Why is Pegasus spyware controversial?
Pegasus is spyware installed covertly on mobile phones (and other devices) running some versions of Apple's mobile operating systems, iOS, and Android.
It was developed by Israeli cyber arms firm NSO Group, which states that it "provides authorized governments with technology that helps them combat terror and crime."
Caption
It has published sections of certain contracts that require customers to use its products only for criminal and national security purposes. Investigated and said it has an industry-leading approach to human rights.
The spyware is named after the mythical winged horse Pegasus – a Trojan horse that can be sent to "fly through the air" to infect phones.
Discovered in August 2016 (in addition to its developers and customers) after a human rights activist's failed attempt to install it on the iPhone,
An investigation revealed details about the spyware, its capabilities, and the security vulnerabilities it exploited.
Pegasus can read text messages, track calls, collect passwords, track location, access the target device's microphone and camera, and access information from apps.
Apple released version 9.3.5 of its iOS software to fix the vulnerabilities. News of the spyware caused significant media coverage.
It was called the "most sophisticated" smartphone attack ever. It was the first time a malicious remote exploit was detected using a jailbreak to gain unrestricted access to the iPhone.
On August 23, 2020, according to intelligence obtained by the Israeli newspaper Haaretz, the NSO Group reported selling Pegasus spyware software to the United Arab Emirates and other Gulf states for hundreds of millions of US dollars for anti-government surveillance.
Activists, journalists, and political leaders from rival countries with the encouragement and mediation of the Israeli government.
The Al Jazeera investigation show The Tip of the Iceberg, Spy Partners, featured exclusive footage on December 20, 2020, about Pegasus and its penetration into the phones of media professionals and activists, which Israel used to attack its opponents and even Used to hide on his colleagues.
Pegasus is spyware owned by the Israeli NSO Group. The company was owned by American private equity firm Francisco Partners, then bought back by the founders in 2019.
Spyware can be installed on devices running some versions of iOS, Apple's mobile operating system.
When a malicious link is clicked, Pegasus secretly enables a jailbreak on the device and can read text messages, track calls, collect passwords, trace phone locations, and more.
as well as collect information from the App, including but not limited to the communication App iMessage. , Gmail, Viber, Facebook, WhatsApp, Telegram, and Skype.
At the 2017 Security Analyst Summit hosted by Kaspersky Lab, researchers revealed that Pegasus was available for Android in addition to iOS; Google refers to the Android version as Chrysaor, the brother of the winged horse Pegasus.
Its functionality is similar to the iOS version, but the method of attack is different. Android version tries to gain root access (similar to jailbreaking in iOS); If it fails, it asks the user for permissions that enable it to harvest at least some of the data.
At the time, Google said that only a few Android devices were infected.
security fix
Apple released iOS version 9.3.5 for its iPhone smartphones in August 2016, fixing three critical security vulnerabilities exploited by Pegasus.
spyware discovery
The vulnerabilities were detected ten days before the release of the iOS 9.3.5 update. Arab human rights defender Ahmed Mansour received a text message promising a "secret" about torture in UAE prisons by following a link. Mansoor sent the link to Citizen Lab,
In collaboration with Lookout, which investigated that if Mansoor had followed the link, it would have jailbroken his phone and installed spyware as a form of social engineering.
The New York Times and The Times of Israel both reported that it appeared the United Arab Emirates was using this spyware as early as 2013.
You must be logged in to post a comment.