Transcription
[Music] [Music]
In mid-2020, a mobile phone belonging to Al Jazeera Arabic was hacked. Over the next few months, working with an organization called Citizen Lab, the team from Al Jazeera unpicked an extraordinary story of some of the most advanced spyware in the world and how it's used, not least on Al Jazeera's journalists.
"With the click of a button, you can bring down nations to their knees very rapidly if you so desire and if you're willing to take the rules, because every system can be hacked."
Israel manufactures Pegasus, some of the most advanced spyware in the world. It first came to attention in 2016. Since then, various governments have bought the spyware for their own use. Questions today are: How does Pegasus work? Who is using it? And who are its victims?
"Well, there's very little in the actual detail behind the Pegasus spyware, the code, the malicious code that was used. That's very, very difficult to find out more about."
For Al Jazeera Arabic, investigative reporter Tamar Mishal followed a complicated technical process to track this infamous spyware over many months. He had one of his own phones monitored constantly with the help of Citizen Lab, an international research laboratory based in Canada that specializes in data surveillance.
Citizen Lab was the first to expose the existence of Israel's Pegasus spyware in 2016. They disclosed details of what they called an exploit infrastructure connected to a phone belonging to an activist from the United Arab Emirates. The infiltration, the hack, led to the arrest of Ahmed Mansour, who remains imprisoned to this day. The new hacking technique was called a zero-day exploit, and Pegasus was the spyware used to infiltrate Mansour's phone.
Bill Marczak from Citizen Lab has worked for several years to expose Pegasus.
"So what happened in 2016 started with this man, Ahmed Mansour, the activist in the UAE, and he noticed some suspicious messages on his phone that he was getting via SMS. He thought they were weird because they came from unknown numbers and they were promising information about human rights. So he forwarded them to me at Citizen Lab. We had known each other for a while. I got a burner phone, not obviously my, my real phone, a burner phone, and clicked on the links. And while I was doing this, I was recording the internet traffic and recording the activity on the phone. And what was installed when I clicked the link was a very sophisticated spyware payload. And the interesting question was, well, who could be behind this? Who might have programmed the spyware? Who might have sold it? Who might be using it? And the process to figure that out is called attribution.
So what we did in the report is we noticed that when you clicked on the link a second time, it wouldn't cause the infection. It was only limited to the first click. And the second click would send you to a decoy website to try and make it look innocuous or benign. So we clicked on it the second time, we got redirected to Google. But it wasn't just any redirect to Google. It was a very specific piece of code that someone had sat down and written on their computer. So we figured, well, maybe this is part of this spyware somehow. And if we can scan the internet, we can find other servers that have the same weird redirect to Google.
So this is exactly what we did. We used the popular open-source ZMap program. We scanned the internet and found 149 other servers. And this is where it gets interesting, because this second redirect to Google was also returned by three servers: nsoqa.com, qaaintqa.com, and mailone.nsogroup.com. And the name here, NSO Group, we found in a brochure on the Israeli government's website. They had a brochure for this company, NSO Group, which is based in Israel and sells a product called Pegasus, which is spyware for mobile phones."
"In the case of Pegasus, Citizen Lab did very good work and was very, you know, very conclusively able to say that Pegasus had been written by NSO Group. But it's actually extremely rare that we're able to get that sort of concrete attribution and say, 'This malware was written by this company.'"
The NSO Group is a technology company based in Herzliya, Israel, founded in 2010. It employs over 500 cybersecurity experts. Pegasus spyware is viewed as its most important product.
"Israel is one of the most sophisticated cyber actors in the world, and I think that a lot of this is because the Israeli army is training, uh, people to do this sort of offensive hacking for, you know, in their military service. Our NSA, which is called Unit 8200, is pretty big. We allow them to create companies, uh, and we, in order for the companies to develop, they need to make, what do they need to make money? They need to make money."
Tomorrow Mishal spoke to William Binney, who for over 30 years worked with the U.S. National Security Agency. A former cryptographer and later a whistleblower, Binney was the NSA's technical leader of intelligence. Binney has a high-level understanding of the agency's data collection systems.
"What that means is any iPhone or any phone in the world, first connecting to the network when you want to use it, you're immediately known worldwide. I mean, all the switches have you, and they capture your IPs and all that, and your phone and Mac numbers and all that. That's how they bill you. So that also is known by the network. And the implants, computer network exploitation implants, they have around the world. Over, this was in 2004 or 2010, somewhere in that range, they had over 50,000 implants in all these switches, servers, and networks worldwide. I mean, that means they own the entire network. So that if you, your phone comes on the air, then they can, they can know who you are and where you are."
When Citizen Lab exposed NSO and its Pegasus spyware in 2016, it attracted worldwide controversy. NSO claims its mission is to develop technology for government agencies to "detect and prevent terrorism and crime." However, the nature of its targets, the individuals whose phones have been hacked, raises questions about these claims.
