Posts Tagged ‘hacking’

NGOs demand EU to impose sanctions on NSO Group

December 7, 2021

Dozens of rights groups are urging the European Union to impose sanctions on the Israeli NSO Group to ban the company’s Pegasus surveillance technology. The letter sent to the EU was signed by 86 rights groups and independent experts, including Reporters Without Borders, Amnesty International, Human Rights Watch, the Electronic Frontier Foundation and Privacy International, among others. A consortium of media revealed that this powerful spyware was used extensively by several governments to spy on lawyers, journalists, political opponents and human rights activists.

Several victims of illegal surveillance have been identified in Hungary, where the government initially denied being a client of NSO Group, before admitting to having purchased the software. See also: https://humanrightsdefenders.blog/2021/11/10/palestinian-ngos-dubbed-terrorist-were-hacked-with-pegasus-spyware/

A good resource is here: https://www.haaretz.com/israel-news/MAGAZINE-nso-pegasus-spyware-file-complete-list-of-individuals-targeted-1.10549510

Several victims of illegal surveillance have been identified in Hungary, where the government initially denied being a client of NSO Group, before admitting to having purchased the software. See also:

There is overwhelming evidence that Pegasus spyware has been repeatedly used by abusive governments to clamp down on peaceful human rights defenders, activists and perceived critics,” Deborah Brown, senior digital rights researcher and advocate at Human Rights Watch, said in a statement. “The EU should immediately sanction NSO Group and ban any use of its technologies.”

The EU’s global human rights sanctions would allow the EU to adopt “ “targeted sanctions against entities deemed responsible for violations or abuses that are “of serious concern as regards the objectives of the common foreign and security policy”, including violations or abuses of freedom of peaceful assembly and of association, or of freedom of opinion and expression,” the letter read.

According to Human Rights Watch, these rights have been “repeatedly violated using NSO technology,” and, as highlighted by the UN Special Rapporteur on freedom of opinion and expression, “the use of spyware by abusive governments can also facilitate extrajudicial, summary or arbitrary executions and killings, or enforced disappearance of persons.” See also: https://humanrightsdefenders.blog/2021/10/04/big-coalition-urges-un-to-denounce-abuses-facilitated-by-spyware-technologies/

NSO Group was blacklisted by the US State Department at the beginning of November, and slapped with a sanction that drastically limited the business relationships the US company had with US customers or suppliers, according to the French newspaper Le Monde. “The EU should unequivocally close its doors to business with NSO Group,” Brown said.

“Targeted sanctions are necessary to that end, and to add to growing international pressure against the company and the out-of-control spyware industry.”

In Europe, several investigations are ongoing, but no sanctions have been formally imposed on the company. In addition to Hungary, several other countries are, or have been, customers of NSO Group – although this does not mean that all these countries have made illegal use of Pegasus.

In addition to Germany, several EU countries have purchased access to the software, according to Le Monde.

See also: https://www.haaretz.com/israel-news/tech-news/.premium.HIGHLIGHT.MAGAZINE-citizen-lab-vs-nso-the-institute-taking-down-israel-s-mercenary-spyware-firms-1.10536773

https://slate.com/technology/2021/12/apple-lawsuit-nso-group-q-cyber-pegasus.html

https://www.euronews.com/next/2021/12/03/pegasus-spyware-ngos-urge-the-eu-to-sanction-israeli-group-nso

And the latest: https://marketresearchtelecast.com/spyware-sale-at-nso-group-the-end-of-pegasus/226205/

as well as

https://www.irishtimes.com/news/ireland/irish-news/concern-activist-s-phone-infected-with-spyware-during-dublin-conference-1.4778962

in 2022 the following items can be added:

https://www.hrw.org/news/2022/01/26/human-rights-watch-among-pegasus-spyware-targets

https://thewire.in/tech/nso-chairman-quits-says-departure-unrelated-to-recent-scandals

