search

Bahrain used NSO spyware to target activists, says cybersecurity watchdog

In response, the embattled Israeli cyber firm questions the methods and motives behind the new report

Illustrative. An Israeli woman uses her phone in front of a building in Herzliya that housed the NSO Group intelligence firm, on August 28, 2016. (Jack Guez/AFP/File)
Illustrative. An Israeli woman uses her phone in front of a building in Herzliya that housed the NSO Group intelligence firm, on August 28, 2016. (Jack Guez/AFP/File)

RICHMOND, Virginia (AP) — Nine activists from Bahrain had their iPhones hacked by advanced spyware made by Israel’s NSO Group, the world’s most infamous hacker-for-hire firm, a cybersecurity watchdog reported on Tuesday.

Citizen Lab at the University of Toronto said NSO Group’s Pegasus malware successfully hacked the phones between June 2020 and February 2021. Those reportedly hacked included members of the Bahrain Center for Human Rights and two political dissidents living in exile. At least one of the activists lived in London when the hacking occurred, Citizen Lab said.

Citizen Lab said it has “high confidence” that at least four of the activists were hacked by the Bahraini government, which has a history of using commercially available spyware. One of the activists targeted is Moosa Mohammed, who said he was previously a victim of spyware in 2012.

“When I fled torture and persecution in Bahrain, I thought I would find safety in London but have continued to face surveillance and physical attacks by Gulf regimes,” he said.

The government of Bahrain, a tiny island kingdom off the coast of Saudi Arabia that’s home to the US Navy’s 5th Fleet, has a long history of suppressing dissent. But it said in a statement, “these claims are based on unfounded allegations and misguided conclusions. The government of Bahrain is committed to safeguarding the individuals’ rights and freedoms.”

NSO Group said in a statement that it had not yet seen the report, but questioned Citizen Lab’s methods and motives. “If NSO receives reliable information related to the misuse of the system, the company will vigorously investigate the claims and act accordingly,” the company said.

Congress party workers shout slogans during a protest accusing Prime Minister Narendra Modi’s government of using military-grade spyware to monitor political opponents, journalists and activists in New Delhi, India, Tuesday, July 20, 2021. (AP Photo/Manish Swarup)

Citizen Lab found that in some instances the malware infected targeted iPhones without the users taking any action — what’s known as a zero-click vulnerability.

Bill Marczak of Citizen Lab said the exploits worked against a recent version of the iPhone’s operating system, adding that there’s “no indication that the bugs exploited have been fixed.”

Ivan Krstic, head of Apple Security Engineering and Architecture, said such attacks are costly and often have a short shelf life. “They are not a threat to the overwhelming majority of our users,” he said in a statement, adding that Apple constantly adds new protections for its devices and data.

The new report is the latest unwelcome news for NSO Group. The firm was the focus of recent reports by a media consortium that found the company’s spyware tool Pegasus was used in several instances of successful or attempted phone hacks of business executives, human rights activists and others around the world.

French President Emmanuel Macron speaks on his cellphone during a round table meeting at an EU summit in Brussels, on July 20, 2020. (John Thys, Pool Photo via AP)

Those investigations, based on leaked data obtained by the Paris-based journalism nonprofit Forbidden Stories and the human rights group Amnesty International, sparked widespread condemnation of the company.

Israel’s Defense Ministry has vowed to look into such claims and take action against the company if necessary. Defense Minister Benny Gantz asserted that Israel follows international law when it comes to exporting cyber software.

Last month, around 1,000 protesters in Hungary’s capital demanded answers to allegations that the country’s right-wing government used Pegasus to secretly monitor critical journalists, lawyers and business figures. India’s parliament also erupted in protests as opposition lawmakers accused Prime Minister Narendra Modi’s government of using NSO Groups’ product to spy on opponents and others.

France is also trying to get to the bottom of allegations that President Emmanuel Macron and members of his government may have been targeted in 2019 by an unidentified Moroccan security service using Pegasus. Morocco, a key French ally, denied those reports and is taking legal action to counter allegations implicating the North African kingdom in the spyware scandal.

Facebook is currently suing NSO Group in US federal court for allegedly targeting some 1,400 users of its encrypted messaging service WhatsApp with highly sophisticated spyware. That includes users in Bahrain, Facebook said.

Human rights experts working with the United Nations recently called on countries to pause the sale and transfer of spyware and other surveillance technology until they set rules governing its use, with the aim of ensuring that it won’t impinge upon human rights.

read more:
comments
Never miss breaking news on Israel
Get notifications to stay updated
You're subscribed