Tag: NSO Group

  • Israeli Spyware Firm Odered to Pay $167 Million for WhatsApp Hack

    Israeli Spyware Firm Odered to Pay $167 Million for WhatsApp Hack

    A US federal jury ordered Israeli spyware company NSO Group to pay more than $167 million in damages for hacking the devices of approximately 1,400 WhatsApp users in 2019 using its Pegasus software.

    The verdict delivered Tuesday after a five-year legal battle includes $167.25 million in punitive damages and $445,000 in compensatory damages to WhatsApp and its parent company, Meta.

    The US District Court for the Northern District of California rejected NSO Group’s claim of sovereign immunity as a private company, finding that the Pegasus spyware exploited vulnerabilities in WhatsApp’s platform.

    The Pegasus tool enabled “zero-click” attacks that could infect devices without any user interaction, a capability governments allegedly used to surveil journalists, dissidents and activists worldwide.

    Meta hailed the ruling as “the first victory against illegal spyware that threatens the safety and privacy of everyone.”

    “The jury’s decision to force NSO to pay damages is a critical deterrent to this malicious industry against their illegal acts aimed at American companies and our users worldwide,” it said in a statement.

    Evidence presented during the trial revealed WhatsApp was not NSO’s only target. Meta noted that while it stopped the attack vector that exploited the company’s calling system in 2019, “Pegasus has had many other spyware installation methods” targeting different technologies.

    The case began in October 2019 when WhatsApp filed a lawsuit claiming that the NSO Group had deployed malware to some mobile devices.

  • ‪Apple Warns iPhone Users They May Have Been Bugged By Israeli’s Pegasus-Type Spyware ‬

    ‪Apple Warns iPhone Users They May Have Been Bugged By Israeli’s Pegasus-Type Spyware ‬

    Apple sent out threat notifications to users in 92 countries on Wednesday, informing them that they may have been the target of “mercenary spyware attacks,” a warning that comes as several countries are preparing to hold critical elections.

    What you need to know

    Apple updated the security notice on its website Wednesday, which states that threat notifications are “designed to inform and assist users who may have been individually targeted by mercenary spyware attacks.”

    According to several Indian news outlets, including the Economic Times and the Indian Express, some iPhone users in the country received notifications from Apple alerting them of an attack “that is trying to remotely compromise the iPhone associated with your Apple ID.”

    The notification informed the user they were likely being targeted specifically “because of who you are or what you do,” and urged them to take it “seriously.”

    The reports do not name any individuals in India who received the notifications, but it comes just a week before the start of the country’s six-week general elections—the world’s largest democratic exercise.

    Apple doesn’t include specific steps for users who have received the notifications, other than urging them to enlist help from cybersecurity experts.

    BIG NUMBER

    150. That’s the number of countries in which iPhone users have received threat notifications since 2021, the company said.

    KEY BACKGROUND

    In October, Apple sent out similar notifications to several prominent political leaders in India who represented opposition parties. Rahul Gandhi, the top leader of Congress—India’s main opposition party—told reporters he and several members of his and other opposition parties had received notifications that their iPhones were being targeted by “state-sponsored attackers.” At the time, Gandhi called out Prime Minister Narendra Modi’s government and accused them of carrying out the attack. Prominent activists and journalists who are critical of the Modi government also received the notification at the time. Apple confirmed it had sent out the notifications but said it had not attributed it to a “specific state-sponsored attacker.” In late December, Amnesty International said it had conducted a forensic investigation to confirm Apple’s findings and said NSO Group’s Pegasus spyware was used to carry out the attacks. Indian authorities publicly denied carrying out the attacks but, according to the Washington Post, they reportedly pressured Apple to “come up with alternative explanations for the warnings to users,” to ease the political fallout.

    FURTHER READING

    Apple warns users of “mercenary spyware” attack; India, 91 other countries impacted (Economic Times)

    Apple warns some Indian users their iPhone may be bugged by Pegasus-type spyware (Indian Express)

    Kenyan intelligence agency NIS has also been accused of using NSO Group’s Pegasus Spyware.

    Israelis Powerful Pegasus Spyware May Have Been Used By NIS To Target And Spy On Journalists Bloggers And Dissidents

  • Israel’s NSO Pegasus Spyware International Weapon Used By Horrific Regimes To Silence Critics

    Israel’s NSO Pegasus Spyware International Weapon Used By Horrific Regimes To Silence Critics

    On March 2, 2017, Mexican journalist Cecilio Pineda took out his mobile phone and in a Facebook live broadcast spoke about alleged collusion between state and local police and the leader of a drug cartel. Two hours later, he was dead – shot at least six times by two men on a motorcycle.

    It was a few weeks later that Forbidden Stories – a global network of journalists engaged in investigations – confirmed that not just Pineda, but also the state prosecutor who investigated the case, Xavier Olea Pelaez, were the targets of Israel’s Pegasus spyware in the weeks and months before his murder.

    Pineda’s phone was also never found, as it had disappeared from the crime scene by the time the authorities had arrived.

    Two weeks after Washington Post columnist Jamal Khashoggi was killed in the Saudi Consulate in Istanbul, Turkey in October 2018, the digital rights organization Citizen Lab reported that a close friend of Khashoggi, Omar Abdulaziz, had been targeted with Pegasus software developed by NSO Group Technologies — an Israeli technology firm.

