Skip to main content

NSO has carried out 'unlawful' surveillance to target Amnesty staff members, HRDs


Counterview Desk
Following the exposure that Israeli spyware Pegasus, manufactured by NSO Group, has been used as a surveillance tool on smartphones used by about 1,500 human rights defenders (HRDs), journalists and activists, including in India, the top rights body, Amnesty International India, has appealed to those who have received a notification immediately to get in touch with Amnesty Tech at share@amnesty.tech for support.
An Amnesty release on November 2 said that the rights body could also be contacted “on Signal or WhatsApp at +44 7492 882216”, adding, “We would be keen to provide support to HRDs, who have been targeted, to ensure they take defensive security measures immediately, as well as to understand more about the attacks and investigate possible infections.”
Meanwhile, Amnesty has put out questions and answers for HRDs, activist, or journalist based in India to understand NSO Group’s spyware Pegasus especially the WhatsApp targeting.

Text:

Q: What do we know about the NSO Group and its ‘Pegasus’ Spyware?
A: ‘NSO Group’ is an Israeli spyware manufacturer that claims to sell its surveillance tools – the most well-known being its Pegasus spyware – exclusively to governments and government agencies ‘to combat terror and crime’.
Its products have been misused multiple times to conduct unlawful surveillance against human rights defenders. In the past, it has been used to target an Amnesty International staff member, HRDs, activists, and journalists from Saudi Arabia, UAE, Mexico, Morocco, and Rwanda.
Q: How does Pegasus work?
A: If infected by the Pegasus spyware, the user’s Smartphone is compromised. It can track keystrokes, take control of the phone’s camera and microphone, and access contact lists and encrypted messages.
Until now, Pegasus is known to be delivered through SMS messages carrying malicious links and through exploiting a zero-day vulnerability on WhatsApp. In the latter, intrusive spyware could be delivered on to the target’s mobile device without the targeted person having to click on a malicious link. The targeted person would simply see a missed call on WhatsApp.
In addition to this, Amnesty International has also found evidence of network injection attacks that could also be attributed to NSO Group. Network injection attacks are generally called “man-in-the-middle” attacks. Through this, an attacker with access to a target’s mobile network connection can monitor and opportunistically hijack web traffic and silently re-route the web browser to malicious exploit pages.
Q: How did the targeting via WhatsApp work?
A: NSO Group exploited a security vulnerability in WhatsApp until May 2019. In order to exploit this, the digital attack initiated WhatsApp calls to the target’s device. Attackers may have tried to exploit this issue by making calls multiple times during the night when the target was likely to be asleep and not notice these calls. Successful infection of the target’s device may result in the app crashing. There is a possibility that the attacker may also remotely erase evidence of these calls from the device’s call logs. Evidence of failed attacks may appear as missed calls from unknown numbers in your WhatsApp call log.
Q: If I didn’t receive a notification from WhatsApp, does this mean I wasn’t targeted by NSO Group’s tools?
A: NSO Group’s Pegasus tool is used for targeted attacks and by design, is not meant for mass surveillance. This means that only select individuals would have been targeted. However, if you are a high risk user, i.e., an activist, journalist, or HRD involved in politically sensitive activism, you cannot presume that you have not been targeted simply because you haven’t received a notification from WhatsApp.
The attack was delivered by exploiting a vulnerability in WhatsApp. However, NSO Pegasus infections can also be delivered through other means. Based on information revealed by our own investigations, an Amnesty International staffer was targeted using SMS messages. One HRD in Morocco was targeted both before and after the attacks using the WhatsApp exploit, but not with the WhatsApp exploit itself. Both of them were targeted using SMS messages containing malicious links and network injection attacks that could also be attributed to NSO Group’s tools. This indicates that NSO Group has the documented capability to deliver infections through means other than WhatsApp.
Q: If WhatsApp was targeted, can’t I just switch to another encrypted platform?
A: No. A vulnerability in the WhatsApp software was exploited to deliver the spyware. All complex software can have these types of vulnerabilities. This vulnerability was not a flaw in WhatsApp’s end-to-end encryption protocol.
This also does not mean that only the Whatsapp data of the target was compromised. If the attack attempt was successful, the spyware would gain full access to the device. Any other data on the device including encrypted platforms such as Signal or Telegram could then also have been accessed.
Q: Can Pegasus plant data into my devices?
A: Based on publicly available information, planting data is not a feature of NSO Group’s Pegasus spyware.
Q: What steps can I take to protect myself?
A: None of the security best practices offer complete and foolproof protection. However, it is a good practice to install the latest software updates of operating systems and encrypted messaging applications on your mobile device.
Pegasus remains a relatively uncommon threat and standard digital hygiene steps are still important. Keep your devices software up-to-date. Use a unique password for each service that you use and store these passwords in a secure password manager. Enable two-factor authentication on all accounts where it is available.

