John Scott-Railton Profile picture
Jul 18, 2021 37 tweets 44 min read Read on X
BREAKING: massive, global leak of the targets of NSO Group's Pegasus spyware. *huge deal.*

Forensic investigation by @AmnestyTech
in collaboration with @FbdnStories reporters.

We @citizenlab conducted peer review.

Here's an explainer THREAD.
washingtonpost.com/investigations… Image
2. Background: the already-notorious NSO Group makes mercenary spyware to silently & remotely hack iPhones & Androids.

Many of their government customers are authoritarians.

Most cannot resist the temptation to target their critics, reporters, human rights groups etc. Image
3. More about leaked numbers & targets in a sec, but first you need to know:

@AmnestyTech just released a report with technical analysis of NSO's infrastructure... & analysis validating w/forensics that some phones were infected with Pegasus.

amnesty.org/en/latest/rese…
4. We @citizenlab independently peer reviewed @AmnestyTech's forensic methodology, including how they identify an infected phone.

Our review, led by my colleague @billmarczak, judged their forensics & research methodology to be SOUND.

citizenlab.ca/2021/07/amnest… Image
5. Now, to the findings: >50k numbers were leaked that are reportedly part of the infection & targeting workflow with Pegasus.

To help validate the relationship between these numbers & infections @AmnestyTech got consent to forensically examine a subset of the devices. Image
6. The @FbdnStories consortium worked w/the leaked phone numbers... what they found reveals 10 of NSO Group's customers insatiable intent to snoop.

And the massive scale of the operation.

- Mexico customer > 15,000
- Morocco > 10,000
- UAE > 10,00

Etc. Image
7. #SaudiArabia 🇸🇦 murdered & dismembered Jamal Khashoggi.

Jamal's wife was targeted with Pegasus spyware before the killing...

Then his fiancee was hacked multiple times just days after.

@citizenlab independently confirmed findings.

#PegasusProject
washingtonpost.com/investigations… ImageImageImageImage
8. #HUNGARY 🇭🇺

Ask the government for comment... get hacked.

Hungary's far-right PM Viktor Orbán is using Pegasus spyware to surveil & attack Hungary's independent media, like @direkt36, @panyiszabolcs, and many more.

Story: @shaunwalker7 theguardian.com/news/2021/jul/… ImageImageImageImage
9. #INDIA🇮🇳 Over 40 reporters, major opposition figures, serving ministers in the #Modi government, members of the security services and beyond are in the list.

Story to watch as the scandal unfolds there.

Story @svaradarajan @thewire_in
thewire.in/government/pro… Image
10. HUNDREDS of journalists around the globe are on the #PegasusProject list.

NSO Group's role in fueling the authoritarian assault on democratic values (like a free press) is coming into sharp focus

theguardian.com/world/2021/jul… ImageImageImageImage
11. NSO Group puts up a facade of caring about human rights, doing due diligence, etc.

This leak exposes the farce of that performance.

When your customers are dictators... they will do bad things. NSO knows this. We know it.

Now everybody knows it. Image
12. Continuing with cases.... in #FRANCE 🇫🇷

#PegasusProject list includes @edwyplenel, founder of independent news site @Mediapart, a reporter from @lemondefr, etc..

Story lemonde.fr/projet-pegasus… Image
13. in #Mexico 🇲🇽 Journalist Cecilio Pineda Birto was getting death threats for reporting on official collusion with a cartel capo...

...then his number showed up on the #PegasusProject list.

Then he was assassinated.
theguardian.com/news/2021/jul/… ImageImageImageImage
14. Bookmark this thread. Things are only getting started.

I'll be updating it with more cases & context as #PegasusProject revelations keep dropping.
15. REASON TO CARE #1

So, you didn't know today's #PegasusProject hacking victims personally.

But tomorrow? Who knows. You don't.

