NYT reporter details being attacked by Pegasus malware

Posted:
in iOS
A journalist who was a victim of hacking by Pegasus spyware has revealed their experience in being a target for hacking, including how suspicious messages and "zero-click" exploits led to access to the journalist's smartphone.




An investigation in July highlighted how the NSO Group's Pegasus spyware was used to attack journalists and human rights activists. The spyware, which was intended by NSO Group to only be used for crime prevention and investigative purposes, was misused by some governments to perform surveillance on potentially thousands of activists and journalists.

In a New York Times report, Middle East correspondent Ben Hubbard explains how he became a target, in part due to often speaking to "people who take great risks to share information that their authoritarian rulers want to keep secret." While Hubbard took precautions to protect sources due to the risk of imprisonment or death, he still became a victim of Pegasus hacking.

In working with Citizen Lab, Hubbard found that he had been targeted with a suspicious text message in 2018, thought to have been sent by Saudi Arabia. The publication's tech security team uncovered another hacking attempt from 2018, with a second message sent via WhatsApp, inviting the journalist to a protest at a Saudi Embassy in Washington, complete with a suspicious link.

Neither attempt succeeded, Citizen Lab confirmed, as Hubbard didn't click the links included in each message, though it wasn't the end of the harassment.

Further investigations of Hubbard's device revealed a pair of hacks in 2020 and 2021 that were successful, using a zero-click exploit that didn't require users to click a link to infect. It seems unlikely that the identity of the hacking party will be uncovered, it was discovered that the second hack took place to remove traces left behind from the first.

Pegasus is believed to be used for all of the attacks. NSO Group denied that its products were used in the attacks, that "technical and contractual reasons and restrictions" meant Hubbard couldn't possibly have been a target in the 2020 and 2021 incidents.

The attacks against Hubbard are among a large number using the spyware, which have been condemned by Apple and other organizations around the world.

It is unclear exactly what smartphone Hubbard was using throughout this period, but Pegasus is famous for attacking iPhones, among other devices, taking advantage of various exploits in iOS to defeat on-device security. In September, Apple's release of patches for iOS 14.8 and iOS 12.5.5 plugged security holes that Pegasus abused to take control of a target's iPhone.

A successful infection of Pegasus allowed n attacker practically unlimited access to the iPhone or other device, including being able to extract data, read encrypted messages, enable cameras and microphones, record phone calls, and to track the device's GPS co-ordinates live.

Governments thought to have been NSO clients include Azerbaijan, Kazakhstan, Rwanda, and the UAE, among others considered to have authoritarian regimes. Other more progressive governments have also become customers, including Germany, as was revealed in September.

Read on AppleInsider

Comments

  • Reply 1 of 7
    Imagine if these devices had built in back doors like someone the government want. 
    rcfaentropyswatto_cobra
  • Reply 2 of 7
    larryjwlarryjw Posts: 1,031member
    Everyone needs to recognize: There are no good guys. 
    rcfaGeorgeBMac
  • Reply 3 of 7
    lkrupplkrupp Posts: 10,557member
    NSO Group denied that its products were used in the attacks, that "technical and contractual reasons and restrictions" meant Hubbard couldn't possibly have been a target in the 2020 and 2021 incidents.”

    Right, and we’re supposed to believe them, just like their claim that they only sell to official government entities. 

    And of course, these attacks only happen to iPhone users. Android users are completely safe from Pegasus attacks because of Android’s superior security. All journalists, human rights and political dissidents activists should chuck their iPhones and buy Pixels to protect themselves from prying eyes.
    edited October 2021 williamlondonGeorgeBMacwatto_cobrajony0
  • Reply 4 of 7
    maestro64maestro64 Posts: 5,043member
    j2fusion said:
    Imagine if these devices had built in back doors like someone the government want. 
    Actual Time and other so called news outlets were also pushing for back doors so the Government could go after the "Bad Guy" of course the bad guy is anyone government or the media does not like at the time. 

    People have no idea how important privacy is and they want to give everyone else's away until the thought and idea police what to know you they are up too. not sure what this writer is complaining about, if he had nothing to hear why does he care what snooping eye want to see what they are doing.
    edited October 2021 entropysviclauyycwatto_cobra
  • Reply 5 of 7
    GeorgeBMacGeorgeBMac Posts: 11,421member
    maestro64 said:
    j2fusion said:
    Imagine if these devices had built in back doors like someone the government want. 
    Actual Time and other so called news outlets were also pushing for back doors so the Government could go after the "Bad Guy" of course the bad guy is anyone government or the media does not like at the time. 

    People have no idea how important privacy is and they want to give everyone else's away until the thought and idea police what to know you they are up too. not sure what this writer is complaining about, if he had nothing to hear why does he care what snooping eye want to see what they are doing.

    To be honest, I trust my government more than I do NSO group.
  • Reply 6 of 7
    maestro64maestro64 Posts: 5,043member
    maestro64 said:
    j2fusion said:
    Imagine if these devices had built in back doors like someone the government want. 
    Actual Time and other so called news outlets were also pushing for back doors so the Government could go after the "Bad Guy" of course the bad guy is anyone government or the media does not like at the time. 

    People have no idea how important privacy is and they want to give everyone else's away until the thought and idea police what to know you they are up too. not sure what this writer is complaining about, if he had nothing to hear why does he care what snooping eye want to see what they are doing.

    To be honest, I trust my government more than I do NSO group.
    you should never trust anyone, and NSO group only exist to support the government.
  • Reply 7 of 7
    GeorgeBMacGeorgeBMac Posts: 11,421member
    maestro64 said:
    maestro64 said:
    j2fusion said:
    Imagine if these devices had built in back doors like someone the government want. 
    Actual Time and other so called news outlets were also pushing for back doors so the Government could go after the "Bad Guy" of course the bad guy is anyone government or the media does not like at the time. 

    People have no idea how important privacy is and they want to give everyone else's away until the thought and idea police what to know you they are up too. not sure what this writer is complaining about, if he had nothing to hear why does he care what snooping eye want to see what they are doing.

    To be honest, I trust my government more than I do NSO group.
    ...  NSO group only exist to support the government.
    LOL....
    Yeh, they even claim that they only sell to the "Good" governments!   That's hilarious!

    watto_cobrajony0
Sign In or Register to comment.