Skip to main content

NSO has carried out 'unlawful' surveillance to target Amnesty staff members, HRDs


Counterview Desk
Following the exposure that Israeli spyware Pegasus, manufactured by NSO Group, has been used as a surveillance tool on smartphones used by about 1,500 human rights defenders (HRDs), journalists and activists, including in India, the top rights body, Amnesty International India, has appealed to those who have received a notification immediately to get in touch with Amnesty Tech at share@amnesty.tech for support.
An Amnesty release on November 2 said that the rights body could also be contacted “on Signal or WhatsApp at +44 7492 882216”, adding, “We would be keen to provide support to HRDs, who have been targeted, to ensure they take defensive security measures immediately, as well as to understand more about the attacks and investigate possible infections.”
Meanwhile, Amnesty has put out questions and answers for HRDs, activist, or journalist based in India to understand NSO Group’s spyware Pegasus especially the WhatsApp targeting.

Text:

Q: What do we know about the NSO Group and its ‘Pegasus’ Spyware?
A: ‘NSO Group’ is an Israeli spyware manufacturer that claims to sell its surveillance tools – the most well-known being its Pegasus spyware – exclusively to governments and government agencies ‘to combat terror and crime’.
Its products have been misused multiple times to conduct unlawful surveillance against human rights defenders. In the past, it has been used to target an Amnesty International staff member, HRDs, activists, and journalists from Saudi Arabia, UAE, Mexico, Morocco, and Rwanda.
Q: How does Pegasus work?
A: If infected by the Pegasus spyware, the user’s Smartphone is compromised. It can track keystrokes, take control of the phone’s camera and microphone, and access contact lists and encrypted messages.
Until now, Pegasus is known to be delivered through SMS messages carrying malicious links and through exploiting a zero-day vulnerability on WhatsApp. In the latter, intrusive spyware could be delivered on to the target’s mobile device without the targeted person having to click on a malicious link. The targeted person would simply see a missed call on WhatsApp.
In addition to this, Amnesty International has also found evidence of network injection attacks that could also be attributed to NSO Group. Network injection attacks are generally called “man-in-the-middle” attacks. Through this, an attacker with access to a target’s mobile network connection can monitor and opportunistically hijack web traffic and silently re-route the web browser to malicious exploit pages.
Q: How did the targeting via WhatsApp work?
A: NSO Group exploited a security vulnerability in WhatsApp until May 2019. In order to exploit this, the digital attack initiated WhatsApp calls to the target’s device. Attackers may have tried to exploit this issue by making calls multiple times during the night when the target was likely to be asleep and not notice these calls. Successful infection of the target’s device may result in the app crashing. There is a possibility that the attacker may also remotely erase evidence of these calls from the device’s call logs. Evidence of failed attacks may appear as missed calls from unknown numbers in your WhatsApp call log.
Q: If I didn’t receive a notification from WhatsApp, does this mean I wasn’t targeted by NSO Group’s tools?
A: NSO Group’s Pegasus tool is used for targeted attacks and by design, is not meant for mass surveillance. This means that only select individuals would have been targeted. However, if you are a high risk user, i.e., an activist, journalist, or HRD involved in politically sensitive activism, you cannot presume that you have not been targeted simply because you haven’t received a notification from WhatsApp.
The attack was delivered by exploiting a vulnerability in WhatsApp. However, NSO Pegasus infections can also be delivered through other means. Based on information revealed by our own investigations, an Amnesty International staffer was targeted using SMS messages. One HRD in Morocco was targeted both before and after the attacks using the WhatsApp exploit, but not with the WhatsApp exploit itself. Both of them were targeted using SMS messages containing malicious links and network injection attacks that could also be attributed to NSO Group’s tools. This indicates that NSO Group has the documented capability to deliver infections through means other than WhatsApp.
Q: If WhatsApp was targeted, can’t I just switch to another encrypted platform?
A: No. A vulnerability in the WhatsApp software was exploited to deliver the spyware. All complex software can have these types of vulnerabilities. This vulnerability was not a flaw in WhatsApp’s end-to-end encryption protocol.
This also does not mean that only the Whatsapp data of the target was compromised. If the attack attempt was successful, the spyware would gain full access to the device. Any other data on the device including encrypted platforms such as Signal or Telegram could then also have been accessed.
Q: Can Pegasus plant data into my devices?
A: Based on publicly available information, planting data is not a feature of NSO Group’s Pegasus spyware.
Q: What steps can I take to protect myself?
A: None of the security best practices offer complete and foolproof protection. However, it is a good practice to install the latest software updates of operating systems and encrypted messaging applications on your mobile device.
Pegasus remains a relatively uncommon threat and standard digital hygiene steps are still important. Keep your devices software up-to-date. Use a unique password for each service that you use and store these passwords in a secure password manager. Enable two-factor authentication on all accounts where it is available.

Comments

TRENDING

Swami Vivekananda's views on caste and sexuality were 'painfully' regressive

By Bhaskar Sur* Swami Vivekananda now belongs more to the modern Hindu mythology than reality. It makes a daunting job to discover the real human being who knew unemployment, humiliation of losing a teaching job for 'incompetence', longed in vain for the bliss of a happy conjugal life only to suffer the consequent frustration.