#NSOGROUP is aggressively pitching *local* cops, including in USA 🇺🇸

Pause. Think about the oversight at your local PD.

vice.com/en/article/889… ImageImageImageImage
16. REASON TO CARE #2:

Since all phones are vulnerable, #Pegasus spyware lets its autocrat-users *export fear*

They want want *you* to be afraid to criticize them.

Yes, you. A continent away. In a democracy.

Think about the implications.
7. REASON TO CARE #3:

Think only human rights defenders & journalists get hacked with #Pegasus?

Wrong.

Good chance officials responsible for the national security of YOUR country have been / will be targeted.

Example pic: 2019 #NSOGroup WhatsApp hack.
reuters.com/article/us-fac… Image
18. Know who else is saying #NSOGroup must be stopped?

Big tech.

These days they are hitting back hard against the mercenary spyware industry for hacking their products & users.

E.g. this thread by @wcathcart @WhatsApp's CEO.👇
19. #INDIA🇮🇳 (2/)

She accused the Chief Justice of India’s Supreme Court of sexual harassment.

Just days later:

Her phone. Her husband's phone. Their family members..

11 in total then showed up on the #PegasusProject list.

thewire.in/rights/ranjan-… ImageImageImage
20. #FRANCE 🇫🇷 Claude Mangin is campaigning for the release of her husband, a political activist, from a #moroccan prison.

She's in France.

Last month her iPhone 11 was silently hacked w/#Pegasus spyware. A second iPhone she borrowed? Also infected.
washingtonpost.com/technology/202… ImageImageImage
21. BREAKING: Americans 🇺🇸 including US. Gov. officials are on the #PegasusProject list...

...even the #Biden administration's lead Iran negotiator Robert Malley!

#NSOGroup is an urgent national security problem for the United States.
washingtonpost.com//national-secu… Image
22. #MEXICO 🇲🇽: At least *50 people* close to the president ... are on the #PegasusProject spyware list.

They were put there while he was campaigning.

-His wife
-Family members, drivers, doctor
-Aides, chief of staff
-Doctor...

#PegasusProject
Story theguardian.com/news/2021/jul/… ImageImage
23. Paul Rusesabagina inspired Hotel #Rwanda 🇷🇼

He's become a critic of the gov., and was recently thrown in jail.

His American 🇺🇸 daughter, while advocating for his release, has been incessantly surveilled w/ #Pegasus.

#PegasusProject
By @skirchy theguardian.com/news/2021/jul/… ImageImageImage
24. Policies to stop the global spyware catastrophe?

Experts @davidakaye & @MarietjeSchaake say:

- Immediate moratorium on sale & transfer
-Rule-of-law requirements on users
-Victims must be able to sue
-Global principles of conduct

#PegasusProject
washingtonpost.com/opinions/2021/… ImageImageImageImage
25. #INDIA 🇮🇳 (3/) Rahul Gandhi was Prime Minister #Modi's main opponent in the 2019 nat'l elections.

During the campaign, 2 of his phones were put on the #PegasusProject list, and 5 of his friends & fellow Congress party officials.

theguardian.com/news/2021/jul/… Image
26. #NSOGroup & #Pegasus spyware customers are issuing panicky, fairy-tale denials.

Here's my take.

#PegasusProject
27. BREAKING: 10 prime ministers, 3 presidents & a king on the #PegasusProject spyware list.

Included, French president @EmmanuelMacron
🇫🇷

Crystal clear: #NSOGroup is a global national security threat.

Story: washingtonpost.com/world/2021/07/… Image
28. #NSOGroup, after courting a lot of press, is suddenly not interested in talking....

So begins the hope-this-dies-down phase of crisis management?
#PegasusProject
29. NEW "there's gotta be some accountability for spies-for-hire"

Senator @RonWyden to Senate Intelligence Committee yesterday in light of #PegasusProject revelations about #NSOGroup spyware.
Full:
30. NEW: 1st legal complaint from #Pegasus victims over latest spyware revelations has landed in France 🇫🇷

Brought by 2 journalists, supported by press freedom org @RSF_inter

Their statement says more complaints inbound.
#PegasusProject
rsf.org/en/news/after-… ImageImageImage
31. NEW: Dalai Lama's inner circle on the #PegasusProject list. (He's not thought to carry a phone)

Happened in period before & after a private meeting with @BarackObama.