US Court says Facebook can pursue lawsuit against NSO Group

November 10, 2021

On 8 November 2021 media (here Reuters) reported that a U.S. appeals court said Facebook can pursue a lawsuit accusing Israel’s NSO Group of exploiting a bug in its WhatsApp messaging app to install malware allowing the surveillance of 1,400 people, including journalists, human rights activists and dissidents. In a 3-0 decision on Monday, the 9th U.S. Circuit Court of Appeals in San Francisco rejected privately owned NSO’s claim it was immune from being sued because it had acted as a foreign government agent. See also: https://humanrightsdefenders.blog/2021/10/04/big-coalition-urges-un-to-denounce-abuses-facilitated-by-spyware-technologies/

Facebook, now known as Meta Platforms Inc, sued NSO for an injunction and damages in October 2019, accusing it of accessing WhatsApp servers without permission six months earlier to install its Pegasus malware on victims’ mobile devices. NSO has argued that Pegasus helps law enforcement and intelligence agencies fight crime and protect national security.

It was appealing a trial judge’s July 2020 refusal to award it “conduct-based immunity,” a common law doctrine protecting foreign officials acting in their official capacity. Upholding that ruling, Circuit Judge Danielle Forrest said it was an “easy case” because NSO’s mere licensing of Pegasus and offering technical support did not shield it from liability under federal law, which took precedence over common law.

Whatever NSO’s government customers do with its technology and services does not render NSO an ‘agency or instrumentality of a foreign state,'” Forrest wrote. “Thus, NSO is not entitled to the protection of foreign sovereign immunity.”

The case will return to U.S. District Judge Phyllis Hamilton in Oakland, California.

Asked for comment on the decision, NSO said in an email that its technology helps defend the public against serious crime and terrorism, and that it “stands undeterred in its mission.”

WhatsApp spokesman Joshua Breckman in an email called the decision “an important step in holding NSO accountable for its attacks against journalists, human rights defenders and government leaders.”

Facebook’s case drew support from Microsoft Corp (MSFT.O), Alphabet Inc’s (GOOGL.O) Google and Cisco Systems Corp (CSCO.O), which in a court filing called surveillance technology such as Pegasus “powerful, and dangerous.”

On Nov. 3, the U.S. government blacklisted NSO and Israel’s Candiru for allegedly providing spyware to governments that used it to “maliciously target” journalists, activists and others. See also: https://humanrightsdefenders.blog/2021/11/10/palestinian-ngos-dubbed-terrorist-were-hacked-with-pegasus-spyware/.

https://www.reuters.com/technology/facebook-can-pursue-malware-lawsuit-against-israels-nso-group-us-appeals-court-2021-11-08/

https://gadgets.ndtv.com/apps/news/facebook-meta-pegasus-nso-group-lawsuit-whatsapp-hack-spyware-us-appeals-court-2604175

Vietnamese Human Rights Defenders Targeted with Ocean Lotus Spyware

February 25, 2021

On 24 February 2021 a new Amnesty International investigation has identified a campaign of spyware attacks targeting Vietnamese human rights defenders (HRDs) from February 2018 to November 2020. Amnesty International’s Security Lab attributes these attacks to an attack group known as Ocean Lotus. The group has been active since at least 2014, targeting the private sector and HRDs. The spyware attacks investigated and identified by the Security Lab are the latest evidence of a crackdown on freedom of expression in Viet Nam and against Vietnamese activists outside the country.

