Skip to main content

NSO has carried out 'unlawful' surveillance to target Amnesty staff members, HRDs


Counterview Desk
Following the exposure that Israeli spyware Pegasus, manufactured by NSO Group, has been used as a surveillance tool on smartphones used by about 1,500 human rights defenders (HRDs), journalists and activists, including in India, the top rights body, Amnesty International India, has appealed to those who have received a notification immediately to get in touch with Amnesty Tech at share@amnesty.tech for support.
An Amnesty release on November 2 said that the rights body could also be contacted “on Signal or WhatsApp at +44 7492 882216”, adding, “We would be keen to provide support to HRDs, who have been targeted, to ensure they take defensive security measures immediately, as well as to understand more about the attacks and investigate possible infections.”
Meanwhile, Amnesty has put out questions and answers for HRDs, activist, or journalist based in India to understand NSO Group’s spyware Pegasus especially the WhatsApp targeting.

Text:

Q: What do we know about the NSO Group and its ‘Pegasus’ Spyware?
A: ‘NSO Group’ is an Israeli spyware manufacturer that claims to sell its surveillance tools – the most well-known being its Pegasus spyware – exclusively to governments and government agencies ‘to combat terror and crime’.
Its products have been misused multiple times to conduct unlawful surveillance against human rights defenders. In the past, it has been used to target an Amnesty International staff member, HRDs, activists, and journalists from Saudi Arabia, UAE, Mexico, Morocco, and Rwanda.
Q: How does Pegasus work?
A: If infected by the Pegasus spyware, the user’s Smartphone is compromised. It can track keystrokes, take control of the phone’s camera and microphone, and access contact lists and encrypted messages.
Until now, Pegasus is known to be delivered through SMS messages carrying malicious links and through exploiting a zero-day vulnerability on WhatsApp. In the latter, intrusive spyware could be delivered on to the target’s mobile device without the targeted person having to click on a malicious link. The targeted person would simply see a missed call on WhatsApp.
In addition to this, Amnesty International has also found evidence of network injection attacks that could also be attributed to NSO Group. Network injection attacks are generally called “man-in-the-middle” attacks. Through this, an attacker with access to a target’s mobile network connection can monitor and opportunistically hijack web traffic and silently re-route the web browser to malicious exploit pages.
Q: How did the targeting via WhatsApp work?
A: NSO Group exploited a security vulnerability in WhatsApp until May 2019. In order to exploit this, the digital attack initiated WhatsApp calls to the target’s device. Attackers may have tried to exploit this issue by making calls multiple times during the night when the target was likely to be asleep and not notice these calls. Successful infection of the target’s device may result in the app crashing. There is a possibility that the attacker may also remotely erase evidence of these calls from the device’s call logs. Evidence of failed attacks may appear as missed calls from unknown numbers in your WhatsApp call log.
Q: If I didn’t receive a notification from WhatsApp, does this mean I wasn’t targeted by NSO Group’s tools?
A: NSO Group’s Pegasus tool is used for targeted attacks and by design, is not meant for mass surveillance. This means that only select individuals would have been targeted. However, if you are a high risk user, i.e., an activist, journalist, or HRD involved in politically sensitive activism, you cannot presume that you have not been targeted simply because you haven’t received a notification from WhatsApp.
The attack was delivered by exploiting a vulnerability in WhatsApp. However, NSO Pegasus infections can also be delivered through other means. Based on information revealed by our own investigations, an Amnesty International staffer was targeted using SMS messages. One HRD in Morocco was targeted both before and after the attacks using the WhatsApp exploit, but not with the WhatsApp exploit itself. Both of them were targeted using SMS messages containing malicious links and network injection attacks that could also be attributed to NSO Group’s tools. This indicates that NSO Group has the documented capability to deliver infections through means other than WhatsApp.
Q: If WhatsApp was targeted, can’t I just switch to another encrypted platform?
A: No. A vulnerability in the WhatsApp software was exploited to deliver the spyware. All complex software can have these types of vulnerabilities. This vulnerability was not a flaw in WhatsApp’s end-to-end encryption protocol.
This also does not mean that only the Whatsapp data of the target was compromised. If the attack attempt was successful, the spyware would gain full access to the device. Any other data on the device including encrypted platforms such as Signal or Telegram could then also have been accessed.
Q: Can Pegasus plant data into my devices?
A: Based on publicly available information, planting data is not a feature of NSO Group’s Pegasus spyware.
Q: What steps can I take to protect myself?
A: None of the security best practices offer complete and foolproof protection. However, it is a good practice to install the latest software updates of operating systems and encrypted messaging applications on your mobile device.
Pegasus remains a relatively uncommon threat and standard digital hygiene steps are still important. Keep your devices software up-to-date. Use a unique password for each service that you use and store these passwords in a secure password manager. Enable two-factor authentication on all accounts where it is available.

