European officials reportedly targeted by NSO spyware
(2022/04/12)
- Reference: 1649715759
- News link: https://www.theregister.co.uk/2022/04/11/nso_spyware_eu/
- Source link:
Someone at least tried to use NSO Group's surveillance software to spy on European Commission officials last year, according to a Reuters report.
European Justice Commissioner Didier Reynders and at least four commission staffers were [1]targeted , according to the news outlet, citing two EU officials and documentation.
The European Commission did not immediately respond to The Register 's request for comment.
[2]
NSO is the Israeli cyber-surveillance firm that developed the infamous Pegasus software that, once in an infected phone or other device, can extract data and carry out other espionage. It can be installed on a victim's gadget without any user interaction: typically, they have to just receive a booby-trapped message. And once it's deployed, the NSO customer controlling that instance of Pegasus has access to everything on the victim's handheld, including text messages, phone calls, emails, passwords, and photos.
[3]Whistleblower claims NSO offered 'bags of cash' for access to US phone networks
[4]NSO fails once again to claim foreign sovereign immunity in WhatsApp spying lawsuit
[5]Uncle Sam to clip wings of Pegasus-like spyware – sorry, 'intrusion software' – with proposed export controls
[6]Who honestly has a crown prince in their threat model? UN report officially fingers Saudi royal as Bezos hacker
In November Apple sent [7]security alerts to iPhone owners whose devices may have been compromised by Pegasus. Reuters said the European Commission "became aware of the targeting" of its people following Apple raising that alarm. The news agency also said it reviewed an email originating from a "senior tech staffer" who warned Euro officials: "Given the nature of your responsibilities, you are a potential target."
Reuters said it couldn't determine who planted the spyware, what they were looking for, or if the attempts were successful. It's unclear to us if the European officials were actually targeted or simply on alert after Apple issued its warning about Pegasus. Reuters is adamant Reynders and at least four other commission staffers were menaced by the spyware, according to its sources.
[8]
[9]
NSO didn't respond to The Register 's inquiries. But it sent a statement to Reuters saying that it wasn't responsible, and that targeting EU commissioners and staffers "could not have happened with NSO's tools."
Also last November [10]Apple sued NSO Group for targeting Apple users with an exploit called ForcedEntry. It abused a now-patched vulnerability to hijack Apple devices and install Pegasus. According to Apple, the spyware was used to monitor "a small number of Apple users worldwide."
[11]
Shortly after that, the US government [12]block-listed NSO for providing spyware to foreign governments that "used these tools to maliciously target" government officials, journalists, businesses, embassy workers, activists, and academics.
Despite Uncle Sam's crackdown, the FBI admitted to [13]testing Pegasus for potential use in criminal investigations.
Facebook parent company Meta has also [14]sued NSO , alleging that the spyware illegally targeted WhatsApp users.
[15]
Meanwhile, as lawsuits and political pressure mount against the NSO in the US, the European Parliament is moving ahead with its own [16]probe into the use of Pegasus surveillance software.
EU lawmaker Sophie in 't Veld, who lobbied for the committee investigation, told Reuters that she wasn't aware that the spyware had targeted Reynders and other commission officials.
"We really have to get to the bottom of this," she said. ®
Get our [17]Tech Resources
[1] https://www.reuters.com/technology/exclusive-senior-eu-officials-were-targeted-with-israeli-spyware-sources-2022-04-11/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2022/02/02/whistleblower_nso_group/
[4] https://www.theregister.com/2021/11/09/nso_foreign_immunity_whatsapp_decision/
[5] https://www.theregister.com/2021/10/20/us_intrusion_software_rules/
[6] https://www.theregister.com/2020/01/22/saudi_bezos_phone_hack/
[7] https://support.apple.com/en-us/HT212960
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2021/11/23/apple_nso_group/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://www.commerce.gov/news/press-releases/2021/11/commerce-adds-nso-group-and-other-foreign-companies-entity-list
[13] https://thehill.com/policy/national-security/592520-fbi-says-pegasus-spyware-was-tested-not-used-in-any-investigation/
[14] https://www.theregister.com/2021/11/09/nso_foreign_immunity_whatsapp_decision/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://www.europarl.europa.eu/doceo/document/TA-9-2022-0071_EN.html
[17] https://whitepapers.theregister.com/
European Justice Commissioner Didier Reynders and at least four commission staffers were [1]targeted , according to the news outlet, citing two EU officials and documentation.
The European Commission did not immediately respond to The Register 's request for comment.