Viet Nam’s history of Online Repression: Human rights are increasingly under attack both offline and online in Viet Nam. Over the past 15 years, repression linked to online activity has intensified, leading to a wave of harassment, intimidation, physical assault, and prosecution. Amnesty International has documented multiple cases of the arrest and prosecution of HRDs in Viet Nam in retaliation for their online expression since 2006. That year, former prisoner of conscience Truong Quoc Huy was arrested at an internet café in Ho Chi Minh City. Many activists and bloggers have been convicted for “conducting propaganda against the state.” Human rights blogger Nguyen Ngoc Nhu Quynh (Mother Mushroom) was sentenced to 10 years in prison in June 2017 on such charges. Activists and bloggers also face frequent physical assaults by officials or government-connected thugs. [see: https://www.trueheroesfilms.org/thedigest/laureates/70F07728-1E21-4D33-F0BE-460D5A188B9D] Police place activists under house arrest or briefly detain them to prevent them from participating in public events. The government also uses travel bans to prevent activists and HRDs from going abroad and engaging with the international community. In December 2020, Amnesty International published “Let Us Breathe”, a report documenting the widespread criminalization, online harassment and physical attacks faced by activists and bloggers and the rising numbers of individuals detained for peacefully expressing themselves online. [see: https://humanrightsdefenders.blog/2020/12/01/facebook-and-youtube-are-allowing-themselves-to-become-tools-of-the-vietnamese-authorities-censorship-and-harassment/ ]

What is Ocean Lotus?

The cyber-security industry, comprised of individual and company-based researchers, routinely researches and publishes information about attack groups targeting companies and governments. The industry often gives informal names to groups they continuously track based on each group’s unique tactics and tools. Ocean Lotus (also commonly called APT32 or APT-C-00) is one of these groups. The first known Ocean Lotus attack happened in 2014. It targeted US-based NGO Electronic Frontier Foundation (EFF), the Associated Press international news organization and two Vietnamese activists. This group was named Ocean Lotus in a report from the Chinese company Qihoo 360 in May 2015. In 2017, the American cyber-security company FireEye published a report linking the 2014 EFF and other attacks to this same Ocean Lotus. Over the years, Ocean Lotus has developed a sophisticated spyware toolkit comprised of several variants of Mac OS spyware, Android spyware and Windows spyware. They also strategically compromise websites in order to identify visitors and conduct further targeting. More recently, Ocean Lotus was found creating fake media websites based on content automatically gathered online. A significant part of the group’s activities is the targeting of HRDs and civil society. In 2017, the cyber-security company Volexity revealed that over 100 websites were compromised, including many belonging to human rights organizations from Viet Nam, in an attack campaign that they attributed to Ocean Lotus. Numerous other spyware attacks linked to Ocean Lotus against human rights organizations have also been reported, such as the targeting of the Cambodian human rights organization, LICADHO, in 2018. The cyber-security company FireEye describes Ocean Lotus’ operations as “aligned with Vietnamese state interests” based on the list of targeted companies and civil society groups they identified. In December 2020, Facebook published a threat report linking Ocean Lotus’ activities with a Vietnamese company named CyberOne Group. Although Amnesty International was unable to independently verify any direct connection between Ocean Lotus and Cyber One or with the Vietnamese authorities, the attacks described in this investigation confirm a pattern of targeting Vietnamese individuals and organizations.

Attacks against HRDs.