#India🇮🇳 suspected as #NSOGroup #spyware client responsible.

Report: theguardian.com/news/2021/jul/… ImageImageImageImage
32. NEW: While #NSOGroup is trying to distract you with a counter narrative...

Here are #Indian 🇮🇳 Police barging into the offices of one of the #PegasusProject media outlets. 👇
35. TODAY: @WhatsApp CEO @wcathcart rubbishes #NSOGroup's denials:

- #PegasusProject reporting consistent w/targeting in #NSOGroup's 2019 attack on WhatsApp users.
- Points out: in *only* 2 weeks 1.4k numbers were confirmed targeted in 2019. Do the math.

theguardian.com/technology/202… ImageImage
36. BIG DEAL: today @WhatsApp CEO @wcathcart *publicly confirmed* that senior national security officials of US allies🇺🇸 were targeted with #Pegasus spyware in 2019.

Clear message: #NSOGroup spyware is a national security threat.

By @skirchy theguardian.com/technology/202… Image
37. Taking #NSOGroup's denials at face value?

CEO: "you won't reach 50,000 #Pegasus targets since the company was founded"

FACT: there were >1,400 *confirmed* targets in just 2 weeks in 2019 per @WhatsApp.

At this rate NSO would have easily reached 50k+
calcalistech.com/ctech/articles… Image
38. Not familiar with the 2019 #NSOGroup attack on @WhatsApp?

#Pegasus spyware was used to target people via WhatsApp in 2019. WhatsApp spotted it, quickly shut it down, notified all targets...and then *sued* NSO.

We @citizenlab helped investigate.
washingtonpost.com/opinions/2019/…
39. "A.Q. Khans of the cyber world"

🇺🇸 US lawmakers just came out swinging against mercenary hacking company #NSOGroup.

Statement: US Gov must impose consequences in light of latest revelations of spyware misuse.

Reps @Malinowski @RepKatiePorter @JoaquinCastrotx @RepAnnaEshoo ImageImageImage

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Scott-Railton

John Scott-Railton Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @jsrailton

Nov 14
Whoa: NSO Group allegedly rolled a @WhatsApp exploit to implant #Pegasus spyware even after WhatsApp sued them.

This previously-unrevealed "Erised" vector was later disabled by #WhatsApp.

These un-redacted filings are quite the read. Even some footnotes have scoops. 1/Image
2/ We learn that NSO Group had at least three @whatsapp exploits: Heaven, Eden & Erised.

The first, called Heaven, was active some time prior to Sept-Dec 2018. It worked by using manipulated messages to direct targeted devices to a malicious WhatsApp relay controlled by NSO Group.

Heaven was ultimately disabled by changes made in Sept & December 2018 by WhatsApp.

storage.courtlistener.com/recap/gov.usco…Image
Image
Image
Image
3/ After the Heaven vector stopped working, NSO Group deployed Eden, which had a key feature: it needed to pass through relays controlled by @WhatsApp.

There's some detail about how the exploit was deployed to avoid detection.

Ultimately, it was detected, leading to the lawsuit.Image
Image
Read 7 tweets
Oct 31
WILD: actual photo of Musk-hired door knockers being driven around #Michigan.

This group of mostly-black workers were driven in the back of a truck with no seats.

They say they were flown in, given unrealistic goals, and threatened with their lodging being cut off & being forced to pay their own way home if they couldn't meet them.

Some didn't even know which candidate they were working for.

Article by @JakeLahut
wired.com/story/elon-mus…Image
Working to help the richest man in the world get his preferred candidate into office, folks. Image
You really have to read the whole article by @JakeLahut Image
Read 4 tweets
Oct 26
I'm excited for the #HarrisWalz plan to massively expand medicare to cover in-home care.