    New revelations from Forbidden Stories and its partners have found that Pegasus spyware was successfully installed on the mobile phone of Khashoggi’s fiancée, Hatice Cengiz, just four days after his murder. The phone of Khashoggi’s son, Abdullah, was selected as a target of an NSO client based on the consortium’s analysis of the leaked data.

    Overall, the phones of 180 journalists around the world are claimed to have been selected as targets by clients of NSO Group Technologies. Its spyware Pegasus enables the remote surveillance of smartphones.

    Forbidden Stories, which conducted investigations along with Amnesty International’s Security Lab, found that the phones of many politicians, civil society activists and even judges were being monitored in many countries, breaching privacy laws.

    According to Forbidden Stories, they had access to a leak of more than 50,000 records of phone numbers belonging to journalists, politicians, officials, activists and even judges that NSO clients had selected for surveillance.

    Forensic analysis

    The forensic analyses of their phones – conducted by Amnesty International’s Security Lab and peer-reviewed by the Canadian organization Citizen Lab – were able to confirm infection or attempted infection with NSO Group’s spyware in 85% of cases.

    “The numbers vividly show the abuse is widespread, placing journalists’ lives, those of their families and associates in danger, undermining freedom of the press and shutting down critical media,” said Agnes Callamard, secretary-general of Amnesty International.

    NSO Group, in a written response to Forbidden Stories, said the consortium’s reporting was based on “wrong assumptions” and “uncorroborated theories” and reiterated that the company was on a “life-saving mission”.

    “The alleged amount of leaked data of more than 50,000 phone numbers cannot be a list of numbers targeted by governments using Pegasus,” it added.

    NSO Group maintains that its technology is used exclusively by intelligence agencies to track criminals and terrorists. According to NSO Group’s Transparency and Responsibility report released in June this year, the company has 60 clients in 40 countries around the world.

    Pegasus “is not a mass surveillance technology and only collects data from the mobile devices of specific individuals suspected to be involved in serious crime and terror,” NSO Group wrote in the report.

    In India, the phone of Paranjoy Guha Thakurta, an investigative journalist and author of several books, was hacked in 2018.

    Quoting Thakurta, Forbidden Stories said he was targeted when he was working on an investigation into the finances of the famous Ambani business group.

    “The purpose of getting into my phone and looking at who are the people I’m speaking to would be to find out who are the individuals who have been providing information to me and my colleagues,” he said.

    Thakurta is one of at least 40 Indian journalists selected as targets of an NSO client in India, based on the consortium’s analysis of the leaked data.

    The phones of two of the three cofounders of the independent online news outlet The Wire – Siddharth Varadarajan and MK Venu – were both infected by Pegasus, with Venu’s phone hacked as recently as July.

    Top journalists targeted

    Several other journalists who work for or have contributed to the independent news outlet The Wire– including columnist Prem Shankar Jha, investigative reporter Rohini Singh, diplomatic editor Devirupa Mitra and contributor Swati Chaturvedi – were all selected as targets, according to the records accessed by Forbidden Stories and its partners.

    “It was alarming to see so many names of people linked to The Wire, but then there are lots of people not linked to the Wire,” said Varadarajan, whose phone was compromised in 2018.

    Addressing parliament on Monday, Information Technology Minister Ashwini Vaishnaw said there is “no substance behind this sensational” claim and that “with checks and balances in place, illegal surveillance [is] not possible.”

    “A highly sensational story was published by a web portal last night. Many over-the-top allegations [were] made around this story. The press reports appeared a day before [the] monsoon session of parliament. This can’t be a coincidence,” he said.

    He described these revelations as an attempt to malign Indian democracy.

    The Committee to Protect Journalists (CPJ) had previously documented 38 cases of spyware – developed by software companies in four countries – used against journalists in nine countries since 2011.

    How does Pegasus work?

    Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation (EFF), was one of the first security researchers to identify and document cyber-attacks against journalists and human rights defenders in Mexico, Vietnam and elsewhere in the early 2010s.

    “Back in 2011, you would receive an email, and the email would go to your computer, and the malware would be designed to install itself on your computer,” she said.

    But the installation of Pegasus spyware on smartphones has become subtler. Instead of the target having to click on a link to install the spyware, so-called “zero-click” exploits allow the client to take control of the phone without any engagement on the part of the target.

    Once successfully installed on the phone, Pegasus spyware gives NSO clients complete device access and thereby the ability to bypass even encrypted messaging apps like Signal, WhatsApp and Telegram. Pegasus can be activated at will until the device is shut off. As soon as it’s powered back on, the phone can be reinfected.

    According to Galperin Pegasus operators can remotely record audio and video, extract data from messaging apps, use the GPS for location tracking and recover passwords and authentication keys, among other things.

    Spying governments have moved in recent years toward a more “hit and run” strategy to avoid detection, she said, infecting phones, exfiltrating the data and quickly exiting the device.

    Over the years, governments the world over have moved to gather intelligence using technology instead of humans. In the past, they developed spyware tools in-house until private spyware companies like NSO Group, FinFisher and Hacking Team stepped in to sell their products to governments, according to Galperin.

    In June 2021, French spyware company Amesys was charged with “complicity in acts of torture” for selling its spyware to Libya from 2007-2011. According to plaintiffs, in that case, information gleaned through digital surveillance was used to identify and hunt down opponents of deposed dictator Muammar Gaddafi, who were later tortured in prison.

    The revelations stemming from this international collaborative investigation have thrown into question the safeguards put in place to prevent misuse of cyber weapons like Pegasus and, more specifically, NSO Group’s commitment to creating “a better, safer world.”