John Scott-Railton Profile picture
Apr 18 16 tweets 15 min read
🚨MAJOR NEW INVESTIGATION: #CatalanGate state-run hacking operation.

Stunning range of #Pegasus & #Candiru infections in the EU.

Many political & civil society targets got infected. Multiple 🇪🇺 MEPs.

THREAD 1/
catalonia.citizenlab.ca
2/ A jaw dropping list of people were targeted in #CatalanGate

Let's take the 🇪🇺 European Parliament.

*Every pro-independence MEP* was targeted directly or w/relational targeting:

-@toni_comin
-@DianaRibaGiner
-@jordisolef
-@ClaraPonsati
-@KRLS
3/ Catalan civil society was extensively targeted.

From the leadership of major civic organizations like @omnium & @assemblea_int...to open source developers working on digital voting.

Mostly #Pegasus, but #Candiru spyware, too.

Link: citizenlab.ca/2022/04/catala…
4/ So many Catalan politicians were targeted with #Pegasus between 2017-2020.

Like every current/former President of Catalonia since 2010.

Catalan's Parliamentary leadership, legislators, etc. etc. #CatalanGate
5/The #Pegasus hacking was via a mix of zero-click vulnerabilities & SMS infection attempts.

Texts were *very* well informed.

Like this one: @jbaylina was sent a mobile boarding pass link...for a @FlySWISS flight he'd booked.
6/ WILD: while doing #Pegasus forensics, at the 11th hour on this project, @billmarczak actually discovered another NSO iOS Zero-Click 0day!

We call it #Homage

We think it stopped working by 13.2 so if you are updated, you're likely OK.

We notified @apple.
7/ The #Candiru targeting that we saw was via email. Again, often super personalized.

They impersonated official COVID communications from Spanish gov, notifications from biz registries, etc.

Sometimes Candiru & #Pegasus targeting themes overlapped.
8/ Craziest story? Victim working on a live #Candiru infected computer had to be persuaded to step into the hallway using a ruse so we could explain the situation away from it's microphones...

Material was shared w/@MsftSecIntel which led to 1.4 billion devices getting patched.
9/ The folks at @AmnestyTech conducted an independent validation of our forensic methods on a selection of cases.
10/ Which government is behind #CatalanGate? Well, we aren't conclusively attributing to a specific government...

But substantial circumstantial evidence suggests a nexus with the Government of Spain.
11/ Big picture: people think the problem with mercenary spyware is that it gets sold to dictators. Who abuse it. True.

Turns out that when democracies acquire it, risk of abuse is dangerously high.

It's abundantly clear that this is now a major problem in the #EU.
12/ EU MEPs have begun weighing in👇

🇪🇺 EU Parliament's new committee on Pegasus spyware has first meeting tomorrow.

Sure to be interesting.
13/ Investigations like this are group effort, huge credit to my coauthors @elies @billmarczak @insyria @sienaanstis @gozdebocu @SalSolimano & @RonDeibert

With help from Miles Kenyon @rizhouto @adamsenft
& so many others.
citizenlab.ca/2022/04/catala…
14/ Cases like this cannot come to light without the many victims & organizations that graciously consent to participating in our research, and chose to come forward & be named.

Without them, this report would not have been possible.
15/ Special acknowledgement to the team @domesticstream who helped us do the amazing graphical companion to our report.

They do great work, give them a follow!

catalonia.citizenlab.ca
16/ 16/ Nice thread by David Kaye, former UN Special Rapporteur, talking about *solutions* to the mercenary spyware problem.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Scott-Railton

John Scott-Railton Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @jsrailton

Apr 18
BREAKING: we @citizenlab found signs of a #Pegasus spyware infection at the 🇬🇧Prime Minister's office, 10 Downing St.

We notified 🇬🇧.

We'd found other infections within the Gov.. THREAD 1/

Must-read by @RonanFarrow: newyorker.com/magazine/2022/…
2/ Meanwhile, we also found signs that multiple 🇬🇧 officials at the @FCDOGovUK had been infected with #Pegasus spyware.
3/ Many assumed that 🇬🇧's vaunted security apparatus could protect the government from the scourge of mercenary spyware like #Pegasus.

Wrong.

🇬🇧 got spectacularly burned.

So, which foreign governments might have hacked @10DowningStreet & @FCDOGovUK?
Read 5 tweets
Apr 5
Selection goes into what gets filmed & posted from #Ukraine. Somebody is always making choices.

This selection effect that biases what we see. But that's only the beginning. 1/
2/ Social media shows us more of what we like.

If we & people we follow prefer seeing destroyed Russian tanks & Ukrainian successes, we'll be shown more of them.

Like it or not, the algorithm designed to *not* give us a balanced, representative sample of material.
3/ The OSINT ecosystem is an inspiring force for truth & accountability.

But it doesn’t mean that we come away from our feeds with a balanced, realistic assessment of the direction of the whole war.

Analysis & analytical biases are hard.
Read 4 tweets
Apr 4
BREAKING: bodies in Bucha were visible in satellite imagery for weeks.

Directly rebuts Russia's claim that bodies only appeared after they left.

By @malachybrowne @bottidavid @heytherehaley
nytimes.com/2022/04/04/wor…
2/ Gaps in information during war are fertile soil for Russian dezinformatsia.

Part of what's so powerful about visual investigations & OSINT is that they accelerate truth & reduce the space Kremlin propagandists have to work with.
3/ Many OSINT techniques have genesis in past wars & crises. Some groups & visual investigations teams, too.

Yet there's a ton of exciting progress & maturing going on right now.

One key driver? Rapid hires satellite imagery like
@maxar's daily releases.
Read 6 tweets
Apr 3
If you haven't noticed, these autocrats run a mutual aid society.

Orban's win helps Putin.

And of course, success for for Putin helps Assad, Kadyrov, and Lukashenko, etc. etc. 1/
2/ The great autocratic cousinate needs a global ecosystem of enablers.

From private banks & libel lawyers, to spyware & surveillance firms, political consultants, lobbyists, investors, former lawmakers, media people..

This ecosystem took a blow when sanctions hit...
3/...But Orban, untouched by the sting of sanctions, continues to pump money into the vast influence industry.

Great overview of what that looks like in the US
by @kenvogel & @b_novak nytimes.com/2021/10/04/us/…
Read 5 tweets
Apr 3
NEW: Putin ally, autocrat Viktor Orban just declared victory in #hungaryelections.

The news is surely being welcomed in Moscow.

Dark times for Hungary & Europe.

By @robpicheta & @balintbardi
cnn.com/2022/04/03/eur…
2/ Orban's victory speech had a list of"opponents."

Including Zelensky.

Awful.
3/ #Orban pulled out all the stops to win.

Gerrymandering, legalizing a type of voter fraud...

Even using Hungary's COVID response to push propaganda & lies about his opponents.

By Matt Apuzzo & @b_novak
nytimes.com/2022/03/31/wor…
Read 4 tweets
Apr 2
Incredibly disturbing footage is surfacing showing bound bodies left behind by Russian forces.

Clearly, it's time for the UN & other international bodies to send in evidence teams to work these sites.
You should not be surprised.

#Putin signaled his plans to the world.

Now, ask yourself what atrocities are as yet unknown.. evidence still hidden behind Russian lines.
How many more mass graves will Putin visit upon #Ukraine before he stops this evil misadventure?
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(