The investigation conducted by Amnesty International’s Security Lab revealed that two HRDs and a non-profit human rights organization from Viet Nam have been targeted by a coordinated spyware campaign. This spyware allows to fully monitor a compromised system, including reading and writing files, or launching other malicious programs. Bui Thanh Hieu is a blogger and pro-democracy activist who goes by the name “Nguoi Buon Gio” (The Wind Trader). He writes about social and economic justice and human rights. He is also critical of the Vietnamese government’s policies and actions regarding its relations with China, including the dispute over sovereignty in the South China Sea. Due to his writing and activism, the licence for an Internet Café he owned in Ha Noi has been revoked and he has been repeatedly subjected to reprisals. He was arrested along with activists Pham Doan Trang [see https://www.trueheroesfilms.org/thedigest/laureates/fe8bf320-1d78-11e8-aacf-35c4dd34b7ba] and Nguyen Ngoc Nhu Quynh in 2009 and was kept in police custody for 10 days for“abusing democratic freedoms to infringe upon the interests of the State.” In January 2013, Bui Thanh Hieu reported on the trial of 14 dissidents in Viet Nam and was arrested and released a few days later. He has since left Viet Nam and has lived in exile in Germany since 2013. Vietnamese Overseas Initiative for Conscience Empowerment (VOICE) is a non-profit organization supporting Vietnamese refugees and promoting human rights in Viet Nam. It was established in 1997 in the Filipino capital of Manila as a legal aid office, before formally registering in the United States in 2007. The organization continues to operate out of Manila and has helped 3,000 Vietnamese refugees resettle in third countries. Since 2011, VOICE has operated an internship programme to equip Vietnamese people with knowledge, skills, and tools to become effective activists. The organization has faced reprisals from Vietnamese authorities several times. Staff at VOICE told Amnesty International that employees and interns have been harassed, banned from travelling, and have had their passports confiscated when they have returned to Viet Nam. Furthermore, state-owned media has run an unsubstantiated smear campaign against VOICE, claiming that the organization is a terrorist group. A blogger residing in Viet Nam has also been confirmed as an Ocean Lotus target by the Security Lab, but due to security concerns their name has been omitted. They are known to have spoken out publicly about the Dong Tam incident on 9 January 2020, when approximately 3,000 security officers from Ha Noi raided Dong Tam village and killed the 84-year-old village leader Le Dinh Kinh. Three police officers were also killed. The Dong Tam incident sparked a national outcry in Viet Nam. Activists and bloggers were at the forefront of the public debate online, prompting a nationwide crackdown on on-line expression by the government. VOICE and the two bloggers all received emails containing spyware between February 2018 and November 2020. These emails pretended to share an important document. They either contained spyware as an attachment or as a link. Once downloaded and launched on the victim’s computer, the spyware would then open a decoy document in line with what the email pretended to share to trick the victim in believing the file was benign. Screenshot of the email sent to VOICE in April 2020The spyware identified by the Security Lab were either for Mac OS or Windows systems. The Windows spyware was a variant of a malware family called Kerrdown and used exclusively by the Ocean Lotus group. Kerrdown is a downloader that installs additional spyware from a server on the victim’s system and opens a decoy document. In this case, it downloaded Cobalt Strike, a commercial spyware toolkit developed by the American company Strategy Cyber and routinely used to lawfully audit the security of organizations through simulated attacks. It allows an attacker full access to the compromised system including executing scripts, taking screenshots or logging keystrokes. Unlicensed versions of Cobalt Strikes have been increasingly used by attack groups, including Ocean Lotus, over the past three years.Example of Windows Spyware Infection Chain from one of the emails received The Mac OS Spyware was a variant of a malware family for Mac OS developed and used exclusively by Ocean Lotus, analysed by Trend Micro in April 2018 and November 2020. It allows the perpetrator to access system information, download, upload or execute files and execute commands.

Tech giants join legal battle against NSO

December 22, 2020

Raphael Satter reports on 22 December 2020 for Reuters that tech giants Google, Cisco and Dell on Monday joined Facebook’s legal battle against hacking company NSO, filing an amicus brief in federal court that warned that the Israeli firm’s tools were “powerful, and dangerous.”

The brief, filed before the U.S. Court of Appeals for the Ninth Circuit, opens up a new front in Facebook’s lawsuit against NSO, which it filed last year after it was revealed that the cyber surveillance firm had exploited a bug in Facebook-owned instant messaging program WhatsApp to help surveil more than 1,400 people worldwide. See also: https://humanrightsdefenders.blog/2020/07/20/the-ups-and-downs-in-sueing-the-nso-group/

NSO has argued that, because it sells digital break-in tools to police and spy agencies, it should benefit from “sovereign immunity” – a legal doctrine that generally insulates foreign governments from lawsuits. NSO lost that argument in the Northern District of California in July and has since appealed to the Ninth Circuit to have the ruling overturned.

Microsoft, Alphabet-owned Google, Cisco, Dell Technologies-owned VMWare and the Washington-based Internet Association joined forces with Facebook to argue against that, saying that awarding soverign immunity to NSO would lead to a proliferation of hacking technology and “more foreign governments with powerful and dangerous cyber surveillance tools.”

