Amnesty International blames ‘hostile government’ after Israeli-made spyware targets staff

The organisation was targeted by a ‘sophisticated campaign’ that has seen 175 attacks around the world since 2016

Amnesty International has disclosed how its staff were targeted in a spyware attack launched by what it believes to be "a government hostile to its work".

Alarms sounded in June after an Amnesty researcher received a suspicious WhatsApp message with details of an alleged protest outside the Saudi embassy in Washington DC, along with a link to a website.

An investigation by the charity's technology team revealed clicking this would have installed a surveillance tool called "Pegasus", developed by Israeli-based company NSO Group. The software enables an "extraordinarily invasive form of surveillance" and allows a malicious actor to intercept phone calls, and messages received on the handset, the charity claims.

"NSO Group is known to only sell its spyware to governments. We therefore believe that this was a deliberate attempt to infiltrate Amnesty International by a government hostile to our human rights work," said Amnesty International's head of technology and human rights Joshua Franco.

"This chilling attack on Amnesty International highlights the grave risk posed to activists around the world by this kind of surveillance technology."

Researchers from the University of Toronto's Citizen Lab, which investigates digital espionage among other subjects, corroborated Amnesty's assessment, suggesting the SMS messages Amnesty received contain domain names pointing to websites that appear to be part of NSO Group's Pegasus infrastructure.

Citizen Lab's researchers found the domains social-life.info and akhbar-arabia.com, which appeared on the WhatsApp messages, were consistent with the Pegasus infrastructure they had been tracking since 2016.

The organisation suggest the contents of the WhatsApp message were connected with the organisation's campaigning that week for the release of six women's rights activists being detained in Saudi Arabia. The organisation learned a Saudi Arabian rights activist received a similar message shortly afterwards.

"Can you please cover [the protest] for your brothers detained in Saudi Arabia in front of the Saudi embassy in Washington," the message read. "My brother was detained in Ramadan and I am on a scholarship here so please do not link me to this. [LINK]. Cover the protest now it will start in less than an hour. We need your support please."

Citizen Lab has identified 175 reported such instances of surveillance with ties to NSO in its experience, with up to 150 incidents in Panama alone, as well as reports from the United Arab Emirates, Mexico and Saudi Arabia.

The institution's researchers identified the links as matching websites appearing as part of NSO's new infrastructure that retains a Saudi-focus. They concluded the messages appear to represent attempts to infect the Amnesty researcher and the Saudi activist based abroad with NSO Group's Pegasus spyware.

"NSO Group develops cyber technology to allow government agencies to identify and disrupt terrorist and criminal plots," the Israeli-based company said.

"Our product is intended to be used exclusively for the investigation and prevention of crime and terrorism. Any use of our technology that is counter to that purpose is a violation of our policies, legal contracts, and the values that we stand for as a company.

"If an allegation arises concerning a violation of our contract or inappropriate use of our technology, as Amnesty has offered, we investigate the issue and take appropriate action based on those findings. We welcome any specific information that can assist us in further investigating of the matter."

Featured Resources

BIOS security: The next frontier for endpoint protection

Today’s threats upend traditional security measures

Download now

The role of modern storage in a multi-cloud future

Research exploring the impact of modern storage in defining cloud success

Download now

Enterprise data protection: A four-step plan

An interactive buyers’ guide and checklist

Download now

The total economic impact of Adobe Sign

Cost savings and business benefits enabled by Adobe Sign

Download now

Recommended

What is cyber warfare?
Security

What is cyber warfare?

22 Sep 2020
8 of the most secure web browsers
web browser

8 of the most secure web browsers

25 Sep 2020
Your essential guide to internet security
Security

Your essential guide to internet security

23 Sep 2020
How to enable private browsing on any device
privacy

How to enable private browsing on any device

22 Sep 2020

Most Popular

16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
Google removes 17 apps infected with evasive ‘Joker’ malware
malware

Google removes 17 apps infected with evasive ‘Joker’ malware

28 Sep 2020