"When Pegasus was released a few years ago, it was mainly targeted on human rights activists, journalists, and politicians, um, and targeted people, maybe of people with high wealth. But it's never really going to be used on the, on Joe Public. If you were to target everyone in a mass net, I don't think that would be as important to the people behind it. They don't want to see my data, they don't want to see your data. They're going after specific people."
The danger of such spyware is its ability to infiltrate every piece of private information and hack the targeted device through the most used applications.
[Music]
In 2019, WhatsApp, owned by Facebook, accused NSO of hacking the popular communications tool. This raised fear amongst the huge numbers of global users of WhatsApp, especially at a time when some targeted victims appear to meet with dreadful consequences.
"So if you know, you do think that you are, uh, someone who's an important target, you're likely to face scrutiny by some government, uh, in the Middle East or elsewhere, and you are a journalist, an activist, or a member of civil society, I'd recommend that, yes, please do get in touch with, with Citizen Lab or other researchers who work in this space."
Tamar Mishal wanted to know how difficult it was to monitor a phone suspected of being hacked.
"Basically, it involves installing an app on the phone which allows us to inspect the internet traffic, um, and we do this for some period of time, um, depending on what the user would like. We can do it for a short time, we can do it for a long time, and try and identify suspicious patterns or evidence that the phone might be hacked."
While working as an investigative journalist, Mishal received threats and other suspicious messages through different apps. The threats increased over the months, ramping up as he worked on more sensitive regional subjects. He decided to install a tracking app on his work phone, developed by Citizen Lab, to trace possible hacking.
The conventional way to hack a smartphone is to send a suspicious message to the targeted phone that includes a short text and a link. When the user clicks on the link, software takes control of the phone and thus makes the device accept any command sent through the link. The device is then automatically connected to a server used by the hackers, and that is how the spyware gets installed on the phone. The user doesn't see the spyware on their phone, which has already been hacked. The hackers can then control the device and all its functions.
The main challenge for spyware is to find a vulnerability in the targeted phone, particularly as modern smartphone security protection techniques have developed significantly. Pegasus managed to advance this capability considerably.
"To be able to penetrate various kinds of smartphone, once the infection happens, the malware itself did the same stuff that we see a lot of malware do, which is spy on phone calls, spy on text messages and WhatsApp messages and any other encrypted messages you're sending, and turn on your microphone and turn on your camera. What made it especially sophisticated was that they were willing to use brand new exploits for iPhones to infect their victims, and some of these exploits could cost upwards of a million dollars each."
The supply of Pegasus spyware to its clients costs millions of dollars, and it can only be used for a limited period of time. That means targeting a large number of smartphones for long periods of time costs hundreds of millions of dollars. This extremely expensive cost raises questions: Who can afford this spyware? Who are NSO Group's main clients?
On its website, NSO Group says its spyware is "used exclusively by government intelligence as officially requested by the governments themselves." Does this mean that Pegasus cannot be purchased by other parties?
"When people leave the Israeli military service, they have all this very specialized, very highly sought-after, well-paid knowledge, and so they take it to private companies such as NSO Group, right? Um, and then they, they sell it to, uh, countries that are known to violate human rights because, you know, even though they are, you know, perhaps very intelligent about computer security, they clearly haven't thought so much about the human rights implications of what they are doing, or maybe they don't care."
Mishal, while working on this investigation, saw many signs of hacking attempts on his phone, the one he had fitted out to track any infiltrations. After seven months, on the 19th of July 2020, he received a phone call from Citizen Lab informing him that the phone had been hacked. The hacking happened a few days after he had aired an investigative documentary about an Indian tycoon, which disclosed controversial leaked documents about the tycoon's links to the UAE and his flight from that country. Mishal had used the same phone to communicate with officials and individuals in the UAE in order to give them the right to reply to the allegations in the film.
"So the first thing that we saw on your phone was on July 19th, between about 10:33 and 11:28 AM GMT, there were a very high number of connections to Apple servers. Now, usually your phone will just communicate with one Apple server for iCloud, for your backups, for your contacts syncing the information. But in this case, in less than an hour, we saw your phone communicate with 18 different Apple servers. And this was very unusual. You don't usually see this on phones. So that was the first clue that something suspicious was going on. And immediately after this communication stopped, we saw your phone reach out to this website, regular hours.net. In other words, your phone connected to this website. And this website stands out because we know from our research at Citizen Lab that regular hours.net, this website is linked to NSO Group's Pegasus spyware. So we saw your phone reaching out to this NSO Pegasus spyware server, which led us to suspect, and then later conclude, that your phone was infected.