That in turn “means dramatically more opportunities for those tools to fall into the wrong hands and be used nefariously,” the brief argues.

NSO – which did not immediately return a message seeking comment – argues that its products are used to fight crime. But human rights defenders and technologists at places such as Toronto-based Citizen Lab and London-based Amnesty International have documented cases in which NSO technology has been used to target reporters, lawyers and even nutrionists lobbying for soda taxes.

Citizen Lab published a report on Sunday alleging that NSO’s phone-hacking technology had been deployed to hack three dozen phones belonging to journalists, producers, anchors, and executives at Qatar-based broadcaster Al Jazeera as well as a device beloning to a reporter at London-based Al Araby TV.

NSO’s spyware was also been linked to the slaying of Washington Post journalist Jamal Khashoggi, who was murdered and dismembered in the Saudi consulate in Istanbul in 2018. Khashoggi’s friend, dissident video blogger Omar Abdulaziz, has long argued that it was the Saudi government’s ability to see their WhatsApp messages that led to his death.

NSO has denied hacking Khashoggi, but has so far declined to comment on whether its technology was used to spy on others in his circle.

https://www.reuters.com/article/us-facebook-nso-cyber/microsoft-google-cisco-dell-join-legal-battle-against-hacking-company-nso-idUSKBN28V2WX?il=0

The Ups and downs in sueing the NSO Group

July 20, 2020

Written By Shubham Bose

facebook

While AI stranded in its effort in Israel [https://humanrightsdefenders.blog/2020/07/15/amnesty-internationals-bid-to-block-spyware-company-nso-fails-in-israeli-court/ ] a federal US court has passed an order allowing WhatsApp to move forward with its case against the Israeli company for allegedly targeting 1,400 users with malware in 2019. According to reports, it is believed that spyware produced by the Israeli firm NSO Group was used to target various groups of people around the world, such as journalists, human rights defenders, and even politicians. [see: https://humanrightsdefenders.blog/2019/10/30/nso-accused-of-largest-attack-on-civil-society-through-its-spyware/

Judge Phyllis Hamilton, in her ruling on the cases, stated that she was not convinced by NSO Group’s claims and arguments that it had no hand in targeting WhatsApp users. Moving forward in the trial, the NSO Group might be forced to reveal its clients and make the list public.

The judge also added that even if NSO was operating at the direction of its customer, it still appeared to have a hand in targeting WhatsApp users. As per reports, a WhatsApp spokesperson said the Facebook-owned venture was pleasd with the court’s decision and will now be able to uncover the practices of NSO Group.

Even in the face of criticism from privacy advocates, the company has claimed that law enforcement agencies are facing difficulties due to the proliferation of encrypted messaging apps like WhatsApp.

The law firm King & Spalding has reportedly been hired by the NSO group to represent them. Among the company’s legal team is Rod Rosenstein, Trump administration’s former attorney general. The NSO Group has reportedly had multiple government clients like Saudi Arabia, Mexico, and the United Arab Emirates who have used spyware to target political opponents and human rights, campaigners.

https://www.republicworld.com/world-news/us-news/whatsapp-lawsuit-against-israeli-firm-nso-group-given-green-light-by-u.html

Amnesty International’s bid to block spyware company NSO fails in Israeli court

July 15, 2020

Amnesty International’s bid to block spyware company NSO Group’s international export licence has been shut down in a Tel Aviv court, apparently due to a lack of evidence, reported several media, here in the New Statesman of 14 July 2020. [see: https://humanrightsdefenders.blog/2019/09/17/has-nso-really-changed-its-attitude-with-regard-to-spyware/ ]

The case argued that the Israeli defence ministry should revoke the group’s export licence in light of numerous allegations that its phone-hacking Pegasus spyware has been used by governments (including Mexico, Saudi Arabia, Morocco and the UAE) to spy on civilians including an Amnesty International employee, human rights activists, lawyers and journalists..