Comments

TRENDING

राजस्थान, मध्यप्रदेश, पश्चिम बंगाल, झारखंड और केरल फिसड्डी: जल जीवन मिशन के लक्ष्य को पाने समन्वित प्रयास जरूरी

- राज कुमार सिन्हा*  जल संसाधन से जुड़ी स्थायी समिति ने वर्तमान लोकसभा सत्र में पेश रिपोर्ट में बताया है कि "नल से जल" मिशन में राजस्थान, मध्यप्रदेश, पश्चिम बंगाल, झारखंड और केरल फिसड्डी साबित हुए हैं। जबकि देश के 11 राज्यों में शत-प्रतिशत ग्रामीणों को नल से जल आपूर्ति शुरू कर दी गई है। रिपोर्ट में समिति ने केंद्र सरकार को सिफारिश की है कि मिशन पुरा करने में राज्य सरकारों की समस्याओं पर गौर किया जाए। 

Beyond his riding skill, Karl Umrigar was admired for his radiance, sportsmanship, and affability

By Harsh Thakor*  Karl Umrigar's name remains etched in the annals of Indian horse racing, a testament to a talent tragically cut short. An accident on the racetrack at the tender age of nineteen robbed India of a rider on the cusp of greatness. Had he survived, there's little doubt he would have ascended to international stature, possibly becoming the greatest Indian jockey ever. Even 46 years after his death, his name shines brightly, reminiscent of an inextinguishable star. His cousin, Pesi Shroff, himself blossomed into one of the most celebrated jockeys in Indian horse racing.

Aurangzeb’s last will recorded by his Maulvi: Allah shouldn't make anyone emperor

By Mohan Guruswamy  Aurangzeb’s grave is a simple slab open to the sky lying along the roadside at Khuldabad near Aurangabad. I once stopped by to marvel at the tomb of an Emperor of India whose empire was as large as Ashoka the Great's. It was only post 1857 when Victoria's domain exceeded this. The epitaph reads: "Az tila o nuqreh gar saazand gumbad aghniyaa! Bar mazaar e ghareebaan gumbad e gardun bas ast." (The rich may well construct domes of gold and silver on their graves. For the poor folks like me, the sky is enough to shelter my grave) The modest tomb of Aurangzeb is perhaps the least recognised legacies of the Mughal Emperor who ruled the land for fifty eventful years. He was not a builder having expended his long tenure in war and conquest. Towards the end of his reign and life, he realised the futility of it all. He wrote: "Allah should not make anyone an emperor. The most unfortunate person is he who becomes one." Aurangzeb’s last will was re...

How the slogan Jai Bhim gained momentum as movement of popularity and revolution

By Dr Kapilendra Das*  India is an incomprehensible plural country loaded with diversities of religions, castes, cultures, languages, dialects, tribes, societies, costumes, etc. The Indians have good manners/etiquette (decent social conduct, gesture, courtesy, politeness) that build healthy relationships and take them ahead to life. In many parts of India, in many situations, and on formal occasions, it is common for people of India to express and exchange respect, greetings, and salutation for which we people usually use words and phrases like- Namaskar, Namaste, Pranam, Ram Ram, Jai Ram ji, Jai Sriram, Good morning, shubha sakal, Radhe Radhe, Jai Bajarangabali, Jai Gopal, Jai Jai, Supravat, Good night, Shuvaratri, Jai Bhole, Salaam walekam, Walekam salaam, Radhaswami, Namo Buddhaya, Jai Bhim, Hello, and so on. A soft attitude always creates strong relationships. A relationship should not depend only on spoken words. They should rely on understanding the unspoken feeling too. So w...