So what we can see from the recording of your internet traffic, so let's go to this point in time here, 11:29, where the phone communicates with the Pegasus server. And we can look beforehand to see what was going on immediately before that. And the only thing that we see is this communication with iCloud, with Apple servers. We don't see any evidence that you pressed on a link or clicked on anything or went to any website. So what we think happened is that these communications with the Apple servers delivered the initial exploit to hack your phone. In other words, you didn't click on anything. Your phone was automatically hacked. A so-called zero-click, like we say, zero-click exploit delivered through Apple servers."
"This is a very expensive exploit. Yes. This is, if you think about, uh, the sophistication of exploits to break into phones, this is as good as it gets. Zero-click means hacking without clicking on any links. Pegasus does not require any action by the user or a click on any suspicious links. The user receives a call from an unknown caller through the internet, and the phone gets hacked even without answering the phone call. After that, Pegasus spyware is installed on the targeted phone, taking full control of the device."
"Well, it's definitely the most sophisticated attack I've seen in the last few years. The fact it was able to be installed on a target's device without the target even clicking on anything, so a zero-click attack. This is incredibly impressive, and like I say, very rarely seen. To better do that, it's so sophisticated, but as it is rare, it is difficult for us to really know much more about it. If something of this magnitude was able to be conducted to steal such data, this is a bit of a worry."
Zero-click. Tamar Mishal wanted to know if the zero-click process enabled complete access to all the applications and content on his phone.
"As far as we know, they can access everything on the phone. We saw from looking at the log files on your phone that they were able to access the media framework, so they were able to turn on the microphone, turn on the camera if they wanted to, and listen into meetings or conversations going on around your device. They were also able to tap into the keychain on the phone. This is where your passwords for email accounts, social media may be stored."
The fact that Citizen Lab was tracking Tamar's phone helped him take precautionary measures to prevent sensitive information being accessed. The most important thing was for him to discover the moment the hacking took place and who else was affected.
"But what we found working together with Al Jazeera's IT team is that your case was not the only one. There were at least 36 other cases inside Al Jazeera of phones that were communicating with servers that we linked to NSO Group's Pegasus spyware. In other words, there were many different people at Al Jazeera who were hacked and targeted, not just you."
Mishal and the team from Citizen Lab analyzed the data connected to the hacking technology which targeted these devices. The hack appeared to be part of an organized campaign targeting simultaneously the mobile phones of dozens of Al Jazeera journalists in order to spy on them. According to Citizen Lab's technical report, Israel's Pegasus spyware was used to infiltrate these phones. By looking at the links and the accounts, the hacking of the phones was carried out mainly in the UAE and Saudi Arabia, the two countries that most used this advanced Israeli technology in the region.
"Well, what we saw with the infections inside Al Jazeera is that about half of them were from this operator that we call Monarchy. It's a code name that we give these operators when we refer to them inside Citizen Lab. And this operator is spying mostly in Saudi Arabia and Qatar, but not very many other countries. So this tells us, well, if they're spying mostly in Saudi Arabia, maybe it is, in fact, the Saudi Arabian government. And the other half were from this other operator that we call Sneaky Kestrel inside Citizen Lab. And this operator seems to be mostly targeting inside the United Arab Emirates and Qatar. So this tells us that the government in this case, may be the United Arab Emirates government. In other words, two different governments, it looks like, were behind this campaign."
Deals to purchase Pegasus spyware are no longer a secret. Many reports claim that Saudi Arabia and the UAE have spent hundreds of millions of US dollars to buy Pegasus from Israel. Such deals seemed to be reinforced after the recent US-brokered so-called normalization deal between the UAE and Israel.
In November 2020, Al Jazeera Arabic contacted the top Israeli cybersecurity official to find out more about data and cyber cooperation between Israel and the UAE. The official refused to speak on camera but said he had just returned from an official business trip to the UAE designed to promote high-profile official coordination between the two countries. According to leaked reports, Israeli-Emirati cyber cooperation developed significantly around this time. The arrangement seemed to be that full security coordination between the two countries allowed an exchange of information, while the UAE invested millions of US dollars in the Israeli spyware. The benefits were allegedly governed by rules set by the Israeli intelligence services.
[Music] [Music]
Dark Matter is an Emirati company that is seen as the main player in the UAE cybersecurity market.
"Dark Matter is a very interesting case. It's this company based in the United Arab Emirates, and they do sort of both, uh, defense as well as offense. There was this great reporting from both Foreign Policy as well as Reuters, which looked into their offensive operations, meaning hacking. So what, what these reports were able to establish is that there was this group of NSA former NSA and former CIA intelligence officials from the United States that went to go work for the UAE government under the auspices of this company, Dark Matter. And just to follow on to that, and be clear, Dark Matter was not employing former NSA officials to spy on Americans because that would obviously be a federal crime in the United States. We don't do that, and it's, it's not within our limit. Our mission is to enable societies and economies to sort of pursue their agenda of smart and safe digital. So it will be contrary to our mission. And I would like, sort of, to stress this point is to enable societies and economies to sort of pursue their agenda of smart and safe digital. So it will be contrary to our mission. And you can categorically say that Dark Matter doesn't spy on UAE citizens. We don't do that. That's not within our capabilities. So categorically, we don't do this work."