The district court judge Rachel Barkai wrote in a statement that there was not enough evidence to “substantiate the claim that an attempt was made to monitor a human rights activist”. She wrote that in reviewing materials provided by the Ministry of Defence and Ministry of Foreign Affairs, she was persuaded that export licences were granted as part of a “sensitive and rigorous process”, and closely monitored and revoked if conditions were violated, “in particular in cases of human rights violations.”

Amnesty International decried the court’s decision. Danna Ingleton, acting co-director of Amnesty Tech, said in a statement: “Today’s disgraceful ruling is a cruel blow to people put at risk around the world by NSO Group selling its products to notorious human rights abusers. […] The ruling of the court flies in the face of the mountains of evidence of NSO Group’s spyware being used to target human rights defenders from Saudi Arabia to Mexico, including the basis of this case – the targeting of one of our own Amnesty employees.

NSO said: “Our detractors, who have made baseless accusations to fit their own agendas, have no answer to the security challenges of the 21st century. Now that the court’s decision has shown that our industry is sufficiently regulated, the focus should turn to what answer those who seek to criticise NSO have to the abuse of encryption by nefarious groups.”

The NSO Group is currently embroiled in another lawsuit brought by WhatsApp, which alleges that Pegasus spyware was used to hack more than a thousand of the messaging platform’s users. [see: https://humanrightsdefenders.blog/2019/10/30/nso-accused-of-largest-attack-on-civil-society-through-its-spyware/]

https://tech.newstatesman.com/security/amnesty-international-nso-group-export-licence

After NSO, now Indian based hacking group targets NGOs

June 10, 2020

A multi-year investigation by Citizen Lab has unearthed a hack-for-hire group from India that targeted journalists, advocacy groups, government officials, hedge funds, and human rights defenders.

A lot has been written about the NSO group and human rights defenders [see: https://humanrightsdefenders.blog/tag/nso-group/], now another case of cyber insecurity has come up:

Jay Jay – a freelance technology writer – posted an article in Teiss on 9 June 2020 stating that Citizen Lab revealed in a blog post published Tuesday that the hack-for-hire group’s identity was established after the security firm investigated a custom URL shortener that the group used to shorten the URLs of phishing websites prior to targeting specific individuals and organisations. Citizen Lab has named the group as “Dark Basin“.

“Over the course of our multi-year investigation, we found that Dark Basin likely conducted commercial espionage on behalf of their clients against opponents involved in high profile public events, criminal cases, financial transactions, news stories, and advocacy,” the firm said.

It added that the hack-for-hire group targeted thousands of individuals and organisations in six continents, including senior politicians, government prosecutors, CEOs, journalists, and human rights defenders, and is linked to BellTroX InfoTech Services, an India-based technology company.

….The range of targets, that included two clusters of advocacy organisations in the United States working on climate change and net neutrality, made it clear to Citizen Lab that Dark Basin was not state-sponsored but was a hack-for-hire operation.

…As further proof of Dark Basin’s links with BellTroX, researchers found that several BellTroX employees boasted capabilities like email penetration, exploitation, conducting cyber intelligence operations, pinging phones, and corporate espionage on LinkedIn. BellTroX’s LinkedIn pages also received endorsements from individuals working in various fields of corporate intelligence and private investigation, including private investigators with prior roles in the FBI, police, military, and other branches of government.

The list of organisations targeted by Dark Basin over the past few years includes Rockefeller Family Fund, Greenpeace, Conservation Law Foundation, Union of Concerned Scientists, Oil Change International, Center for International Environmental Law, Climate Investigations Center, Public Citizen, and 350.org. The hack-for-hire group also targeted several environmentalists and individuals involved in the #ExxonKnew campaign that wanted Exxon to face trial for hiding facts about climate change for decades.