PUCL files complaint with SC against Gujarat police, municipal authorities for 'unlawful' demolitions, custodial 'violence'

By A Representative   The People's Union for Civil Liberties (PUCL) has lodged a formal complaint with the Chief Justice of India, urging the Supreme Court to initiate suo-moto contempt proceedings against the police and municipal authorities in Ahmedabad, Gujarat. The complaint alleges that these officials have engaged in unlawful demolitions and custodial violence, in direct violation of a Supreme Court order issued in November 2024.

Incarcerated for 2,424 days, Sudhir Dhawale combines Ambedkarism with Marxism

By Harsh Thakor   One of those who faced incarceration both under Congress and BJP rule, Sudhir Dhawale was arrested on June 6, 2018, one of the first six among the 16 people held in what became known as the Elgar Parishad case. After spending 2,424 days in incarceration, he became the ninth to be released from jail—alongside Rona Wilson, who walked free with him on January 24. The Bombay High Court granted them bail, citing the prolonged imprisonment without trial as a key factor. I will always remember the moments we spent together in Mumbai between 1998 and 2006, during public meetings and protests across a wide range of issues. Sudhir was unwavering in his commitment to Maoism, upholding the torch of B.R. Ambedkar, and resisting Brahmanical fascism. He sought to bridge the philosophies of Marxism and Ambedkarism. With boundless energy, he waved the banner of liberation, becoming the backbone of the revolutionary democratic centre in Mumbai and Maharashtra. He dedicated himself ...

Censor Board's bullying delays 'Phule': A blow to India's democratic spirit

By Vidya Bhushan Rawat*  A film based on the life and legacy of Jyotiba Phule and Savitribai Phule was expected to release today. Instead, its release has been pushed to the last week of April. The reason? Protests by self-proclaimed guardians of caste pride—certain Brahmin groups—and forced edits demanded by a thoroughly discredited Censor Board.

State Human Rights Commission directs authorities to uphold environmental rights in Vadodara's Vishwamitri River Project

By A Representative  The Gujarat State Human Rights Commission (GSHRC) has ordered state and Vadodara municipal authorities to strictly comply with environmental and human rights safeguards during the Vishwamitri River Rejuvenation Project, stressing that the river’s degradation disproportionately affects marginalized communities and violates citizens’ rights to a healthy environment.  The Commission mandated an immediate halt to ecologically destructive practices, rehabilitation of affected communities, transparent adherence to National Green Tribunal (NGT) orders, and public consultations with experts and residents.   The order follows the Concerned Citizens of Vadodara coalition—environmentalists, ecologists, and urban planners—submitting a detailed letter to authorities, amplifying calls for accountability. The group warned that current plans to “re-section” and “desilt” the river contradict the NGT’s 2021 Vishwamitri River Action Plan, which prioritizes floodpla...

CPM’s evaluation of BJP reflects its political character and its reluctance to take on battle against neo-fascism

By Harsh Thakor*  A controversial debate has emerged in the revolutionary camp regarding the Communist Party of India (Marxist)'s categorization of the Bharatiya Janata Party. Many Communists criticize the CPM’s reluctance to label the BJP as a fascist party and India as a fascist state. Various factors must be considered to arrive at an accurate assessment. Understanding the original meaning and historical development of fascism is essential, as well as analyzing how it manifests in the present global and national context.

Implications of deaths of Maoist leaders G. Renuka and Ankeshwarapu Sarayya in Chhattisgarh

By Harsh Thakor*  In the wake of recent security operations in southern Chhattisgarh, two senior Maoist leaders, G. Renuka and Ankeshwarapu Sarayya, were killed. These operations, which took place amidst a historically significant Maoist presence, resulted in the deaths of 31 individuals on March 20th and 16 more three days prior.