surveillance. This means that only select individuals would have been targeted. However, if you are a high risk user, i.e., an activist, journalist, or HRD involved in politically sensitive activism, you cannot presume that you have not been targeted simply because you haven’t received a notification from WhatsApp.
The attack was delivered by exploiting a vulnerability in WhatsApp. However, NSO Pegasus infections can also be delivered through other means. Based on information revealed by our own investigations, an Amnesty International staffer was targeted using SMS messages. One HRD in Morocco was targeted both before and after the attacks using the WhatsApp exploit, but not with the WhatsApp exploit itself. Both of them were targeted using SMS messages containing malicious links and network injection attacks that could also be attributed to NSO Group’s tools. This indicates that NSO Group has the documented capability to deliver infections through means other than WhatsApp.
Q: If WhatsApp was targeted, can’t I just switch to another encrypted platform?
A: No. A vulnerability in the WhatsApp software was exploited to deliver the spyware. All complex software can have these types of vulnerabilities. This vulnerability was not a flaw in WhatsApp’s end-to-end encryption protocol.
This also does not mean that only the Whatsapp data of the target was compromised. If the attack attempt was successful, the spyware would gain full access to the device. Any other data on the device including encrypted platforms such as Signal or Telegram could then also have been accessed.
Q: Can Pegasus plant data into my devices?
A: Based on publicly available information, planting data is not a feature of NSO Group’s Pegasus spyware.
Q: What steps can I take to protect myself?
A: None of the security best practices offer complete and foolproof protection. However, it is a good practice to install the latest software updates of operating systems and encrypted messaging applications on your mobile device.
Pegasus remains a relatively uncommon threat and standard digital hygiene steps are still important. Keep your devices software up-to-date. Use a unique password for each service that you use and store these passwords in a secure password manager. Enable two-factor authentication on all accounts where it is available.

Comments

TRENDING

Modi win may force Pak to put Kashmir on backburner, resume trade ties with India

By Salman Rafi Sheikh*  When Narendra Modi returned to power for a second term in India with a landslide victory in 2019, his government acted swiftly. Just months after the election, the Modi government abrogated Article 370 of the Constitution of India. In doing so, it stripped the special constitutional status conferred on Jammu and Kashmir, India’s only Muslim-majority state, and downgraded its status from a state with its own elected assembly to a union territory administered by the central government in Delhi. 

Stagnating wages since 2014-15: Economists explain Modi legacy for informal workers

By Our Representative  Real wages have barely risen in India since 2014-15, despite rapid GDP growth. The country’s social security system has also stagnated in this period. The lives of informal workers remain extremely precarious, especially in states like Jharkhand where casual employment is the main source of livelihood for millions. These are some of the findings presented by economists Jean Drèze and Reetika Khera at a press conference convened by the Loktantra Bachao 2024 campaign. 

A Hindu alternative to Valentine's Day? 'Shiv-Parvati was first love marriage in Universe'

By Rajiv Shah*   The other day, I was searching on Google a quote on Maha Shivratri which I wanted to send to someone, a confirmed Shiv Bhakt, quite close to me -- with an underlying message to act positively instead of being negative. On top of the search, I chanced upon an article in, imagine!, a Nashik Corporation site which offered me something very unusual. 

'Assault on civic, academic freedom, right to dissent': TISS PhD student's suspension

By Our Representative  The Mumbai-based civil rights group All India Secular Forum (AISF) has said that the suspension of Tata Institute of Social Sciences (TISS) PhD student Ramadas Prini Sivanandan (30) for two years for allegedly indulging in activities which were "not in the interest of the nation" is meant to send out the message that students and educational institutes will be targeted if they don’t align with the agenda and ideology of the ruling regime.  TISS in a notice served to Ramadas has cited that his role in screening the documentary 'Ram Ke Naam' on January 26 as a "mark of dishonour and protest" against the Ram Mandir idol consecration in Ayodhya.  Another incident cited in the notice was Ramadas’ participation in the protest against unfair government policies in Delhi under the banner of the Progressive Students' Forum (PSF)-TISS. TISS alleges the institute's name was "misused", which wrongfully created an impression that

Magnetic, stunning, Protima Bedi 'exposed' malice of sexual repression in society

By Harsh Thakor*  Protima Bedi was born to a baniya businessman and a Bengali mother as Protima Gupta in Delhi in 1949. Her father was a small-time trader, who was thrown out of his family for marrying a dark Bengali women. The theme of her early life was to rebel against traditional bondage. It was extraordinary how Protima underwent a metamorphosis from a conventional convent-educated girl into a freak. On October 12th was her 75th birthday; earlier this year, on August 18th it was her 25th death anniversary.

Tyre cartel's monopoly: Farmers' groups seek legal fight for better price for raw rubber

By Our Representative  The All India Kisan Sabha and the Kerala Karshaka Sangham that represents the largest rubber producing state of Kerala along with rubber farmers have sought intervention against the monopoly tyre companies that have formed a cartel against the interests of consumers and farmers.  Vijoo Krishnan, AIKS General Secretary, Valsan Panoli, Kerala Karshaka Sangham General Secretary, and four farmers representing different rubber growing regions of Kerala have filed an intervention application in the Supreme Court.

Joblessness, saffronisation, corporatisation of education: BJP 'squarely responsible'

Counterview Desk  In an open appeal to youth and students across India, several student and youth organizations from across India have said that the ruling party is squarely accountable for the issues concerning the students and the youth, including expensive education and extensive joblessness.

Why it's only Modi ki guarantee, not BJP's, and how Varanasi has seen it up-close

"Development" along Ganga By Rosamma Thomas*  I was in Varanasi in this April, days before polling began for the 2024 Lok Sabha elections. There are huge billboards advertising the Member of Parliament from Varanasi, Prime Minister Narendra Modi. The only image on all these large hoardings is of the PM, against a saffron background. It is as if the very person of Modi is what his party wishes to showcase.

Following the 3000-year old Pharaoh legacy? Poll-eve Surya tilak on Ram Lalla statue

By Sukla Sen  Located at a site called Abu Simbel in Nubia, Upper Egypt, the eponymous rock temples were created in 1244 BCE, under the orders of Pharaoh Ramesses II (1303-1213 BC)... Ramesses II was fond of showcasing his achievements. It was this desire to brag about his victory that led to the planning and eventual construction of the temples (interestingly, historians say that the Battle of Qadesh actually ended in a draw based on the depicted story -- not quite the definitive victory Ramesses II was making it out to be).

India's "welcome" proposal to impose sin tax on aerated drinks is part of to fight growing sugar consumption

By Amit Srivastava* A proposal to tax sugar sweetened beverages like tobacco in India has been welcomed by public health advocates. The proposal to increase sin taxes on aerated drinks is part of the recommendations made by India’s Chief Economic Advisor Arvind Subramanian on the upcoming Goods and Services Tax (GST) bill in the parliament of India.