A separate investigation into Dark Basin by NortonLifeLock Labs, which they named “Mercenary.Amanda”, revealed that the hack-for-hire group executed persistent credential spearphishing against a variety of targets in several industries around the globe going back to at least 2013…

https://www.teiss.co.uk/indian-hack-for-hire-group-phishing/

https://thewire.in/tech/spyware-rights-activists-lawyers-citizen-lab

https://scroll.in/latest/964803/nine-activists-most-of-them-working-to-release-bhima-koregaon-accused-targets-of-spyware-amnesty

Also: Hack-for-hire firms spoofing WHO accounts to target organisations worldwide

NSO versus Whatsapp continues in court

May 5, 2020

WhatsApp logo is seen displayed on a smart phone screen on 11 December 2019 [Ali Balıkçı/Anadolu Agency]

WhatsApp logo is seen displayed on a smart phone screen on 11 December 2019 [Ali Balıkçı/Anadolu Agency]

The NSO Group has always maintained its innocence insisting that its spyware is purchased by government clients for the purpose of tracking terrorists and criminals and that it had no independent knowledge of how those clients use its spyware. This claim is contradicted by court documents in WhatsApp’s lawsuit filed last year against the Israeli firm. While bringing the lawsuit, WhatsApp said in a statement that 100 civil society members had been targeted and called it “an unmistakable pattern of abuse”. New documents seen last week indicate that servers controlled by NSO Group and not its government clients, as alleged by the Israeli firm, were an integral part of how the hacks were executed. “NSO used a network of computers to monitor and update Pegasus after it was implanted on users’ devices,” said WhatsApp, “these NSO-controlled computers served as the nerve centre through which NSO controlled its customers’ operation and use of Pegasus [software used to hack computers and phones].”NSO Group is also accused by WhatsApp of gaining “unauthorised access” to its servers by evading the company’s security features.

n the ongoing legal battle between Facebook and software surveillance company NSO Group, the social media giant is trying to get NSO Group’s legal counsel dismissed because of an alleged conflict of interest. In a court filing made public this week, Facebook asked a federal judge to disqualify law firm King & Spalding from representing NSO Group because the firm previously represented Facebook-owned WhatsApp in a different, sealed case that is “substantially related” to the NSO Group one. King & Spalding, an Atlanta-based firm with a range of big corporate clients, has denied there is a conflict of interest, according to the filing.“Any attorney defending this suit would love to have insight into how WhatsApp’s platform and systems work,” the court filing states. “And King & Spalding has that insight—because it was once WhatsApp’s counsel.”The dispute with Facebook is one of multiple legal battles currently facing NSO Group. Amnesty International is trying to get an Israeli court to revoke NSO Group’s export license in Israel, citing Pegasus’s alleged role in humans rights abuses. [see: https://humanrightsdefenders.blog/2019/09/17/has-nso-really-changed-its-attitude-with-regard-to-spyware/]https://www.amnesty.org/en/latest/news/2020/06/nso-spyware-used-against-moroccan-journalist/

https://www.cyberscoop.com/nso-group-lawsuit-whatsapp-conflict-of-interest-king-spalding/

Israel’s NSO Group accused of ‘unmistakable pattern of abuse’ in hacking case

Novalpina urged to come clean about targeting human rights defenders

February 19, 2019

In an open letter released today, 18 February 2019, Amnesty International, Human Rights Watch and five other NGOs urged Novalpina to publicly commit to accountability for NSO Group’s past spyware abuses, including the targeting of an Amnesty International employee and the alleged targeting of Jamal Khashoggi. [see also: https://humanrightsdefenders.blog/2016/08/29/apple-tackles-iphone-one-tap-spyware-flaws-after-mea-laureate-discovers-hacking-attempt/]

Danna Ingleton, Deputy Director of Amnesty Tech, said: “Novalpina’s executives have serious questions to answer about their involvement with a company which has become the go-to surveillance tool for abusive governments. This sale comes in the wake of reports that NSO paid private operatives to physically intimidate individuals trying to investigate its role in attacks on human rights defenders – further proof that NSO is an extremely dangerous entity.

