Skip to main content

NSO has carried out 'unlawful' surveillance to target Amnesty staff members, HRDs


Counterview Desk
Following the exposure that Israeli spyware Pegasus, manufactured by NSO Group, has been used as a surveillance tool on smartphones used by about 1,500 human rights defenders (HRDs), journalists and activists, including in India, the top rights body, Amnesty International India, has appealed to those who have received a notification immediately to get in touch with Amnesty Tech at share@amnesty.tech for support.
An Amnesty release on November 2 said that the rights body could also be contacted “on Signal or WhatsApp at +44 7492 882216”, adding, “We would be keen to provide support to HRDs, who have been targeted, to ensure they take defensive security measures immediately, as well as to understand more about the attacks and investigate possible infections.”
Meanwhile, Amnesty has put out questions and answers for HRDs, activist, or journalist based in India to understand NSO Group’s spyware Pegasus especially the WhatsApp targeting.

Text:

Q: What do we know about the NSO Group and its ‘Pegasus’ Spyware?
A: ‘NSO Group’ is an Israeli spyware manufacturer that claims to sell its surveillance tools – the most well-known being its Pegasus spyware – exclusively to governments and government agencies ‘to combat terror and crime’.
Its products have been misused multiple times to conduct unlawful surveillance against human rights defenders. In the past, it has been used to target an Amnesty International staff member, HRDs, activists, and journalists from Saudi Arabia, UAE, Mexico, Morocco, and Rwanda.
Q: How does Pegasus work?
A: If infected by the Pegasus spyware, the user’s Smartphone is compromised. It can track keystrokes, take control of the phone’s camera and microphone, and access contact lists and encrypted messages.
Until now, Pegasus is known to be delivered through SMS messages carrying malicious links and through exploiting a zero-day vulnerability on WhatsApp. In the latter, intrusive spyware could be delivered on to the target’s mobile device without the targeted person having to click on a malicious link. The targeted person would simply see a missed call on WhatsApp.
In addition to this, Amnesty International has also found evidence of network injection attacks that could also be attributed to NSO Group. Network injection attacks are generally called “man-in-the-middle” attacks. Through this, an attacker with access to a target’s mobile network connection can monitor and opportunistically hijack web traffic and silently re-route the web browser to malicious exploit pages.
Q: How did the targeting via WhatsApp work?
A: NSO Group exploited a security vulnerability in WhatsApp until May 2019. In order to exploit this, the digital attack initiated WhatsApp calls to the target’s device. Attackers may have tried to exploit this issue by making calls multiple times during the night when the target was likely to be asleep and not notice these calls. Successful infection of the target’s device may result in the app crashing. There is a possibility that the attacker may also remotely erase evidence of these calls from the device’s call logs. Evidence of failed attacks may appear as missed calls from unknown numbers in your WhatsApp call log.
Q: If I didn’t receive a notification from WhatsApp, does this mean I wasn’t targeted by NSO Group’s tools?
A: NSO Group’s Pegasus tool is used for targeted attacks and by design, is not meant for mass surveillance. This means that only select individuals would have been targeted. However, if you are a high risk user, i.e., an activist, journalist, or HRD involved in politically sensitive activism, you cannot presume that you have not been targeted simply because you haven’t received a notification from WhatsApp.
The attack was delivered by exploiting a vulnerability in WhatsApp. However, NSO Pegasus infections can also be delivered through other means. Based on information revealed by our own investigations, an Amnesty International staffer was targeted using SMS messages. One HRD in Morocco was targeted both before and after the attacks using the WhatsApp exploit, but not with the WhatsApp exploit itself. Both of them were targeted using SMS messages containing malicious links and network injection attacks that could also be attributed to NSO Group’s tools. This indicates that NSO Group has the documented capability to deliver infections through means other than WhatsApp.
Q: If WhatsApp was targeted, can’t I just switch to another encrypted platform?
A: No. A vulnerability in the WhatsApp software was exploited to deliver the spyware. All complex software can have these types of vulnerabilities. This vulnerability was not a flaw in WhatsApp’s end-to-end encryption protocol.
This also does not mean that only the Whatsapp data of the target was compromised. If the attack attempt was successful, the spyware would gain full access to the device. Any other data on the device including encrypted platforms such as Signal or Telegram could then also have been accessed.
Q: Can Pegasus plant data into my devices?
A: Based on publicly available information, planting data is not a feature of NSO Group’s Pegasus spyware.
Q: What steps can I take to protect myself?
A: None of the security best practices offer complete and foolproof protection. However, it is a good practice to install the latest software updates of operating systems and encrypted messaging applications on your mobile device.
Pegasus remains a relatively uncommon threat and standard digital hygiene steps are still important. Keep your devices software up-to-date. Use a unique password for each service that you use and store these passwords in a secure password manager. Enable two-factor authentication on all accounts where it is available.

