Skip to main content

NSO has carried out 'unlawful' surveillance to target Amnesty staff members, HRDs


Counterview Desk
Following the exposure that Israeli spyware Pegasus, manufactured by NSO Group, has been used as a surveillance tool on smartphones used by about 1,500 human rights defenders (HRDs), journalists and activists, including in India, the top rights body, Amnesty International India, has appealed to those who have received a notification immediately to get in touch with Amnesty Tech at share@amnesty.tech for support.
An Amnesty release on November 2 said that the rights body could also be contacted “on Signal or WhatsApp at +44 7492 882216”, adding, “We would be keen to provide support to HRDs, who have been targeted, to ensure they take defensive security measures immediately, as well as to understand more about the attacks and investigate possible infections.”
Meanwhile, Amnesty has put out questions and answers for HRDs, activist, or journalist based in India to understand NSO Group’s spyware Pegasus especially the WhatsApp targeting.

Text:

Q: What do we know about the NSO Group and its ‘Pegasus’ Spyware?
A: ‘NSO Group’ is an Israeli spyware manufacturer that claims to sell its surveillance tools – the most well-known being its Pegasus spyware – exclusively to governments and government agencies ‘to combat terror and crime’.
Its products have been misused multiple times to conduct unlawful surveillance against human rights defenders. In the past, it has been used to target an Amnesty International staff member, HRDs, activists, and journalists from Saudi Arabia, UAE, Mexico, Morocco, and Rwanda.
Q: How does Pegasus work?
A: If infected by the Pegasus spyware, the user’s Smartphone is compromised. It can track keystrokes, take control of the phone’s camera and microphone, and access contact lists and encrypted messages.
Until now, Pegasus is known to be delivered through SMS messages carrying malicious links and through exploiting a zero-day vulnerability on WhatsApp. In the latter, intrusive spyware could be delivered on to the target’s mobile device without the targeted person having to click on a malicious link. The targeted person would simply see a missed call on WhatsApp.
In addition to this, Amnesty International has also found evidence of network injection attacks that could also be attributed to NSO Group. Network injection attacks are generally called “man-in-the-middle” attacks. Through this, an attacker with access to a target’s mobile network connection can monitor and opportunistically hijack web traffic and silently re-route the web browser to malicious exploit pages.
Q: How did the targeting via WhatsApp work?
A: NSO Group exploited a security vulnerability in WhatsApp until May 2019. In order to exploit this, the digital attack initiated WhatsApp calls to the target’s device. Attackers may have tried to exploit this issue by making calls multiple times during the night when the target was likely to be asleep and not notice these calls. Successful infection of the target’s device may result in the app crashing. There is a possibility that the attacker may also remotely erase evidence of these calls from the device’s call logs. Evidence of failed attacks may appear as missed calls from unknown numbers in your WhatsApp call log.
Q: If I didn’t receive a notification from WhatsApp, does this mean I wasn’t targeted by NSO Group’s tools?
A: NSO Group’s Pegasus tool is used for targeted attacks and by design, is not meant for mass surveillance. This means that only select individuals would have been targeted. However, if you are a high risk user, i.e., an activist, journalist, or HRD involved in politically sensitive activism, you cannot presume that you have not been targeted simply because you haven’t received a notification from WhatsApp.
The attack was delivered by exploiting a vulnerability in WhatsApp. However, NSO Pegasus infections can also be delivered through other means. Based on information revealed by our own investigations, an Amnesty International staffer was targeted using SMS messages. One HRD in Morocco was targeted both before and after the attacks using the WhatsApp exploit, but not with the WhatsApp exploit itself. Both of them were targeted using SMS messages containing malicious links and network injection attacks that could also be attributed to NSO Group’s tools. This indicates that NSO Group has the documented capability to deliver infections through means other than WhatsApp.
Q: If WhatsApp was targeted, can’t I just switch to another encrypted platform?
A: No. A vulnerability in the WhatsApp software was exploited to deliver the spyware. All complex software can have these types of vulnerabilities. This vulnerability was not a flaw in WhatsApp’s end-to-end encryption protocol.
This also does not mean that only the Whatsapp data of the target was compromised. If the attack attempt was successful, the spyware would gain full access to the device. Any other data on the device including encrypted platforms such as Signal or Telegram could then also have been accessed.
Q: Can Pegasus plant data into my devices?
A: Based on publicly available information, planting data is not a feature of NSO Group’s Pegasus spyware.
Q: What steps can I take to protect myself?
A: None of the security best practices offer complete and foolproof protection. However, it is a good practice to install the latest software updates of operating systems and encrypted messaging applications on your mobile device.
Pegasus remains a relatively uncommon threat and standard digital hygiene steps are still important. Keep your devices software up-to-date. Use a unique password for each service that you use and store these passwords in a secure password manager. Enable two-factor authentication on all accounts where it is available.

Comments

TRENDING

70,000 migrants, sold on Canadian dream, face uncertain future: Canada reinvents the xenophobic wheel

By Saurav Sarkar*  Bikram Singh is running out of time on his post-study work visa in Canada. Singh is one of about 70,000 migrants who were sold on the Canadian dream of eventually making the country their home but now face an uncertain future with their work permits set to expire by December 2024. They came from places like India, China, and the Philippines, and sold their land and belongings in their home countries, took out loans, or made other enormous commitments to get themselves to Canada.