Comments

TRENDING

Gujarat's high profile GIFT city 'fails to attract' funds, India's FinTech investment dips

By Rajiv Shah  While the Narendra Modi government may have gone out of the way to promote the Gujarat International Finance Tec-City (GIFT City), sought to be developed as India’s formidable financial technology hub off the state capital Gandhinagar, just 20 km from Ahmedabad, a recent report , prepared by Tracxn Technologies suggests that neither of the two cities figure in the list of top FinTech funding receiving centres.

A Hindu alternative to Valentine's Day? 'Shiv-Parvati was first love marriage in Universe'

By Rajiv Shah*   The other day, I was searching on Google a quote on Maha Shivratri which I wanted to send to someone, a confirmed Shiv Bhakt, quite close to me -- with an underlying message to act positively instead of being negative. On top of the search, I chanced upon an article in, imagine!, a Nashik Corporation site which offered me something very unusual. 

Why Ramdev, vaccine producing pharma companies and government are all at fault

By Colin Gonsalves*  It was perhaps Ramdev’s closeness to government which made him over-confident. According to reports he promoted a cure for Covid, thus directly contravening various provisions of The Drugs and Magic Remedies (Objectionable Advertisements) Act, 1954. Persons convicted of such offences may not get away with a mere apology and would suffer imprisonment.

Malayalam movie Aadujeevitham: Unrealistic, disservice to pastoralists

By Rosamma Thomas*  The Malayalam movie 'Aadujeevitham' (Goat Life), currently screening in movie theatres in Kerala, has received positive reviews and was featured also on the website of the British Broadcasting Corporation. The story is based on a 2008 novel by Benyamin, and relates the real-life story of a job-seeker from Kerala tricked into working in slave conditions in a goat farm in Saudi Arabia.

Decade long Modi rule 'undermines' people's welfare and democracy

By Ram Puniyani*  Modi has many ploys up his sleeves when it comes to propaganda. On one hand he is turning many a pronouncements of Congress in the communal direction, on the other he is claiming that whatever has been achieved during last ten years of his rule is phenomenal, but it is still a ‘trailer’ and the bigger things are in the offing as he claims to be coming to power yet again in 2024. While his admirers are ga ga about his achievements, the truth lies somewhere else.

Belgian report alleges MNC Etex responsible for asbestos pollution in Madhya Pradesh town Kymore: COP's Geneva meet

By Our Representative A comprehensive Belgian report has held MNC Etex , into construction business and one of the richest, responsible for asbestos pollution in Kymore, an industrial town in in Katni district of Madhya Pradesh. The report provides evidence from the ground on how Kymore’s dust even today is “annoying… it creeps into your clothes, you have to cough it”, saying “It can be deadly.”

Plagued by opportunism, adventurism, tailism, Left 'doesn't matter' in India

By Harsh Thakor*  2024 elections are starting when India appears to be on the verge of turning proto-fascist. The Hindutva saffron brigade has penetrated in every sphere of Indian life, every social order, destroying and undermining the very fabric of the Constitution.

Can universal basic income help usher in sustainable egalitarianism in India?

By Prof RR Prasad*  The ongoing debate on application of Article 39(b) in the Supreme Court on redistribution of community material resources to subserve common good and for ushering in an egalitarian society has opened new vistas wherein possible available alternative solutions could be explored.

Ahmedabad's Muslim ghetto voters 'denied' right to exercise franchise?

By Tanushree Gangopadhyay*  Sections of Gujarat Muslims, with a population of 10 per cent of the State, have been allegedly denied their rights to exercise their franchise in the Juhapura area of Ahmedabad.

Press freedom? 28 journalists killed since 2014, nine currently in jail

By Kirity Roy*  On the eve of the Press Freedom Day on 3rd of May, the Banglar Manabadhikar Suraksha Mancha (MASUM) shared its anxiety with the broader civil society platforms as the situation of freedom of any form of expression became grimmer in India day by day. This day was intended to raise awareness on the importance of freedom of press and to pay tribute to pressmen who lost their lives in the line of duty.