Sweeping report details how NSO Group spyware leverages iOS software for surveillance
Full article806 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A new report reveals the extent of the spyware company's reach.
NSO Group’s Pegasus spyware may be actively exploiting the most recent software in the iPhone 12 to monitor victims through the world, according to a sweeping new report from Amnesty International.
“These most recent discoveries indicate NSO Group’s customers are currently able to remotely compromise all recent iPhone models and versions of iOS,” the group wrote in a report published on July 18. “We have reported this information to Apple, who informed us they are investigating the matter.”
The revelation comes as part of a broader investigation into the use of the notorious spyware. Between July 2014 and July 2021, the NSO group’s Pegasus software was used to target more than three dozen smartphones belonging to journalists, human rights activists and business executives, according to a joint investigation between Amnesty, French journalism nonprofit Forbidden Stories and 17 media organizations including The Washington Post.
Targets included Hatice Cengiz, fiancee of murdered Washington Post journalist Jamal Khashoggi, Mexican journalist Carmen Aristegui and Siddharth Varadarajan, co-founder of India’s independent online news outlet the Wire.
The scope of victims is likely much wider.
“Pegasus may have been used in thousands of attacks over the past three years,” Amnesty notes.
The new report highlights the growing use of “zero-click” attacks by the group. Such attacks infect phones without a user having to open a message or click on an external link. The most recent known instance of such an attack by Pegasus software was July 2021.
Human rights groups have tied the NSO Group’s technology to the targeting of activists, dissidents and journalists for years. The Israel-based company states that it only licenses its tools to governments for the surveillance of criminals and terrorists.
“This research has uncovered widespread, persistent and ongoing unlawful surveillance and human rights abuses perpetrated using NSO Group’s Pegasus spyware,” Amnesty International notes in its report. “As laid out in the UN Guiding Principles on Business and Human Rights, NSO Group should urgently take proactive steps to ensure that it does not cause or contribute to human rights abuses within its global operations, and to respond to any human rights abuses when they do occur.”
The NSO Group largely disputed the consortium’s findings to The Washington Post.
NSO chief executive Shalev Hulio told The Washington Post that the company had terminated two contracts over alleged human rights abuses in the past 12 months and the company investigates every allegation.
More Scoops
Someone infected a spyware probe overseer with spyware
Citizen Lab says the phone of a member of Europe’s PEGA Committee was infected twice with Pegasus, the NSO Group spyware that gave the panel its name.
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
One House Democrat is pressing Commerce on the government’s spyware use
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nso-group-spyware-ios-amnesty-human-rights/