Kerala government data implicates the Covid vaccines for excess deaths

By Bhaskaran Raman*  On 03 Dec 2024, Mr Unnikrishnan of the Indian Express had written an article titled: “Kerala govt data busts vaccine death myth; no rise in mortality post-Covid”. It claims “no significant change in the death rate in the 35-44 age group between 2019 and 2023”. However, the claim is obviously wrong, even to a casual observer, as per the same data which the article presents, as explained below.

PM-JUGA: Support to states and gram sabhas for the FRA implementation and preparation and execution of CFR management plan

By Dr. Manohar Chauhan*  (Over the period, under 275(1), Ministry of Tribal Affairs has provided fund to the states for FRA implementation. Besides, some states like Odisha, Chhattisgarh and Maharashtra allocated special fund for FRA implementation. Now PM-JUDA under “Dharti Aaba Janjatiya Gram Utkarsh Abhiyan(DAJGUA) lunched by Prime Minister on 2nd October 2024 will not only be the major source of funding from MoTA to the States/UTs, but also will be the major support to the Gram sabha for the preparation and execution of CFR management Plan).

Defeat of martial law: Has the decisive moment for change come in South Korea?

By Steven Lee  Late at night on December 3, soldiers stormed into South Korea’s National Assembly in armored vehicles and combat helicopters. Assembly staff desperately blocked their assault with fire extinguishers and barricades. South Korea’s President Yoon Suk Yeol had just declared martial law to “ eliminate ‘anti-state’ forces .”

Operation Kagar represents Indian state's intensified attempt to extinguish Maoism: Resistance continues

By Harsh Thakor Operation Kagar represents the Indian state's intensified attempt to extinguish Maoism, which claims to embody the struggles and aspirations of Adivasis. Criminalized by the state, the Maoists have been portrayed as a threat, with Operation Kagar deploying strategies that jeopardize their activities. This operation weaves together economic, cultural, and political motives, allegedly with drone attacks on Adivasi homes.

How Amit Shah's statement on Ambedkar reflects frustration of those uncomfortable with Dalit assertion, empowerment

By Vidya Bhushan Rawat*  Dr. B.R. Ambedkar remains the liberator and emancipator of India’s oppressed communities. However, attempts to box him between two Brahmanical political parties betray a superficial and self-serving understanding of his legacy. The statement by Union Home Minister Amit Shah in the Rajya Sabha was highly objectionable, reflecting the frustration of those uncomfortable with Dalit assertion and empowerment.

Balod tech fest tests students’ interest in innovative ideas in the fields of science, engineering, start-ups

By Our Representative  A techno fest scheduled on December 20 and 21 in Balod district of Chhattisgarh will test the innovative ideas of school students in the fields of science, engineering and start-ups.  For this two-day fest organised at Maheswari Bhawan of the district, a total of 824 models made by students were initially registered. Out of those, a selection committee chose 200 models from several schools spread over five blocks of Balod. These will be on display on these two days from 10am to 4.30pm. Out of many ideas, one of the most interesting models is a smart glove which can be used by children with impairments and disabilities. For those who cannot speak at all or have speech difficulty, they can ask for help from caregivers by pressing their fingers on the glove after wearing it. This will attract attention. 

Local businessman subjected to physical assault, verbal abuse: Demand for accountability, justice

By Kirity Roy* On October 9, 2024, a disturbing incident of harassment and abuse took place in the Swarupnagar Block of North 24 Parganas district, involving a local businessman, Hasanur Gazi, who was subjected to physical assault, verbal abuse, and religious discrimination by a Border Security Force (BSF) constable. The incident, which occurred at the Hakimpur Checkpost, has raised serious concerns about the safety and dignity of citizens living in border areas, especially those belonging to religious minorities.

Affable but arrogant, embodying contradictions, Raj Kapoor's legacy will endure as long as Bollywood exists

By Harsh Thakor*  December 14 marks the birth centenary of Raj Kapoor, a filmmaker and visionary who revolutionized Bollywood, elevating it to new heights by exploring uncharted emotional and social territories. Kapoor wasn’t just a filmmaker; he was a storyteller who touched the souls of the masses and reflected the pulse of post-partition India with unparalleled depth. His films acted as a unifying force in a divided nation, transcending social and cultural boundaries.

Suspicious death of Dalit laborer in BSF custody: A call for justice

By Kirity Roy*  The tragic and suspicious death of Mr. Babai Barui, a Dalit daily wage laborer from North 24 Parganas, West Bengal, has raised serious concerns regarding custodial violence and the violation of fundamental rights. Mr. Barui, son of Sukharanjan Barui, resided in Pallishree Sangsad, Bongaon, and was arrested by the Border Security Force (BSF) on November 9, 2024, near the Angrail border on allegations of smuggling. The very next day, he was found dead under mysterious circumstances, with visible injuries that point toward possible custodial violence.