abusesaffiliationarrow-downarrow-leftarrow-rightarrow-upattack-typeblueskyburgerchevron-downchevron-leftchevron-rightchevron-upClock iconclosedeletedevelopment-povertydiscriminationdollardownloademailenvironmentexternal-linkfacebookfilterflaggenderglobeglobegroupshealthC4067174-3DD9-4B9E-AD64-284FDAAE6338@1xinformation-outlineinformationinstagraminvestment-trade-globalisationissueslabourlanguagesShapeCombined Shapeline, chart, up, arrow, graphLinkedInlocationmap-pinminusnewsorganisationotheroverviewpluspreviewArtboard 185profilerefreshIconnewssearchsecurityPathStock downStock steadyStock uptagticktooltiptwitteruniversalitywebwhatsappxIcons / Social / YouTube

Esta página no está disponible en Español y está siendo mostrada en English

Informe

20 dic 2020

Autor:
Bill Marczak, John Scott-Railton, Noura Al-Jizawi, Siena Anstis, & Ron Deibert, The Citizen Lab

The Great iPwn: Journalists hacked with suspected NSO Group iMessage ‘zero-click’ exploit

Summary & Key Findings

In July and August 2020, government operatives used NSO Group’s Pegasus spyware to hack 36 personal phones belonging to journalists, producers, anchors, and executives at Al Jazeera. The personal phone of a journalist at London-based Al Araby TV was also hacked.

The phones were compromised using an exploit chain that we call KISMET, which appears to involve an invisible zero-click exploit in iMessage. In July 2020, KISMET was a zero-day against at least iOS 13.5.1 and could hack Apple’s then-latest iPhone 11.

Based on logs from compromised phones, we believe that NSO Group customers also successfully deployed KISMET or a related zero-click, zero-day exploit between October and December 2019.

The journalists were hacked by four Pegasus operators, including one operator MONARCHY that we attribute to Saudi Arabia, and one operator SNEAKY KESTREL that we attribute to the United Arab Emirates.

We do not believe that KISMET works against iOS 14 and above, which includes new security protections. All iOS device owners should immediately update to the latest version of the operating system.

Given the global reach of NSO Group’s customer base and the apparent vulnerability of almost all iPhone devices prior to the iOS 14 update, we suspect that the infections that we observed were a miniscule fraction of the total attacks leveraging this exploit.

Infrastructure used in these attacks included servers in Germany, France, UK, and Italy using cloud providers Aruba, Choopa, CloudSigma, and DigitalOcean.

We have shared our findings with Apple and they have confirmed to us they are looking into the issue.

Parte de las siguientes historias

Citizen Lab report alleges journalists at Qatar's Al Jazeera were hacked with NSO Group tool; incl. company comments

Investigation finds NSO Group spyware sold to governments used against activists, politicians & journalists; company denies allegations

Información de privacidad

Este sitio usa cookies y otras tecnologías de almacenamiento web. Puede configurar sus preferencias de privacidad más adelante. Los cambios se aplicarán de inmediato.

Para más información sobre el uso que hacemos del almacenamiento web, por favor consulte nuestra Política de Cookies y Uso de Datos

Strictly necessary storage

ON
OFF

Necessary storage enables core site functionality. This site cannot function without it, so it can only be disabled by changing settings in your browser.

Cookies analíticas

ON
OFF

Cuando accede a nuestro sitio web, utilizamos Google Analytics para recopilar información sobre su visita. La aceptación de esta cookie nos permitirá conocer más detalles sobre su visita y mejorar la forma en que mostramos la información. Toda la información analítica es anónima y no la utilizamos para identificarle. Google proporciona un complemento de inhabilitación de Google Analytics para todos los navegadores populares.

Cookies promocionales

ON
OFF

Compartimos noticias y actualizaciones sobre empresas y derechos humanos a través de plataformas de terceros, incluidas las redes sociales y los motores de búsqueda. Estas cookies nos ayudan a comprender el rendimiento de estas promociones.

Sus preferencias de privacidad en este sitio

Este sitio usa cookies y otras tecnologías de almacenamiento web para mejorar su experiencia, mas allá de la funcionalidad básica necesaria.