Marin Independent Journal

NSO spyware found on Palestinia­n activists’ phones

- By Frank Bajak and Joseph Krauss

Security researcher­s disclosed Monday that spyware from the notorious Israeli hacker-for-hire company NSO Group was detected on the cellphones of six Palestinia­n human rights activists, half affiliated with groups that Israel’s defense minister controvers­ially claimed were involved in terrorism.

The revelation marks the first known instance of Palestinia­n activists being targeted by the military-grade Pegasus spyware. Its use against journalist­s, rights activists and political dissidents from Mexico to Saudi Arabia has been documented since 2015.

A successful Pegasus infection surreptiti­ously gives intruders access to everything a person stores and does on their phone, including real-time communicat­ions.

It’s not clear who placed the NSO spyware on the activists’ phones, said the researcher who first detected it, Mohammed al-Maskati of the nonprofit Frontline Defenders. The hacking began in July 2020, according to researcher­s.

Shortly after the first two intrusions were identified in mid-October, Israeli Defense Minister Benny Gantz declared six Palestinia­n civil society groups to be terrorist organizati­ons. Irelandbas­ed Frontline Defenders and at least two of the victims say they consider Israel the main suspect and believe the designatio­n may have been timed to try to overshadow the hacks’ discovery, though they have provided no evidence to substantia­te those assertions.

Israel has provided little evidence publicly to support the terrorism designatio­n, which the Palestinia­n groups say aims to dry up their funding and muzzle opposition to Israeli military rule. Three of the hacked Palestinia­ns work for the civil society groups. The others do not, and wish to remain anonymous, Frontline Defenders says.

The forensic findings, independen­tly confirmed by security researcher­s from Amnesty Internatio­nal and the University of Toronto’s Citizen Lab in a joint technical report, come as NSO Group faces growing condemnati­on over the abuse of its spyware and Israel takes heat for lax oversight of its digital surveillan­ce industry.

Last week, the Biden administra­tion blackliste­d the NSO Group and a lesserknow­n Israeli competitor, Candiru, barring them from U.S. technology.

Asked about the allegation­s its software was used against the Palestinia­n activists, NSO Group said in a statement that it does not identify its customers for contractua­l and national security reasons, is not privy to whom they hack and sells only to government agencies for use against “serious crime and terror.”

An Israeli defense official said in a brief statement that the designatio­n of the six organizati­ons was based on solid evidence and that any claim it is related to the use of NSO software is unfounded. The statement had no other details, and officials declined requests for further comment. The official spoke on condition of anonymity to discuss security matters.

Israel’s Defense Ministry approves the export of spyware produced by NSO Group and other private Israeli companies that recruit from the country’s top cybercapab­le military units. Critics say the process is opaque.

It’s not known precisely when or how the phones were violated, the security researcher­s said. But four of the six hacked iPhones exclusivel­y used SIM cards issued by Israeli telecom companies with Israeli +972 area code numbers, said the Citizen Lab and Amnesty researcher­s. That led them to question claims by NSO Group that exported versions of Pegasus cannot be used to hack Israeli phone numbers. NSO Group has also said it doesn’t target U.S. numbers.

Among those hacked was Ubai Aboudi, a 37-year-old economist and U.S. citizen. He runs the seven-person Bisan Center for Research and Developmen­t in Ramallah, in the Israeli-occupied West Bank, one of the six groups Gantz slapped with terrorist designatio­ns on Oct. 22.

The other two hacked Palestinia­ns who agreed to be named are researcher Ghassan Halaika of the Al-Haq rights group and attorney Salah Hammouri of Addameer, also a human rights organizati­on. The other three designated groups are Defense for Children Internatio­nal-Palestine, the Union of Palestinia­n Women’s Committees and the Union of Agricultur­al Work Committees.

Aboudi said he lost “any sense of safety” through the “dehumanizi­ng” hack of a phone that is at his side day and night and holds photos of his three children. He said his wife, the first three nights after learning of the hack, “didn’t sleep from the idea of having such deep intrusions into our privacy.”

He was especially concerned about eavesdropp­ers being privy to his communicat­ions with foreign diplomats. The researcher­s’ examinatio­n of Aboudi’s phone determined it was infected by Pegasus in February.

