Pegasus spyware spied on mobile users around the world

malware
(Image credit: Shutterstock)

Notable figures such as journalists, activists and politicians have been targeted by phone malware sold to governments by an Israeli software firm.

Multiple reports have claimed the Pegasus spyware was sold by NSO Group to authoritarian governments around the world in order to carry out surveillance on opposition groups and dissidents alike.

A list of around 50,000 phone numbers of individuals affected was leaked to Paris-based NGO Forbidden Stories and human rights group Amnesty International before being reported worldwide, although exactly who revealed the information is still unclear at the moment.

Accusations

NSO denies any wrongdoing, telling the BBC that the report was, "full of wrong assumptions and uncorroborated theories".

The company says its software is sold only to military, law enforcement and intelligence agencies in countries with good human rights records in order to help tackle criminals and terrorists.

The list of 50,000 numbers reportedly contains over 1,000 individuals from more than 50 countries, although 10 countries(Azerbaijan, Bahrain, Hungary, India, Kazakhstan, Mexico, Morocco, Rwanda, Saudi Arabia and the United Arab Emirates) made up the bulk of the entrants.

Affected figures included around 180 journalists, from outlets including CNN, the New York Times and Al Jazeera, several Arab royal family members, politicians, business executives, and political activists - including several close contacts (such as the wife and fiancee) of murdered Saudi journalist Jamal Khashoggi.

Android phone malware

(Image credit: Shutterstock)

The news is not the first time NSO or Pegasus has made headlines for reportedly malicious activity.

In 2019, the company was sued by WhatsApp over allegations 1,400 of its users in 20 countries had been targeted by Pegasus. Although NSO denied any wrongdoing, the company was blocked from using WhatsApp.

The latest allegations include claims that Pegasus infects Android devices and iPhones, giving operators (governments, in this case) access to messages, photos and emails. It can also record calls and surreptitiously activate microphones.

The spyware reportedly needs little activity to install itself on a victim's phone - which can in fact be done via a simple WhatsApp call.

Using this, data packets are altered in the voice call sent to the target/victim, leading to an internal buffer in the WhatsApp application to overflow, which in turn will overwrite parts of the memory leading to the bypassing of the app’s security, allowing further control of the whole device and the data within it.

Researchers claim that 'authoritarian governments' have been known to create fake WhatsApp accounts to make video calls to their targets, transmitting the malicious code and auto-installing the spyware even if the targets did not answer the call.

Experts say that the only way to completely free your mobile of spyware like Pegasus is to discard the phone - as even a 'factory reset' may not be enough to secure your phone back.

TechRadar Pro has contacted NSO Group for comment.

Via The Guardian

Balakumar K
Senior Editor

Over three decades as a journalist covering current affairs, politics, sports and now technology. Former Editor of News Today, writer of humour columns across publications and a hardcore cricket and cinema enthusiast. He writes about technology trends and suggest movies and shows to watch on OTT platforms. 

Read more
WhatsApp China VPN
Paragon spyware campaign targeting journalists disrupted by WhatsApp
Giant eye watching at man working at the computer. Surveillance, hacking, internet security concept. Flat vector illustration.
Israeli spyware company confirms US government and friends are customers
Trojan
WhatsApp patches security flaw which let hackers install spyware
Spyware
Government-linked Italian spyware maker caught distributing malicious Android apps
An illustration of a 1960s spy with sunglasses and a big coat
Paragon spyware cancels contract with Italian government after targeting journalists and citizens across Europe
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras