ZeroHour
CyberScooppublished ()ingested @shanvav

Research shows human rights activists in India were targeted with spyware

criticalMalware exploited in the wildimportance 60
Full article1,005 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Human rights activists in India were targeted by a coordinated spyware campaign, according to research published by Amnesty International and Citizen Lab.

(Getty Images)

Human rights activists in India were targeted by a coordinated spyware campaign from January to October of 2019, according to research published Monday by Amnesty International and the University of Toronto’s Citizen Lab.

Nine activists in total were targeted, eight of which have been calling for the release of 11 people jailed during protests related to the violent uprising in Bhima Koregaon, India in 2018.

The targets were sent spearphishing emails with malicious links and files that, if clicked, would infect the victims’ computers with spyware capable of tracking their communications. Three of the activists were also alleged to have been targeted by Pegasus, a notorious spyware program developed by Israeli surveillance software firm NSO Group last year.

Human rights defenders in India have been victimized by spyware in the past. But the research shows that surveillance software has been leveraged multiple times against activists linked to the Bhima Koregaon activists. One of the activists who was imprisoned following the protests, Anand Teltumbde, alleged last year that someone used NSO’s software in an attempt to hack his devices.

“That some of these individuals were targeted multiple times shows that there is a disturbing pattern of spyware attacks against [human rights defenders] involved in the Bhima Koregaon case,” the researchers wrote in a blog post about the campaign. “This spyware campaign is very concerning in the context of an already perilous situation for [human rights defenders] in India where surveillance is used along with threats, imprisonment and smear campaigns against activists to shrink the space for civil society.”

The case against the Bhima Koregaon protesters has relied “almost entirely on digital evidence obtained from the arrested activists’ devices,” according to Amnesty and Citizen Lab. In 2018, Indian police are alleged to have released materials found on the activists’ devices to smear them.

NSO Group has historically claimed its tools can only be used by law enforcement and government-run intelligence agencies.

“As written in the report, the most recent alleged discoveries have no links to NSO. All other allegations are recycled and misleading,” an NSO spokesperson told CyberScoop in a statement.

The perpetrators behind the new campaign, whose identities remain unknown, also tricked the activists with spearphishing emails that purported to be from journalists, officials from local courts or other people who knew the targets. The perpetrators used links to lead targets to a file hosted on Mozilla’s file-sharing platform Firefox Send, in a likely effort to avoid malware and email filters. The malware was delivered by files that looked like PDFs, but which were actually malicious Windows programs.

The campaign then would deploy commercially available spyware capable of logging keystrokes and stealing credentials and audio recordings. The malware, NetWire, has been used in the past by criminal groups and in corporate espionage incidents. In April, researchers for BlackBerry Cylance found evidence that tied NetWire to a Chinese-based hacking collective known as Winnti Group.

The news comes just one week after Citizen Lab revealed a hack-for-hire business in India has been targeting activists, journalists, and investment firms for approximately seven years in multiple credential-stealing campaigns.

“We currently have no evidence showing any link with the hacker-for-hire research published by the Citizen Lab recently,” a spokesperson from Amnesty International told CyberScoop.

More Scoops

This aerial photograph shows demonstrators and students as they gather in front of Serbia’s Constitutional Court building during a protest to demand accountability for the Novi Sad railway station tragedy, in Belgrade, on January 12, 2025. Thousands of Serbians protested in the capital Belgrade on January 12, 2025, against corruption and demanding justice for those killed in a train station roof collapse. The demonstrations have been ongoing for two months since a roof in a train station in the northern city of Novi Sad, which had recently undergone restoration work, collapsed on November 1, 2024, and killed 15 people. (Photo by TADIJA ANASTASIJEVIC / AFP via Getty Images)

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia…

In this photo illustration, the Cellebrite logo is displayed on the screen of a tablet. (Photo Illustration by Sheldon Cooper/SOPA Images/LightRocket via Getty Images)

Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract

This illustration photograph taken on November 27, 2024, shows the logo of US instant messaging software Whatsapp displayed on a smartphone’s screen, in Frankfurt am Main, western Germany. (Photo by Kirill KUDRYAVTSEV / AFP)

Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/india-spyware-nso-group-amnesty-international-citizen-lab/