[2]
NSO is the Israeli cyber-surveillance firm that developed the infamous Pegasus software that, once in an infected phone or other device, can extract data and carry out other espionage. It can be installed on a victim's gadget without any user interaction: typically, they have to just receive a booby-trapped message. And once it's deployed, the NSO customer controlling that instance of Pegasus has access to everything on the victim's handheld, including text messages, phone calls, emails, passwords, and photos.
[3]Whistleblower claims NSO offered 'bags of cash' for access to US phone networks
[4]NSO fails once again to claim foreign sovereign immunity in WhatsApp spying lawsuit
[5]Uncle Sam to clip wings of Pegasus-like spyware – sorry, 'intrusion software' – with proposed export controls
[6]Who honestly has a crown prince in their threat model? UN report officially fingers Saudi royal as Bezos hacker
In November Apple sent [7]security alerts to iPhone owners whose devices may have been compromised by Pegasus. Reuters said the European Commission "became aware of the targeting" of its people following Apple raising that alarm. The news agency also said it reviewed an email originating from a "senior tech staffer" who warned Euro officials: "Given the nature of your responsibilities, you are a potential target."
Reuters said it couldn't determine who planted the spyware, what they were looking for, or if the attempts were successful. It's unclear to us if the European officials were actually targeted or simply on alert after Apple issued its warning about Pegasus. Reuters is adamant Reynders and at least four other commission staffers were menaced by the spyware, according to its sources.
[8]
[9]
NSO didn't respond to The Register 's inquiries. But it sent a statement to Reuters saying that it wasn't responsible, and that targeting EU commissioners and staffers "could not have happened with NSO's tools."
Also last November [10]Apple sued NSO Group for targeting Apple users with an exploit called ForcedEntry. It abused a now-patched vulnerability to hijack Apple devices and install Pegasus. According to Apple, the spyware was used to monitor "a small number of Apple users worldwide."
[11]
Shortly after that, the US government [12]block-listed NSO for providing spyware to foreign governments that "used these tools to maliciously target" government officials, journalists, businesses, embassy workers, activists, and academics.
Despite Uncle Sam's crackdown, the FBI admitted to [13]testing Pegasus for potential use in criminal investigations.
Facebook parent company Meta has also [14]sued NSO , alleging that the spyware illegally targeted WhatsApp users.
[15]
Meanwhile, as lawsuits and political pressure mount against the NSO in the US, the European Parliament is moving ahead with its own [16]probe into the use of Pegasus surveillance software.
EU lawmaker Sophie in 't Veld, who lobbied for the committee investigation, told Reuters that she wasn't aware that the spyware had targeted Reynders and other commission officials.
"We really have to get to the bottom of this," she said. ®
Get our [17]Tech Resources
[1] https://www.reuters.com/technology/exclusive-senior-eu-officials-were-targeted-with-israeli-spyware-sources-2022-04-11/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2022/02/02/whistleblower_nso_group/
[4] https://www.theregister.com/2021/11/09/nso_foreign_immunity_whatsapp_decision/
[5] https://www.theregister.com/2021/10/20/us_intrusion_software_rules/
[6] https://www.theregister.com/2020/01/22/saudi_bezos_phone_hack/
[7] https://support.apple.com/en-us/HT212960
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2021/11/23/apple_nso_group/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://www.commerce.gov/news/press-releases/2021/11/commerce-adds-nso-group-and-other-foreign-companies-entity-list
[13] https://thehill.com/policy/national-security/592520-fbi-says-pegasus-spyware-was-tested-not-used-in-any-investigation/
[14] https://www.theregister.com/2021/11/09/nso_foreign_immunity_whatsapp_decision/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlT5bhO4CGrh1qCnMSrlhQAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://www.europarl.europa.eu/doceo/document/TA-9-2022-0071_EN.html
[17] https://whitepapers.theregister.com/
@First Light - Re: Beware the Beast of Brussels
Anonymous Coward
Well, they deserve being regulated to death. And those Eurocrats should also bring in court the inept developers who though it's cool for my phone to act without any human intervention (the so called zer-click).
Re: Beware the Beast of Brussels
jasonbrown1965
Two downvotes!
Must be some zero-click fans on here.
Or, more probably, anti-bureaucrats.
While I can empathise with libertarian fears and loathing? I'd rather have large bureaucracies with the power to shut down shithole ops like NSO, than the net become a wtfever free-for-all.
At least more than it already it is.
Beware the Beast of Brussels
Their clients picked on the wrong people. Eurocrats are now going to regulate, and fine, the crap out of NSO and its products. The company and its clients will suffocate in red tape.