Startec

Startec

Researchers say they found spyware used in war for the first time

Mai 25, às 10:00

·

5 min de leitura

·

0 leituras

Security researchers and digital rights organizations believe the government of Azerbaijan used spyware produced by NSO Group to target a government worker, journalists, activists and the human rights...
Researchers say they found spyware used in war for the first time

Security researchers and digital rights organizations believe the government of Azerbaijan used spyware produced by NSO Group to target a government worker, journalists, activists and the human rights ombudsperson in Armenia as part of a years long conflict that has at times broken out into an all-out war.

The cyberattacks may be the first public cases where commercial spyware was used in the context of a war, according to Access Now, a digital rights group that investigated some of the cases. The hacks happened between November 2021 and December 2022. The skirmish between Armenia and Azerbaijan — known as the Nagorno-Karabakh conflict — has been going on for years, and it flared up again in May 2021, when Azerbaijani soldiers crossed into Armenia and occupied parts of its territory.

“While a number of infected individuals are also members of the Armenian opposition or are otherwise critical of the current government, the infections took place at critical times in the Nagorno Karabakh conflict and a deep political crisis caused by the conflict, which resulted in a significant uncertainty over the future of the country’s leadership and its position on Karabakh,” Natalia Krapiva, the tech legal counsel at Access Now, told TechCrunch. “Some of the victims worked closely in or with [Armenia’s] Nikol Pashinyan’s administration and were directly involved in the negotiations or investigation of human rights abuses committed by Azerbaijan in the conflict.”

The Azerbaijani embassy in Washington, D.C. did not respond to a request for comment.

NSO Group did not respond to a request for comment.

Access Now was aided by Citizen Lab, another digital rights organization specialized in investigating spyware; Amnesty International; CyberHUB-AM, an Armenian cybersecurity organization that helps civil society; and local cybersecurity researchers.

According to Access Now, the victims include Kristinne Grigoryan, the top human rights defender in Armenia; Karlen Aslanyan and Astghik Bedevyan, two Radio Free Europe/Radio Liberty’s (RFE/RL) Armenian Service journalists; two unnamed United Nations officials; Anna Naghdalyan, a former spokesperson of Armenia’s Foreign Ministry (now an NGO worker); as well as activists, media owners and academics.

Samvel Farmanyan, the former co-founder and host of an opposition television in Armenia, told TechCrunch that the hack he suffered “is a form of terror.”

“It is not only a clear violation of human rights, my rights of privacy and private communication, but it had [an] enormous psychological effect,” he said in an online chat. “It is difficult what you feel when you are sure that you are illegally under surveillance with no knowledge which government may stand behind and what the real purposes are behind that illegal intervention.”

Farmanyan, as well as other victims, realized they were victims of a hack when Apple sent them a notification that they may have been targeted with government spyware, as the company did with several other victims in other countries. They then reached out to Access Now, Citizen Lab or Amnesty International to get their phones checked.

In the case of Armenia’s top human rights defender Grigoryan, Access Now said that her phone “was infected not long after she shared her phone number with her Azerbaijani counterpart.”

Over the last few years, there have been countless cases of abuse of NSO spying tools in Mexico, Saudi Arabia, Bahrain and many other countries, but Access Now considers this a special case.

“Providing Pegasus spyware to either of the sides in the context of a violent conflict carries a substantial risk of potentially contributing to and facilitating serious human rights violations and even war crimes,” the organization wrote in its press release.

There isn’t conclusive evidence that the Azerbaijan government is behind these attacks, but a coalition of media organizations known as the Pegasus Project showed that the country is one of NSO’s customers. Yet, Ruben Muradyan, a mobile security researcher who analyzed the phones of five victims in Armenia, said that some of them believe the government of Armenia could be behind the hacks, since they were being critical of the local government at the time.

The Armenian embassy in Washington, D.C. did not respond to a request for comment.

In any case, it’s unclear whether using spyware such as Pegasus in the context of an armed conflict constitutes a violation of international law, according to Anna Pagnacco, a cybersecurity policy researcher at Oxford Information Labs.

“International law is silent on the topic of peacetime espionage, which is broadly criminalized at the national level; yet all states still conduct espionage. Intelligence activities carried out by members of a belligerent party’s armed forces in uniform during international armed conflict are legitimate — i.e. spying is not a war crime,” Pagnacco told TechCrunch.


Do you have more information about NSO Group? Or another surveillance tech provider? We’d love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Wickr, Telegram and Wire @lorenzofb, or email [email protected]. You can also contact TechCrunch via SecureDrop.


Continue lendo

Showmetech

Lançamentos do Amazon Prime Gaming em junho de 2023: SteamWorld Dig 2 e mais!
Índice Todos os lançamentos do Amazon Prime Gaming em junho de 2023Jogos gratuitos do Prime Gaming de junho de 2023Mutation NationSengoku 2Over TopSoccer BrawlSteamWorld Dig 2The Super SpyTop...

Hoje, às 18:34

Showmetech

Implante cerebral da Neuralink já pode ser testado em humanos
Índice O histórico da tentativa da empresa de Musk de testar implante cerebralComo a Neuralink pesquisa a interação entre cérebro e máquina?O que as pesquisas em cérebros humanos na Europa conseguiram?Como...

Hoje, às 18:33

Showmetech

Kingston lança pendrive com senha para maior segurança
Índice Linha IronKey para dados sensíveis Pendrive Locker +50 Vault Privacy 50 Ironkey Privacy 200Kingston ajuda usuários em nova compra A Kingston Brasil convidou jornalistas e influencers a comparecem ao...

Hoje, às 16:56

AI | Techcrunch

Skyflow expands its regional footprint as it adds generative AI support to its data privacy tooling
Skyflow, a data-privacy startup, announced Friday that it has expanded the number of markets where it offers data residency support for companies that need to keep certain information inside defined borders....

Hoje, às 16:00

TabNews

Etapas para construri uma tela no Flutter · carlosbatista
Resumo Construir telas pode ser muito simples e fácil, porém pode se tornar um grande desafio quando a tela a ser construida é recheada de elementos. Devemos tomar cuidado com o código, c...

Hoje, às 15:55

DEV

Unleash the Power of JavaScript: Master the Best Practices and Write Top-Notch Code
1- Use const and let instead of var Const declares a variable whose value cannot be changed. Let has block scope instead of function scope like var. Using const and let improves readability and avoid...

Hoje, às 15:36

AI | Techcrunch

Sam Altman shares his optimistic view of our AI future
OpenAI’s CEO Sam Altman has been touring Europe for the past few days, meeting head of governments and startup communities to talk about AI regulation, ChatGPT and beyond. In his latest on-stage appearance at...

Hoje, às 15:36

Hacker News

NASA safety panel skeptical of Starliner readiness for crewed flight
Boeing's CST-100 Starliner being prepared for a crew flight test scheduled for no earlier than July 21. Credit: Boeing/John Grant WASHINGTON — The chair of a NASA safety panel urged the agency not to...

Hoje, às 15:34

Hacker News

How the Lemon was Invented
How the Lemon was Invented How do you make a lemon? Silly question, isn’t it? You just take the seeds out of one and plant them, and wait for the tree to come up, right? That’s true, but it hasn’t...

Hoje, às 14:17

Hacker News

How the Lemon was Invented
How the Lemon was Invented How do you make a lemon? Silly question, isn’t it? You just take the seeds out of one and plant them, and wait for the tree to come up, right? That’s true, but it hasn’t...

Hoje, às 14:17