Whoa: NSO Group allegedly rolled a @WhatsApp exploit to implant #Pegasus spyware even after WhatsApp sued them.
This previously-unrevealed “Erised” vector was later disabled by #WhatsApp.
These un-redacted filings are quite the read. Even some footnotes have scoops. 1/ pic.twitter.com/1vkdu7P0EX
— John Scott-Railton (@jsrailton) November 14, 2024
3/ After the Heaven vector stopped working, NSO Group deployed Eden, which had a key feature: it needed to pass through relays controlled by @WhatsApp.
There’s some detail about how the exploit was deployed to avoid detection.
Ultimately, it was detected, leading to the… pic.twitter.com/Ey1UGYUXUC
— John Scott-Railton (@jsrailton) November 14, 2024
5/ Super interesting: discussion by @WhatsApp suggesting just how much of the work of hacking was allegedly done by NSO Group’s systems.
Not the spyware customers.
While this matches what many of us have believed, seeing it laid out like this is new.https://t.co/GpYlKyMXtj pic.twitter.com/wxCtONBSLS
— John Scott-Railton (@jsrailton) November 14, 2024
7/ And here’s the promised footnote stating that NSO Group’s CEO admitted in a deposition that #Pegasus spyware was used to target Dubai’s Princess Haya.
Apparently confirming a finding made by a UK high court judge 3 years ago that Dubai’s Ruler hacked the princess, his… pic.twitter.com/n0BduL8nxD
— John Scott-Railton (@jsrailton) November 14, 2024
People who thought the customers were doing the hacking themselves do not understand the way these things work at all.
The Israelis are not just going to pass around their 1337 haxx0rs, and people wouldn’t know how to use them anyway.
Obviously, the actual processing of the exploit is done on the side of the Israelis.
Legal documents released in ongoing US litigation between NSO Group and WhatsApp have revealed for the first time that the Israeli cyberweapons maker – and not its government customers – is the party that “installs and extracts” information from mobile phones targeted by the company’s hacking software.
The new details were contained in sworn depositions from NSO Group employees, portions of which were published for the first time on Thursday.
It comes five years after WhatsApp, the popular messaging app owned by Facebook, first announced it was filing suit against NSO. The company, which was blacklisted by the Biden administration in 2021, makes what is widely considered the world’s most sophisticated hacking software, which – according to researchers – has been used in the past in Saudi Arabia, Dubai, India, Mexico, Morocco and Rwanda.
…
WhatsApp filed suit in California in 2019 after it revealed that it had discovered that 1,400 of its users – including journalists and human rights activists – had been targeted by the spyware over a two-week period.
At the heart of the legal fight was an allegation by WhatsApp that NSO had long denied: that it was the Israeli company itself, and not its government clients around the world, who were operating the spyware. NSO has always said that its product is meant to be used to prevent serious crime and terrorism, and that clients are obligated not to abuse the spyware. It has also insisted that it does not know who its clients are targeting.
WhatsApp is seeking a summary judgment in the case, which means it is asking a judge to rule on the case now. NSO has opposed the motion.
The Israelis are not geniuses for being really heavy into hacking. It’s just that this stuff would be illegal in any other country.
Russians are peak autism, really good at this sort of thing, but it’s illegal in Russia. They allow a certain amount of cybercrime, obviously, but they wouldn’t allow a company to just set up shop selling backdoors. Everyone would be angry. The Jews are the only group of people who can get away with this, and that works well for the Americans.
It should be made clear here that NSO and Pegasus were tools of Israeli foreign policy. This is important.https://t.co/AWNW4GYUvb pic.twitter.com/cBF2jtCwq6
— Nadine Chahine 🇱🇧 (@arabictype) November 14, 2024
Elvis Dunderhoff contributed to this article.