Comments

TRENDING

When democracy becomes a performance: The Tibetan exile experience

By Tseten Lhundup*  I was born in Bylakuppe, one of the largest Tibetan settlements in southern India. From childhood, I grew up in simple barracks, along muddy roads, and in fields with limited resources. Over the years, I have watched our democratic system slowly erode. Observing the recent budget session of the 17th Tibetan Parliament-in-Exile, these “democratic procedures” appear grand and orderly on the surface, yet in reality they amount to little more than empty formalities. The parliamentarians seem largely disconnected from the everyday struggles faced by ordinary exiled Tibetans like us.

Study links sanctions to 500,000 deaths annually leading to rise in global backlash

By Bharat Dogra  International opinion is increasingly turning against the expanding burden of sanctions imposed on a growing number of countries. These measures are contributing to humanitarian crises, intensifying domestic discord, and heightening international tensions, thereby increasing the risks of conflicts and wars. 

Dhurandhar: The Revenge — Blurring the line between fiction and political narrative

By Mohd. Ziyaullah Khan*  "Dhurandhar: The Revenge" does not wait to be remembered; it arrives almost on the heels of its predecessor, released on March 19, 2026, just months after the first film’s December 2025 debut. The speed of its arrival feels less like creative urgency and more like calculated timing—cinema responding not to storytelling rhythm but to the emotional climate of its audience. Director Aditya Dhar, along with actor Yami Gautam, appears acutely aware of this moment and how to harness it.

Beyond the island: Top mythologist reorients the geography of the Ramayana

By Jag Jivan   In a compelling new analysis that challenges conventional geographical assumptions about the ancient epic, writer and mythologist Devdutt Pattanaik has traced the roots of the Ramayana to the forests and river systems of Central and Eastern India, rather than the peninsular south or the modern island nation of Sri Lanka.

BJP accounts for 99% of political donations in Gujarat: Corporate giants dominate

By Jag Jivan   An analysis of the official data on donations received by national parties from Gujarat during the Financial Year 2024-25 reveals a staggering concentration of funding, with the Bharatiya Janata Party (BJP) accounting for nearly the entirety of the contributions. The data, compiled in a document titled "National Parties donations received from Gujarat during FY-2024-25," lists thousands of transactions, painting a detailed picture of the financial backing for political parties from one of India’s most industrially significant states.

Alarming decline in India's repair culture threatens circular economy goals: Study

By Jag Jivan  A comprehensive new study by environmental research and advocacy organisation Toxics Link has painted a worrying picture of India's fading repair culture, warning that the trend towards replacement over repair is accelerating the country's already critical e-waste crisis.

Captains extraordinaire: Ranking cricket’s most influential skippers

By Harsh Thakor*  Ranking the greatest cricket captains is a subjective exercise, often sparking passionate debate among fans. The following list is not merely a tally of wins and losses; it is an assessment of leadership’s deeper impact. My criteria fuse a captain’s playing record with their tactical skill, placing the highest consideration on their ability to reshape a team’s fortunes and inspire those around them. A captain who inherited a dominant empire is judged differently from one who resurrected a nation’s cricket from the doldrums. With that in mind, here is my perspective on the finest leaders the game has ever seen.

Swami Vivekananda's views on caste and sexuality were 'painfully' regressive

By Bhaskar Sur* Swami Vivekananda now belongs more to the modern Hindu mythology than reality. It makes a daunting job to discover the real human being who knew unemployment, humiliation of losing a teaching job for 'incompetence', longed in vain for the bliss of a happy conjugal life only to suffer the consequent frustration.

‘No merit’ in Chakraborty’s claims: Personal ethics talk sans details raises questions

By Jag Jivan  A recent opinion piece published in The Quint by Subhash Chandra Garg has raised questions over the circumstances surrounding the resignation of Atanu Chakraborty from HDFC Bank , with Garg stating that the exit “raises doubts about his own ‘ethics’.” Garg, currently Chief Policy Advisor at Subhanjali and former Secretary of the Department of Economic Affairs, Government of India, writes that the Reserve Bank of India ( RBI ) appears to find no substance in Chakraborty’s claims, noting, “It is clear the RBI sees no merit in Atanu Chakraborty’s wild and vague assertions.”