Skip to main content

NSO has carried out 'unlawful' surveillance to target Amnesty staff members, HRDs


Counterview Desk
Following the exposure that Israeli spyware Pegasus, manufactured by NSO Group, has been used as a surveillance tool on smartphones used by about 1,500 human rights defenders (HRDs), journalists and activists, including in India, the top rights body, Amnesty International India, has appealed to those who have received a notification immediately to get in touch with Amnesty Tech at share@amnesty.tech for support.
An Amnesty release on November 2 said that the rights body could also be contacted “on Signal or WhatsApp at +44 7492 882216”, adding, “We would be keen to provide support to HRDs, who have been targeted, to ensure they take defensive security measures immediately, as well as to understand more about the attacks and investigate possible infections.”
Meanwhile, Amnesty has put out questions and answers for HRDs, activist, or journalist based in India to understand NSO Group’s spyware Pegasus especially the WhatsApp targeting.

Text:

Q: What do we know about the NSO Group and its ‘Pegasus’ Spyware?
A: ‘NSO Group’ is an Israeli spyware manufacturer that claims to sell its surveillance tools – the most well-known being its Pegasus spyware – exclusively to governments and government agencies ‘to combat terror and crime’.
Its products have been misused multiple times to conduct unlawful surveillance against human rights defenders. In the past, it has been used to target an Amnesty International staff member, HRDs, activists, and journalists from Saudi Arabia, UAE, Mexico, Morocco, and Rwanda.
Q: How does Pegasus work?
A: If infected by the Pegasus spyware, the user’s Smartphone is compromised. It can track keystrokes, take control of the phone’s camera and microphone, and access contact lists and encrypted messages.
Until now, Pegasus is known to be delivered through SMS messages carrying malicious links and through exploiting a zero-day vulnerability on WhatsApp. In the latter, intrusive spyware could be delivered on to the target’s mobile device without the targeted person having to click on a malicious link. The targeted person would simply see a missed call on WhatsApp.
In addition to this, Amnesty International has also found evidence of network injection attacks that could also be attributed to NSO Group. Network injection attacks are generally called “man-in-the-middle” attacks. Through this, an attacker with access to a target’s mobile network connection can monitor and opportunistically hijack web traffic and silently re-route the web browser to malicious exploit pages.
Q: How did the targeting via WhatsApp work?
A: NSO Group exploited a security vulnerability in WhatsApp until May 2019. In order to exploit this, the digital attack initiated WhatsApp calls to the target’s device. Attackers may have tried to exploit this issue by making calls multiple times during the night when the target was likely to be asleep and not notice these calls. Successful infection of the target’s device may result in the app crashing. There is a possibility that the attacker may also remotely erase evidence of these calls from the device’s call logs. Evidence of failed attacks may appear as missed calls from unknown numbers in your WhatsApp call log.
Q: If I didn’t receive a notification from WhatsApp, does this mean I wasn’t targeted by NSO Group’s tools?
A: NSO Group’s Pegasus tool is used for targeted attacks and by design, is not meant for mass surveillance. This means that only select individuals would have been targeted. However, if you are a high risk user, i.e., an activist, journalist, or HRD involved in politically sensitive activism, you cannot presume that you have not been targeted simply because you haven’t received a notification from WhatsApp.
The attack was delivered by exploiting a vulnerability in WhatsApp. However, NSO Pegasus infections can also be delivered through other means. Based on information revealed by our own investigations, an Amnesty International staffer was targeted using SMS messages. One HRD in Morocco was targeted both before and after the attacks using the WhatsApp exploit, but not with the WhatsApp exploit itself. Both of them were targeted using SMS messages containing malicious links and network injection attacks that could also be attributed to NSO Group’s tools. This indicates that NSO Group has the documented capability to deliver infections through means other than WhatsApp.
Q: If WhatsApp was targeted, can’t I just switch to another encrypted platform?
A: No. A vulnerability in the WhatsApp software was exploited to deliver the spyware. All complex software can have these types of vulnerabilities. This vulnerability was not a flaw in WhatsApp’s end-to-end encryption protocol.
This also does not mean that only the Whatsapp data of the target was compromised. If the attack attempt was successful, the spyware would gain full access to the device. Any other data on the device including encrypted platforms such as Signal or Telegram could then also have been accessed.
Q: Can Pegasus plant data into my devices?
A: Based on publicly available information, planting data is not a feature of NSO Group’s Pegasus spyware.
Q: What steps can I take to protect myself?
A: None of the security best practices offer complete and foolproof protection. However, it is a good practice to install the latest software updates of operating systems and encrypted messaging applications on your mobile device.
Pegasus remains a relatively uncommon threat and standard digital hygiene steps are still important. Keep your devices software up-to-date. Use a unique password for each service that you use and store these passwords in a secure password manager. Enable two-factor authentication on all accounts where it is available.

Comments

TRENDING

Urgent need to study cause of large number of natural deaths in Gulf countries

By Venkatesh Nayak* According to data tabled in Parliament in April 2018, there are 87.76 lakh (8.77 million) Indians in six Gulf countries, namely Bahrain, Kuwait, Oman, Qatar, Saudi Arabia and the United Arab Emirates (UAE). While replying to an Unstarred Question (#6091) raised in the Lok Sabha, the Union Minister of State for External Affairs said, during the first half of this financial year alone (between April-September 2018), blue-collared Indian workers in these countries had remitted USD 33.47 Billion back home. Not much is known about the human cost of such earnings which swell up the country’s forex reserves quietly. My recent RTI intervention and research of proceedings in Parliament has revealed that between 2012 and mid-2018 more than 24,570 Indian Workers died in these Gulf countries. This works out to an average of more than 10 deaths per day. For every US$ 1 Billion they remitted to India during the same period there were at least 117 deaths of Indian Workers in Gulf ...

