{"id":2480,"date":"2024-02-05T19:20:27","date_gmt":"2024-02-05T19:20:27","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/pegasus-spyware-targets-jordanian-civil-society"},"modified":"2024-02-05T19:20:27","modified_gmt":"2024-02-05T19:20:27","slug":"pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/02\/05\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks\/","title":{"rendered":"Pegasus Spyware Targets Jordanian Civil Society in Wide-Ranging Attacks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt99e755ba1f21e05b\/65c118f67ffa3d040a3e8466\/coredesign-digital-pegasus-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Journalists, lawyers, and human-rights activists in the Middle Eastern nation of Jordan face increased surveillance from the controversial Pegasus spyware app, with nearly three dozen civilians targeted over the past four years.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to an <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.accessnow.org\/publication\/between-a-hack-and-a-hard-place-how-pegasus-spyware-crushes-civic-space-in-jordan\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">analysis published<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by digital rights group Access Now, in total 16 journalists and media staff, eight human-rights lawyers, and 11 other members of human-rights groups and non-governmental organizations (NGOs) were targeted by state-sponsored attackers (the report intimated it was the Jordanian government itself) using the Pegasus rootkit and surveillance tool, the investigation found.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While the investigation started in 2021, the actual attacks started in 2019, with 30 victims discovered by Access Now and Citizen Lab, part of the Munk School of Global Affairs and Public Policy at the University of Toronto, while another five victims were uncovered by Human Rights Watch, Amnesty International, and the Organized Crime and Corruption Reporting Project (OCCRP).<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Spyware Used to Intimidate &amp; Dissuade\">Spyware Used to Intimidate &amp; Dissuade<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Using surveillance tools to wiretap and track the activities of journalists and lawyers undermines free society, warned Access Now.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Surveillance technologies and cyberweapons such as NSO Group&#8217;s Pegasus spyware are used to target human rights defenders and journalists, to intimidate and dissuade them from their work, to infiltrate their networks, and to gather information for use against other targets,&#8221; Access Now stated in its report. &#8220;The targeted surveillance of individuals violates their right to privacy, freedom of expression, association, and peaceful assembly.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The surveillance revelations come as Jordan&#8217;s government is cracking down on cybercrime, amending its statutes with a new law in 2023 that, critics say, is <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.accessnow.org\/press-release\/jordans-cybercrimes-law\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">overly vague and ripe for abuse<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Specific articles outlaw speech that promotes or instigates &#8220;immorality,&#8221; demonstrates a &#8220;contempt for religion,&#8221; or &#8220;undermines national unity,&#8221; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.aljazeera.com\/news\/2023\/8\/12\/king-of-jordan-approves-draconian-cybercrime-law\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">according to reports<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The law garnered criticism from the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.ohchr.org\/en\/press-briefing-notes\/2023\/08\/jordan-concerns-over-cybercrime-legislation-and-shrinking-civic-space\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">United Nations&#8217; Office of the High Commissioner for Human Rights<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/timep.org\/2023\/10\/19\/jordans-new-cybercrime-law-passes-despite-freedom-concerns\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">non-governmental organizations in the region<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The individuals are the latest to be targeted by governments with the NSO Group&#8217;s surveillance software. In September, for example, Pegasus spyware was <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/nation-state-actor-used-0-click-exploit-to-drop-pegasus-spyware-on-russian-journalist-s-iphone\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">detected on the phone of an exiled Russian journalist<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, apparently installed with a zero-click exploit (one that requires no action by the user). In December 2022, a group of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/application-security\/newsroom-sues-nso-group-for-pegasus-spyware\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">nearly two dozen journalists in El Salvador<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> sued the NSO Group for its part in surveillance of the reporters.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Governments are using the software to target critics and activists without due process, says Ilia Kolochenko, founder of ImmuniWeb, a penetration testing service provider.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Journalists and lawyers are commonly protected from overly intrusive investigations by the virtue of criminal procedure or another legislation that was not specifically designed to offer robust protection from cyber investigations,&#8221; he says, adding: &#8220;The Middle East traditionally had less privacy related legislation; however, now the situation [is] rapidly changing.