John Scott-Railton Profile picture
Oct 2, 2022 10 tweets 10 min read Read on X
BREAKING: journalists & human rights defenders hacked with #Pegasus in 🇲🇽#Mexico.

Years *after* spyware scandals & new President's promise that abuses were over.

THREAD 1/

Report by @R3Dmx ejercitoespia.r3d.mx
We @citizenlab did forensic validation: citizenlab.ca/2022/10/new-pe… Key Takeaways Mexican digital rights organization R3D (Red eOur technical validation of forensic artifacts collected fro
2/ Per @R3Dmx, #Pegasus victims were infected while working on:

❌Connections between Los Zetas Cartel & Mexican Army
❌Official misconduct in investigations into #Ayotzinapa forced disappearances
❌Human rights violations by Mexican Armed Forces.

Chilling. Ricardo Raphael  Raphael, a prominent journalist and author Raymundo Ramos Vázquez  Ramos has spent years documenting h
3/ Mexico was first rocked by #Pegasus scandals in 2017 under President @EPN.

We @citizenlab, @R3Dmx @socialtic & @article19org had found dozens of abuse cases.

When Pres. @lopezobrador_ took office, he promised hacking abuses were a thing of the past...
4 Mexico's #Pegasus scandals didn't stop.

The #PegasusProject also revealed that scores in the circle of @lopezobrador_ had been potentially selected for targeting while @EPN was in office.

Including now-President AMLO's wife & children. In 2017, the Citizen Lab, along with partners R3D, SocialTic
5/ Mexico has been one of the *most* notorious cases of #Pegasus spyware abuses.

NSO Group has has been confronted about this. For years.

Mexico's new president, touched himself by spyware abuses prior to entering office... had promised it was over.

Yet here we are.
6/ Yet again, journalists & human rights defenders of intense interest to the Mexican government got hacked.

Chillingly, some of their work was clearly of intense interest to cartels, too.

#Mexico has seen *half a decade* of abuses like this. Need for an Independent Investigation These latest cases, wh
7/ I urge you to read @R3Dmx's full report. Here's their thread on the cases.
8/ Another key find via @R3Dmx: Mexico did recent business with companies linked to prior #Pegasus contracts👇👇

Despite making strenuous efforts to deny any such business.
9/ A key detail: while previous Pegasus cases @citizenlab investigated in #Mexico involved finding SMS messages and 1-click attacks... these latest cases were zero-click attacks.

No action was required on the part of the victims to be infected.
10/ Of course NSO has a response that is not serious.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Scott-Railton

John Scott-Railton Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @jsrailton

Oct 31
WILD: actual photo of Musk-hired door knockers being driven around #Michigan.

This group of mostly-black workers were driven in the back of a truck with no seats.

They say they were flown in, given unrealistic goals, and threatened with their lodging being cut off & being forced to pay their own way home if they couldn't meet them.

Some didn't even know which candidate they were working for.

Article by @JakeLahut
wired.com/story/elon-mus…Image
Working to help the richest man in the world get his preferred candidate into office, folks. Image
You really have to read the whole article by @JakeLahut Image
Read 4 tweets
Oct 26
I'm excited for the #HarrisWalz plan to massively expand medicare to cover in-home care.

Beautiful. So many families are are helping loved ones get through hurdles with dignity & independence. At home.

Oh wait, you hadn't heard about this?

A study shows major broadcast networks mostly ignored the policy announcement on the day she made it.
apnews.com/article/harris…Image
Image
Home health care is ruinously expensive.

But as everyone knows, it's often better for seniors to get help in their homes.

A study found that this new #HarrisWalz #medicare benefit is likely to help more than 14 million beneficiaries.

Chart: kff.org/medicare/issue…Image
Image
The #HarrisWalz in-home care medicare benefit for seniors is a big deal.

Yet major broadcast networks gave it only seconds of coverage .

mediamatters.org/broadcast-netw…Image
Read 5 tweets
Oct 21
You've probably heard about Musk's petition.

It's run on the same website that ran bait-and-switch voter registration back in August.

They had to shut it down.

The goal then: probably soak up detailed voter data.

Remember, lots of shady micro-targeting is going on right now from Musk-backed PACs.

And now? Data collection is again a key priority.

I don't know why this isn't front and center in news stories about this.Image
Image
2/ Coverage of Musk's actions often treats them in isolation.

The petition for example is largely covered as "is this legal?"

Good question, but if you don't focus on the systemic effort to gather data & influence voters using that data, you miss the plot.
3/ Do election influence teams /PACs backed by Musk have any special access to @X data?

His escalating offers of $$ show how important he thinks voter data is.

Well, X is a goldmine of political data.

Temptation must be there.

When will election coverage ask the question?Image
Read 7 tweets
Oct 18
BREAKING: Musk-backed PAC is micro-targeting muslim areas with ads saying Harris stands with Israel... and targeting jewish areas saying the opposite.

Writing is on the wall: Musk willing to further divide America if he thinks it will help his candidate win.

By @jason_koebler
404media.co/this-is-exactl…Image
Review the @google ads data yourself.

A "PRO-ISRAEL TEAM WE CAN TRUST" designed to look like a #HarrisWalz campaign ad is micro-targeted to areas with a high muslim population around Dearborn, Michigan.

Meanwhile, same Musk-backed PAC has a "WHY PANDER TO PALESTINE?" ad micro-targeted to areas in Pennsylvania.

The ads are getting millions of impressions.

adstransparency.google.com/advertiser/AR0…Image
Image
Image
Image
Voters around Dearborn, #Michigan are shown an ad saying that Harris "STOOD UP TO PROTESTERS" and "FOUGHT RISING ANTISEMITISM"

Meanwhile, specific areas in #Pennsylvania get an ad with the line "WHY SYMPATHIZE WITH ANTISEMITIC PROTESTERS"

The Musk-backed PAC's ads are here: adstransparency.google.com/advertiser/AR0…Image
Image
Image
Image
Read 7 tweets
Oct 16
NEW: sprawling AI bot army found attacking #HarrisWalz & dems, supporting Trump and GOP.

Researchers at @ClemsonUniv spotted & mapped the network.

It wasn't hard for them to conclude that an LLM was being used: they found tweets that leaked the prompts.

Which also helps makes the partisan objectives of the campaign crystal clear...

READ: open.clemson.edu/cgi/viewconten…Image
Image
Image
Image
2/ Beyond targeting the national election, specific Senate & House races were also a focus of efforts. As were specific figures like @SenatorBaldwin, who was apparently a perennial target. Image
Image
Image
3/ @DarrenLinvill is absolutely right here.

This campaign exposed by the @ClemsonHub team still gives off early-day vibes.

It is only going to get more sophisticated from here.

He was speaking to @kevincollier for this solid piece on the research: nbcnews.com/tech/internet/…Image
Read 6 tweets
Oct 5
CATASTROPHIC: Chinese hackers massively wiretapped 🇺🇸USA by compromising the interception portals mandated under US law.

Remember this the next time a government demands encryption backdoors.

By: @bysarahkrouse @dnvolz @aviswanatha @bobmcmillan h/t @RonDeibert

READ: wsj.com/tech/cybersecu…Image
Image
Image
Image
Manufacturers of networking and phone gear must follow specific standards for 'lawful interception' in different jurisdictions (e.g. CALEA & ETSI's standards)

But as we learn time & time again, the scope of potential access & harm almost never matched by efforts to detect & block malicious use.Image
There's constant pressure from governments to bake-in systems for access.

Failure to comply with those demands is met with big sanctions. Just look at Durov.

Yet I predict that there will be zero meaningful accountability over this breach.

Read 10 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(