Jayanthi Natarajan "never stood by tribals' rights" in MNC Vedanta's move to mine Niyamigiri Hills in Odisha

By A Representative The Odisha Chapter of the Campaign for Survival and Dignity (CSD), which played a vital role in the struggle for the enactment of historic Forest Rights Act, 2006 has blamed former Union environment minister Jaynaynthi Natarjan for failing to play any vital role to defend the tribals' rights in the forest areas during her tenure under the former UPA government. Countering her recent statement that she rejected environmental clearance to Vendanta, the top UK-based NMC, despite tremendous pressure from her colleagues in Cabinet and huge criticism from industry, and the claim that her decision was “upheld by the Supreme Court”, the CSD said this is simply not true, and actually she "disrespected" FRA.

Stands 'exposed': Cavalier attitude towards rushed construction of Char Dham project

By Bharat Dogra*  The nation heaved a big sigh of relief when the 41 workers trapped in the under-construction Silkyara-Barkot tunnel (Uttarkashi district of Uttarakhand) were finally rescued on November 28 after a 17-day rescue effort. All those involved in the rescue effort deserve a big thanks of the entire country. The government deserves appreciation for providing all-round support.

Urgent need to study cause of large number of natural deaths in Gulf countries

By Venkatesh Nayak* According to data tabled in Parliament in April 2018, there are 87.76 lakh (8.77 million) Indians in six Gulf countries, namely Bahrain, Kuwait, Oman, Qatar, Saudi Arabia and the United Arab Emirates (UAE). While replying to an Unstarred Question (#6091) raised in the Lok Sabha, the Union Minister of State for External Affairs said, during the first half of this financial year alone (between April-September 2018), blue-collared Indian workers in these countries had remitted USD 33.47 Billion back home. Not much is known about the human cost of such earnings which swell up the country’s forex reserves quietly. My recent RTI intervention and research of proceedings in Parliament has revealed that between 2012 and mid-2018 more than 24,570 Indian Workers died in these Gulf countries. This works out to an average of more than 10 deaths per day. For every US$ 1 Billion they remitted to India during the same period there were at least 117 deaths of Indian Workers in Gulf ...

Uttarakhand tunnel disaster: 'Question mark' on rescue plan, appraisal, construction

By Bhim Singh Rawat*  As many as 40 workers were trapped inside Barkot-Silkyara tunnel in Uttarkashi after a portion of the 4.5 km long, supposedly completed portion of the tunnel, collapsed early morning on Sunday, Nov 12, 2023. The incident has once again raised several questions over negligence in planning, appraisal and construction, absence of emergency rescue plan, violations of labour laws and environmental norms resulting in this avoidable accident.

Celebrating 125 yr old legacy of healthcare work of missionaries

Vilas Shende, director, Mure Memorial Hospital By Moin Qazi* Central India has been one of the most fertile belts for several unique experiments undertaken by missionaries in the field of education and healthcare. The result is a network of several well-known schools, colleges and hospitals that have woven themselves into the social landscape of the region. They have also become a byword for quality and affordable services delivered to all sections of the society. These institutions are characterised by committed and compassionate staff driven by the selfless pursuit of improving the well-being of society. This is the reason why the region has nursed and nurtured so many eminent people who occupy high positions in varied fields across the country as well as beyond. One of the fruits of this legacy is a more than century old iconic hospital that nestles in the heart of Nagpur city. Named as Mure Memorial Hospital after a British warrior who lost his life in a war while defending his cou...

New RTI draft rules inspired by citizen-unfriendly, overtly bureaucratic approach

By Venkatesh Nayak* The Department of Personnel and Training , Government of India has invited comments on a new set of Draft Rules (available in English only) to implement The Right to Information Act, 2005 . The RTI Rules were last amended in 2012 after a long period of consultation with various stakeholders. The Government’s move to put the draft RTI Rules out for people’s comments and suggestions for change is a welcome continuation of the tradition of public consultation. Positive aspects of the Draft RTI Rules While 60-65% of the Draft RTI Rules repeat the content of the 2012 RTI Rules, some new aspects deserve appreciation as they clarify the manner of implementation of key provisions of the RTI Act. These are: Provisions for dealing with non-compliance of the orders and directives of the Central Information Commission (CIC) by public authorities- this was missing in the 2012 RTI Rules. Non-compliance is increasingly becoming a major problem- two of my non-compliance cases are...

Pairing not with law but with perpetrators: Pavlovian response to lynchings in India

By Vikash Narain Rai* Lynch-law owes its name to James Lynch, the legendary Warden of Galway, Ireland, who tried, condemned and executed his own son in 1493 for defrauding and killing strangers. But, today, what kind of a person will justify the lynching for any reason whatsoever? Will perhaps resemble the proverbial ‘wrong man to meet at wrong road at night!’

Dowry over duty: How material greed shattered a seven-year bond

By Archana Kumar*  This account does not seek to expose names or tarnish identities. Its purpose is not to cast blame, but to articulate—with dignity—the silent suffering of a woman who lived her life anchored in love, trust, and duty, only to be ultimately abandoned.