TechCrunch News 04月10日 02:28
Court document reveals locations of WhatsApp victims targeted by NSO spyware
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

根据一份新的法庭文件,NSO Group的Pegasus间谍软件在2019年的一次黑客攻击中,针对51个不同国家的1223名WhatsApp用户。该文件是Meta拥有的WhatsApp在2019年对NSO Group提起的诉讼的一部分,指控这家监控技术制造商利用聊天应用程序中的漏洞,攻击了包括100多名活动家、记者和“其他社会成员”在内的数百名用户。该文件提供了受害者所在国家的详细信息,墨西哥受害者最多,有456人,其次是印度、巴林、摩洛哥等。这次黑客攻击仅持续了两个月,揭示了政府间谍软件问题的严重性。

📱在2019年的一次黑客攻击中,NSO Group的Pegasus间谍软件被用于攻击51个不同国家的1223名WhatsApp用户。

🌎受害者遍布全球,其中墨西哥受害者最多,有456人,印度有100人,巴林有82人,摩洛哥有69人,巴基斯坦有58人,印度尼西亚有54人,以色列有51人。

⏱️这次黑客攻击发生在2019年4月至5月之间,仅持续了两个月的时间,表明了间谍软件的快速部署和潜在的广泛影响。

💰NSO Group的间谍软件价格昂贵,一个为期一年的许可证费用高达680万美元,仅2019年就带来了至少3100万美元的收入,这反映了政府间谍软件市场的商业价值。

⚖️WhatsApp在诉讼中取得了一项历史性胜利,法官裁定NSO Group违反了美国的黑客法律。下一步将确定这家间谍软件制造商需要向WhatsApp支付的赔偿金额。

NSO Group’s notorious spyware Pegasus was used to target 1,223 WhatsApp users in 51 different countries during a 2019 hacking campaign, according to a new court document

The document was published on Friday as part of the lawsuit that Meta-owned WhatsApp filed against NSO Group in 2019, accusing the surveillance tech maker of exploiting a vulnerability in the chat app to target hundreds of users, including more than 100 human rights activists, journalists, and “other members of civil society.”

At the time, WhatsApp said around 1,400 users had been targeted. Now, an exhibit published in the court document shows exactly in what countries 1,223 specific victims were located when they were targeted with NSO Group’s Pegasus spyware. 

The country breakdown is a rare insight into which NSO Group customers may be more active, and where their victims and targets are located. 

The countries with the most victims of this campaign are Mexico with 456 individuals, India with 100, Bahrain with 82, Morocco with 69, Pakistan with 58, Indonesia with 54, and Israel with 51, according to a chart titled “Victim Country Count,” that WhatsApp submitted as part of the case.

There are also victims in Western countries like Spain (12 victims), the Netherlands (11), Hungary (8), France (7), United Kingdom (2), and one victim in the United States. 

The court document with the list of victims by country was first reported by Israeli news site CTech

“Numerous news articles have been written over the years documenting use of Pegasus to target victims around the world,” said Runa Sandvik, a cybersecurity expert who’s been tracking victims of government spyware for years.

“What’s often missing from these articles is the true scale of the targeting — the number of victims who were not notified; who did not get their devices checked; who opted not to share their story publicly. The list we see here — with 456 cases in Mexico alone, a country with documented, well-known civil society victims — speaks volumes about the true scale of the spyware problem,” Sandvik told TechCrunch.

Do you have more information about NSO Group, or other spyware companies? From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

Another piece of data that shows the scale of the government spyware problem is that the hacking campaign targeting WhatsApp users occurred over a period of only two months, “between in and around April 2019 and May 2019,” as WhatsApp wrote in its original complaint.

In other words, in just two months, NSO Group’s government customers targeted more than a thousand WhatsApp users.

It’s important to note that it is not clear if the fact that there is a victim located in a certain country means that specific country’s government was the customer using NSO Group’s spyware against those victims. It’s possible that a government customer could be using Pegasus to target someone outside of the country. 

As CTech noted, Syria appears on the victim list, but NSO Group cannot export its technology to Syria, a country that’s sanctioned by countries all over the world

The number of victims also gives an insight into who may be NSO Group’s highest-paying customers. Companies like NSO Group, and other predecessors like Hacking Team and FinFisher, determine what price to offer their surveillance products to their customers in part by the number of targets that can be concurrently infected with the spyware. 

Mexico, for example, was reported to have spent more than $60 million on NSO Group’s spyware, according to a 2023 New York Times article that cited Mexican officials, which could explain why there are so many Mexican targets in this list. 

Last year, WhatsApp scored an historic victory when the judge presiding over the lawsuit ruled that NSO Group had breached U.S. hacking laws by targeting WhatsApp users. The next step in the lawsuit is an upcoming hearing that will determine the damages that the spyware maker will have to pay to WhatsApp. 

Apart from this list of victims, the court case brought by WhatsApp has led to other revelations, including the fact that NSO Group disconnected 10 government customers after reports that they abused the spyware, and that the WhatsApp hacking tool produced by NSO Group cost up to $6.8 million for a one year license, which in total netted the company “at least $31 million in revenue in 2019.”

WhatsApp spokesperson Zade Alsawah declined to comment. NSO Group did not respond to a request for comment.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

NSO Group Pegasus WhatsApp 间谍软件 黑客攻击
相关文章