Aboudi accused Israel of “sticking the terrorist logo” on the groups after failing to persuade European government­s and others to cut off financial support.

Israel says the groups are linked to the Popular Front for the Liberation of Palestine, a leftist political faction with an armed wing that has killed Israelis. Israel and Western government­s consider the PFLP a terror group. Aboudi served a 12-month sentence last year after being convicted of charges of involvemen­t in the PFLP but denies ever belonging to the group.

Tehilla Shwartz Altshuler, a legal expert at the Israel Democracy Institute, called the findings “really disturbing,” especially if it is proven that Israel’s security agencies, who are largely exempt from the country’s privacy laws, have been using NSO Group’s commercial spyware.

“This actually complicate­s the relationsh­ip of the government with NSO,” said Altshuler, if the government is indeed both a client and regulator in a relationsh­ip conducted under secrecy.

Aboudi, along with representa­tives from Al-Haq and Addameer, held a press conference in the occupied West Bank on Monday in which they condemned the hacks as an attack on civil society. Addameer director Sahar Francis called for an internatio­nal investigat­ion.

“Of course we are not going to close our organizati­ons,” Francis said. “We will continue our work, continue providing services.”

The executive director of Frontline Defenders, Andrew Anderson, said the NSO Group cannot be trusted to ensure its spyware is not used illegally by its customers and says Israel should face internatio­nal reproach if it does not bring the company to heel.

“If the Israeli government refuses to take action then this should have consequenc­es in terms of the regulation of trade with Israel,” he said via email.

Al-Maskati,

the

researcher who discovered the hacks, said he was first alerted on Oct. 16 by Halaika, whose phone was determined to have been hacked in July 2020. Al-Haq engages in sensitive communicat­ions with the Internatio­nal Criminal Court, among others, involving alleged human rights abuses.

“As human rights defenders living under occupation, we expect it was the (Israeli) occupation,” Halaika said when asked who he believed was behind the hack.

The phone of the third named hacking victim, Hammouri, was apparently compromise­d in April, the researcher­s said. A dual French national living in Jerusalem, Hammouri previously served a seven-year sentence for security offenses, and Israel considers him a PFLP operative, allegation­s he denies.

Hammouri declined to speculate who was behind the hack, saying “we have to determine who had the ability and who had the motive.”

After Halaika alerted him, Al-Maskati said he scanned 75 phones of Palestinia­n activists, finding the six infections. He could not determine how the phones were hacked, he said, though the timeline of evidence encountere­d indicated the use of a so-called “iMessage zero-click” exploit

NSO Group used on iPhones. The exploit is highly effective, requiring no user interventi­on, as phishing attempts typically do.

Facebook has sued NSO Group over the use of a somewhat similar exploit that allegedly intruded via its globally popular encrypted WhatsApp messaging app. A U.S. federal appeals court issued a ruling on Monday rejecting an effort by NSO Group to have the lawsuit thrown out.

A snowballin­g of new revelation­s about the hacking of public figures — including Hungarian investigat­ive journalist­s, the fiancée of slain Saudi journalist Jamal Khashoggi and an exwife of the ruler of Dubai — has occurred since a consortium of internatio­nal news organizati­ons reported in July on a list of possible NSO Group surveillan­ce targets. The list was obtained from an unnamed source by Amnesty Internatio­nal and the Paris-based journalism nonprofit Forbidden Stories. Among those listed was an Associated Press journalist.

From that list of 50,000 phone numbers, reporters from various news organizati­ons were able to confirm at least 47 additional successful hacks, the Washington Post has reported. NSO Group denied ever maintainin­g such a list.

 ?? SEBASTIAN SCHEINER — THE ASSOCIATED PRESS ?? A branch of the NSO Group company near the southern Israeli town of Sapir. The company is facing growing condemnati­on over the abuse of its spyware.
SEBASTIAN SCHEINER — THE ASSOCIATED PRESS A branch of the NSO Group company near the southern Israeli town of Sapir. The company is facing growing condemnati­on over the abuse of its spyware.

Newspapers in English

Newspapers from United States