We are calling on Novalpina to confirm an immediate end to the sale or further maintenance of NSO products to governments which have been accused of using surveillance to violate human rights. It must also be completely transparent about its plans to prevent further abuses.

This could be an opportunity to finally hold NSO Group to account. Novalpina must commit to fully engaging with investigations into past abuses of NSO’s spyware, and ensure that neither NSO Group nor its previous owners, Francisco Partners, are let off the hook.”

The signatories to the letter are:

  • Amnesty International
  • R3D: Red en Defensa de los Derechos Digitales
  • Privacy International
  • Access Now
  • Human Rights Watch
  • Reporters Without Borders
  • Robert L. Bernstein Institute for Human Rights, NYU School of Law and Global Justice Clinic, NYU School of Law

https://www.amnesty.org/en/latest/news/2019/02/spyware-firm-buyout-reaffirms-urgent-need-for-justice-for-targeted-activists/

https://www.amnesty.org/en/latest/research/2019/02/open-letter-to-novalpina-capital-nso-group-and-francisco-partners/

European Parliament votes to restrict exports of surveillance equipment

January 22, 2018
Members of the European Parliament have voted to curb export of surveillance equipment to states with poor human rights records, following mounting evidence that equipment supplied by companies in Europe has been used by oppressive regimes to suppress political opponents, journalists and campaigners. MEPs in Strasbourg agreed on 17 January to extend EU export controls to include new restrictions on the export of surveillance equipment, including devices for intercepting mobile phones, hacking computers, circumventing passwords and identifying internet users. The proposals also seek to remove encryption technologies from the list of technologies covered by EU export controls, in a move which aims to make it easier for people living in oppressive regimes to gain access to secure communications which can circumvent state surveillance.

Dictators spy on their citizens using EU cyber-surveillance. This must stop. The EU cannot contribute to the suffering of courageous activists, who often risk their lives for freedom and democracy,” said MEP Klaus Buchner, European Parliament rapporteur. “We are determined to close dangerous gaps in the export of dual-use goods and call on member states to follow suit.”

The proposed changes to the EU dual use export control regime are likely to face opposition from the defence industry and governments, as the European Parliament, and the European Commission prepare to negotiate their implantation with Europe’s 28 member states.

European technology companies, including UK firms, have supplied equipment that  has been used for arresting, torturing, and killing people in Iran, Egypt, Ethiopia, and Morocco, according to the European Parliament. An investigation by Computer Weekly revealed that the UK government had approved export licences to Gamma International (UK) to supply mobile phone interception equipment, known as IMSI catchers, to Macedonia, when the regime was engaged in a massive illegal surveillance operation against the public and political opponents.

And the UK’s largest arms manufacturer, BAE Systems, has exported equipment capable of mass internet surveillance to countries that campaigners say regularly commit human rights abuses, including Saudi Arabia, Qatar, Oman, Morocco and Algeria. An overwhelming majority of MEPs supported reforms to the EU’s export control regime, which will require member states to deny export licences if the export of surveillance technology is likely to lead to a serious impact on human rights in the destination country. The proposed changes, backed by 571 votes to 29 against, with 29 abstentions, will impose tough requirements for EU governments.

Member states will be required to assess the likely impact of surveillance technology on citizens’ right to privacy, freedom of speech, and freedom of association, in the destination country before they grant  export licences – a significant step up from current levels of scrutiny.

The proposed rules contain safeguards, however, that will allow legitimate cyber-security research to continue. Companies exporting products that are not specifically listed will be expected to follow the OECD’s “due diligence” guidelines, if there is a risk they could support human-rights violations.

Improved transparency measures will require member states to record and make data on approved and declined export licences publicly available, opening up the secretive global trade in surveillance technologies to greater public scrutiny.

http://www.computerweekly.com/news/252433519/European-Parliament-votes-to-restrict-exports-of-surveillance-equipment