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Pegasus Pushes into More Markets\">Pegasus Pushes into More Markets<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In 2016, Citizen Lab and mobile security firm Lookout released an analysis of the Pegasus spyware, which targeted iOS devices. A year later, Lookout teamed with Google to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/mobile-security\/pegasus-for-android-spyware-just-as-lethal-as-ios-version\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">release an analysis of the Android version<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Since then, Israel-based NSO Group has continued to find ways to install its surveillance software on targeted individuals&#8217; devices \u2014 sometimes requiring social engineering and other times with no activity by the users.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the latest case, both types of attacks took place, according to Access Now.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The Pegasus victims we uncovered were targeted with both zero-click and one-click attacks,&#8221; Access Now stated in its report. &#8220;We also observed sophisticated social engineering attacks delivering malicious links to victims via WhatsApp and SMS. In some cases, perpetrators posed as journalists, seeking a media interview or a quote from targeted victims, while embedding malicious links to Pegasus spyware amid and in between their messages.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In January 2022, Access Now and Front Line Defenders first discovered Pegasus being used to hack Jordanian citizens, and by April 2022, the groups had detected at least five lawyers and journalists.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The NSO Group did not confirm nor deny Access Now&#8217;s findings.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Due to regulatory and contractual constrains, NSO Group cannot confirm or deny who its governmental customers are,&#8221; a company spokesperson states. &#8220;The company only sells to vetted and licensed law enforcement and intelligence agencies for the purpose of investigating and preventing serious crime and terror.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Policy Needed, But Technology Can Help\">Policy Needed, But Technology Can Help<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The NSO Group spokesperson points to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.nsogroup.com\/Newses\/nso-groups-second-transparency-and-responsibility-report\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">its 2023 Transparency and Responsibility Report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to highlight its criteria in allowing sales of software to the governments of specific nations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We help government intelligence and law enforcement agencies lawfully address their most pressing national security and public safety issues,&#8221; the report stated, pointing to the terrorist attacks on Israel by Hamas as an example of the type of incident the company is trying to prevent. &#8220;Cyber intelligence technology is a critical tool for preventing and investigating terrorism and serious crimes, and for thereby protecting individuals&#8217; fundamental rights to life, liberty, and security.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For the most part, better policy is needed to rein in the use of spyware and exploits against individual users. The targeting of journalists, lawyers, and activists for exercising free speech shows that additional protections need to be put in place, says ImmuniWeb&#8217;s Kolochenko.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It&#8217;s a cat-and-mouse game \u2014 privacy technologies will continually improve but cybersecurity experts or hackers will continually bypass them,&#8221; he says. &#8220;I would rather implement protection on the legislative layer, ensuring a transparent and efficient supervision of cyber operations by law enforcement agencies that would both protect confidential information about investigations and ensure due process.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While the NSO Group has found ways \u2014 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/pegasus-spyware-togolese-journalists-mobile-devices\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">and bought exploits on secondary markets<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 to get around smartphone and computer defenses, keeping devices up-to-date and remaining vigilant of links and attachments can make the devices much harder to compromise, he says.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/pegasus-spyware-targets-jordanian-civil-society\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Journalists, lawyers, and human-rights activists in the Middle Eastern nation<\/p>\n","protected":false},"author":12,"featured_media":2481,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2480","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?fit=1200%2C800&ssl=1",1200,800,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?fit=1200%2C800&ssl=1",1200,800,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?fit=1200%2C800&ssl=1",1200,800,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/pegasus-spyware-targets-jordanian-civil-society-in-wide-ranging-attacks.jpg?fit=1200%2C800&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2480"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2480\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2481"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}