Beautiful. So many families are are helping loved ones get through hurdles with dignity & independence. At home.

Oh wait, you hadn't heard about this?

A study shows major broadcast networks mostly ignored the policy announcement on the day she made it.
apnews.com/article/harris…Image
Image
Home health care is ruinously expensive.

But as everyone knows, it's often better for seniors to get help in their homes.

A study found that this new #HarrisWalz #medicare benefit is likely to help more than 14 million beneficiaries.

Chart: kff.org/medicare/issue…Image
Image
The #HarrisWalz in-home care medicare benefit for seniors is a big deal.

Yet major broadcast networks gave it only seconds of coverage .

mediamatters.org/broadcast-netw…Image
Read 5 tweets
Oct 21
You've probably heard about Musk's petition.

It's run on the same website that ran bait-and-switch voter registration back in August.

They had to shut it down.

The goal then: probably soak up detailed voter data.

Remember, lots of shady micro-targeting is going on right now from Musk-backed PACs.

And now? Data collection is again a key priority.

I don't know why this isn't front and center in news stories about this.Image
Image
2/ Coverage of Musk's actions often treats them in isolation.

The petition for example is largely covered as "is this legal?"

Good question, but if you don't focus on the systemic effort to gather data & influence voters using that data, you miss the plot.
3/ Do election influence teams /PACs backed by Musk have any special access to @X data?

His escalating offers of $$ show how important he thinks voter data is.

Well, X is a goldmine of political data.

Temptation must be there.

When will election coverage ask the question?Image
Read 7 tweets
Oct 18
BREAKING: Musk-backed PAC is micro-targeting muslim areas with ads saying Harris stands with Israel... and targeting jewish areas saying the opposite.

Writing is on the wall: Musk willing to further divide America if he thinks it will help his candidate win.

By @jason_koebler
404media.co/this-is-exactl…Image
Review the @google ads data yourself.

A "PRO-ISRAEL TEAM WE CAN TRUST" designed to look like a #HarrisWalz campaign ad is micro-targeted to areas with a high muslim population around Dearborn, Michigan.

Meanwhile, same Musk-backed PAC has a "WHY PANDER TO PALESTINE?" ad micro-targeted to areas in Pennsylvania.

The ads are getting millions of impressions.

adstransparency.google.com/advertiser/AR0…Image
Image
Image
Image
Voters around Dearborn, #Michigan are shown an ad saying that Harris "STOOD UP TO PROTESTERS" and "FOUGHT RISING ANTISEMITISM"

Meanwhile, specific areas in #Pennsylvania get an ad with the line "WHY SYMPATHIZE WITH ANTISEMITIC PROTESTERS"

The Musk-backed PAC's ads are here: adstransparency.google.com/advertiser/AR0…Image
Image
Image
Image
Read 7 tweets
Oct 17
WARNING: fake pro-#HarrisWalz advertising campaign...

Is actually run by dark money network connected to Elon Musk.

The "Progress 2028" ads & text message campaigns feature lies about Harris policies about guns, immigrants & LGBTQ issues...

The goal is clearly to mislead voters.

Dirty politics that must be investigated.

By @annalecta
opensecrets.org/news/2024/10/p…Image
Image
Image
Image
This false-flag #HarrisWalz campaign is hammering #Georgia with ad buys on @meta.

$66,140k in spend in the past week alone, shown to a custom audience. I wonder who it is?

Please reply if you've seen advertisements for "Progress 2028" or gotten text messages promoting this fake campaign.

facebook.com/ads/library/?a…Image
Image
They say dark money destroys democracy.

Here's a case study:

A false-flag advertising campaign weeks before the election, custom-targeting swing state voters, trying to mislead them about a candidate...

And no legal requirement to say whose money is behind it. Ever.Image
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(