NSO Group's Pegasus spyware detected in attacks against Moroccan journalist, activist
Full article709 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Similar spyware attacks have been detected against critics of the Mexican and Saudi governments.
Hackers potentially working on behalf of a foreign government have targeted Moroccan human rights advocates with malicious software built by NSO Group, a controversial spyware vendor, according to Amnesty International.
Since 2017, journalist Maati Monib and Abdessadak El Bouchattaoui, an attorney who has protested the Moroccan government’s security forces, repeatedly have received malicious links and browser redirections that, if trusted, would install the Pegasus malware, Amnesty found. It’s the latest allegation that NSO Group provided Pegasus to a customer that used it for more than combating terrorism and crime. The software allows attackers to take almost total control of an affected phone.
Human Rights Watch has documented a list of government efforts to obstruct reform in Morocco, including prison sentences for people who have “harmed” the monarchy there or insulted Islam. El Bouchattaoui, one of the activists whose experience was detailed by Amnesty, was sentenced to two years in prison for internet posts criticizing authorities’ use of excessive force during demonstrations in 2017.
“Surveillance is a type of punishment,” he said in a statement from Amnesty. “You can’t behave freely. It is part of their strategy to make you suspect you’re being watched so you feel like you’re under pressure all the time.” Pegasus users can track calls, collect username and password credentials, find the infected device’s location and assume other details.
Amnesty did not definitively tie the attacks to the Moroccan government. Israel-based NSO Group consistently has said it does not operate the Pegasus spyware, but that it only licenses it to closely vetted government customers. The tool previously has been aimed against journalists in Mexico, Saudi dissidents and Amnesty’s own researchers.
“As per our policy, we investigate reports of alleged misuse of our products,” an NSO Group spokesperson said. “If an investigation identifies actual or potential adverse impacts on human rights, we are proactive and quick to take the appropriate action to address them. This may include suspending or immediately terminating a customer’s use of the product, as we have done in the past.”
In this case, the messages targeting El Bouchattaoui were sent during Hirak El-Rif, a series of mass demonstrations two years ago. The messages appeared to be automated spam texts, directing the recipient to click the link in order to stop receiving them. The attacks against Monjib relied on a different tact, redirecting his desktop internet browser to malicious links that masqueraded as legitimate websites like Yahoo.
“Network injection attacks, like those we described in our report, are difficult to identify and prevent, even for the most tech-savvy and privacy conscious human rights defenders,” said Claudio Guarnieri, head of Amnesty’s security lab. “There are no SMS messages, no links to be clicked. The attack happens transparently and, at best, the victim might only experience an application crash, which are not uncommon.”
This story has been updated to include comment from NSO Group.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/morocco-spyware-nso-group-pegasus/