A comrade in culture and controversy: Yao Wenyuan’s revolutionary legacy

By Harsh Thakor*  This year marks two important anniversaries in Chinese revolutionary history—the 20th death anniversary of Yao Wenyuan, and the 50th anniversary of his seminal essay "On the Social Basis of the Lin Biao Anti-Party Clique". These milestones invite reflection on the man whose pen ignited the first sparks of the Great Proletarian Cultural Revolution and whose sharp ideological interventions left an indelible imprint on the political and cultural landscape of socialist China.

India's health workers have no legal right for their protection, regrets NGO network

Counterview Desk In a letter to Union labour and employment minister Santosh Gangwar, the civil rights group Occupational and Environmental Health Network of India (OEHNI), writing against the backdrop of strike by Bhabha hospital heath care workers, has insisted that they should be given “clear legal right for their protection”.

Uttarakhand tunnel disaster: 'Question mark' on rescue plan, appraisal, construction

By Bhim Singh Rawat*  As many as 40 workers were trapped inside Barkot-Silkyara tunnel in Uttarkashi after a portion of the 4.5 km long, supposedly completed portion of the tunnel, collapsed early morning on Sunday, Nov 12, 2023. The incident has once again raised several questions over negligence in planning, appraisal and construction, absence of emergency rescue plan, violations of labour laws and environmental norms resulting in this avoidable accident.

History, culture and literature of Fatehpur, UP, from where Maulana Hasrat Mohani hailed

By Vidya Bhushan Rawat*  Maulana Hasrat Mohani was a member of the Constituent Assembly and an extremely important leader of our freedom movement. Born in Unnao district of Uttar Pradesh, Hasrat Mohani's relationship with nearby district of Fatehpur is interesting and not explored much by biographers and historians. Dr Mohammad Ismail Azad Fatehpuri has written a book on Maulana Hasrat Mohani and Fatehpur. The book is in Urdu.  He has just come out with another important book, 'Hindi kee Pratham Rachna: Chandayan' authored by Mulla Daud Dalmai.' During my recent visit to Fatehpur town, I had an opportunity to meet Dr Mohammad Ismail Azad Fatehpuri and recorded a conversation with him on issues of history, culture and literature of Fatehpur. Sharing this conversation here with you. Kindly click this link. --- *Human rights defender. Facebook https://www.facebook.com/vbrawat , X @freetohumanity, Skype @vbrawat

Job opportunities decreasing, wages remain low: Delhi construction workers' plight

By Bharat Dogra*   It was about 32 years back that a hut colony in posh Prashant Vihar area of Delhi was demolished. It was after a great struggle that the people evicted from here could get alternative plots that were not too far away from their earlier colony. Nirmana, an organization of construction workers, played an important role in helping the evicted people to get this alternative land. At that time it was a big relief to get this alternative land, even though the plots given to them were very small ones of 10X8 feet size. The people worked hard to construct new houses, often constructing two floors so that the family could be accommodated in the small plots. However a recent visit revealed that people are rather disheartened now by a number of adverse factors. They have not been given the proper allotment papers yet. There is still no sewer system here. They have to use public toilets constructed some distance away which can sometimes be quite messy. There is still no...

Women's rights leaders told to negotiate with Muslimness, as India's donor agencies shun the word Muslim

By A Representative Former vice-president Hamid Ansari has sharply criticized donor agencies engaged in nongovernmental development work, saying that they seek to "help out" marginalizes communities with their funds, but shy away from naming Muslims as the target group, something, he insisted, needs to change. Speaking at a book release function in Delhi, he said, since large sections of Muslims are poor, they need political as also social outreach.

Warning bells for India: Tribal exploitation by powerful corporate interests may turn into international issue

By Ashok Shrimali* Warning bells are ringing for India. Even as news drops in from Odisha that Adivasi villages, one after another, are rejecting the top UK-based MNC Vedanta's plea for mining, a recent move by two senior scholars Felix Padel and Samarendra Das suggests the way tribals are being exploited in India by powerful international and national business interests may become an international issue. In fact, one has only to count days when things may be taken up at the United Nations level, with India being pushed to the corner. Padel, it may be recalled, is a major British authority on indigenous peoples across the world, with several scholarly books to his credit. 

Gujarat Bitcoin scam worth Rs 5,000 crore "linked" with BJP leaders: Need for Supreme Court monitored probe

By Shaktisinh Gohil* BJP hit a jackpot in the form of demonetisation, which it used as an alibi to convert black money into white in Gujarat. Even as party scrambles for answers of how the Ahmedabad District Cooperative Bank (ADCB), whose director is BJP president Amit Shah, received old currency worth Rs 745.58 crore in just five days, and how Rs 3118.51 crore was deposited in 11 district cooperative banks linked with Gujarat BJP leaders, a new mega Bitcoin scam, worth more than Rs 5,000 crore has been unraveled.