"They're lying. They're lying. It's the only thing that had could handle massive data for them. I designed these mathematical programs. We had no upper limit on the capacity to handle data, none. There was no, no problem at trillions, quadrillions of data, doesn't matter. We had no mathematical limit that I could see."
The American investigative website The Intercept published a report in October 2016 based on the experiences of an Italian cybersecurity researcher approached by Dark Matter. The report claimed that Dark Matter had discussed plans to hack any device it wanted to in the UAE at the press of a button. The report also cited a number of Dark Matter employees who were former US NSA and intelligence officials. The employees said they were asked to carry out offensive operations under the banner of protecting UAE's national security. Dark Matter dismissed the researcher's allegations, saying it preferred "talking reality, not fantasy."
Tamar Mishal met the author of the report, Jenna McLaughlin, who has investigated the work of Dark Matter extensively.
"Around 2015, the UAE and its company, essentially linked pretty closely to its own defense, defense services. Dark Matter wanted to get some of those employees into their own roof so they could do a lot more things more freely because some of those US contractors were restricted by US laws. They were drawn by massive salaries, promises of staying in beautiful places, pools, villas, yachts, even sometimes. So once some of these employees arrived in, in Dark Matter, they were sort of asked questions about how to use those skills in an offensive manner. In order to do that, they would also have to have their, see, clearances would be held by, by that contractor in a skip, but the approval for the, the clearance would come from NSA if it was against EIA, if it was human, and so on. So that the agencies would approve it. So that implies that everything that they're doing with these contractors is approved."
"The leading cybersecurity firm in the region, Dark Matter, and we're covering nearly the whole spectrum of cybersecurity. We've also grabbed a lot of people all around the world."
"Within the last few years, I returned to Abu Dhabi for a defense conference, IDEX, and I got the chance to speak to some of my sources and, and others that I've met since. And they told me that all the negative attention on Dark Matter from my reporting and subsequent reporting from Reuters and others really drew a lot of attention that the royal family was not interested in. And as a result of that, members of the royal family, extremely high-ranking officials, sort of went to Dark Matter and said, 'You need to change the names of this, remove it, get it out of here, be a lot more discreet.' I think from my perspective, okay, having a contractor, a US contractor working for a foreign government means they are now an agent of that foreign government, not, not a US agent. Or, and having them come from a place like NSA where they're dealing with classified activities, and then going over and assisting in classified act, similar classified activities in another country means there's, uh, foreign spies now. They're not US citizens."
"In the couple months after I published my first story, in between publishing my second at Foreign Policy magazine, I was contacted by sort of mysterious source who offered documents that I was never able to verify and who had been telling me that within the company, they had already been debating whether or not to hack me. But I mean, years later, The Intercept, after I had left, confirmed that The Intercept was a target of the UAE government."
According to a number of reports, Dark Matter tried to hack The Intercept website. A report published by The Intercept in June 2019 said that Dark Matter brought ex-National Security Agency hackers and other intelligence and military veterans to compromise the computers of political dissidents at home and abroad, including American citizens. According to The Intercept, Dark Matter's headquarters is located in this building in Abu Dhabi.
"They had a problem analyzing data on US citizens from another country. As a US citizen, see, so that's, uh, that is illegal, and I'm sure under Title 18 laws governing, you know, classified material and classified activities."
Later on, Citizen Lab demonstrated that Dark Matter was the main operator of the Israeli Pegasus spyware in the UAE. Besides its American staffers, Dark Matter also employed ex-Israeli officers in branches in the UAE, Cyprus, and Singapore. The company is reported to have paid millions of dollars for their services.
Both Al Jazeera Arabic and Al Jazeera English contacted Dark Matter and offered them the opportunity to respond to all the allegations made in the film. They declined to comment to either request.
[Music]
"We certainly do see that Israel is a hub, if not in the world, then certainly in the region, for this sort of cyber technology. And I think, you know, one of the things that we're going to see more and more countries like the UAE that have these big ambitions in cyberspace are going to try and replicate that sort of talent pipeline in their countries. It's very scary, especially when the targets are journalists, civil society, dissidents, these sorts of people being spied on by foreign governments or their own government in some cases. It's really shocking, and I think it's an abuse of the spyware. The reason that the governments are interested in spying on them is for intelligence purposes, to figure out what they're up to, what they might do next. And if they can figure out what someone's doing, what they're about to do, then they can put a little bit of pressure on people and try and influence and shape the way that events unfold."
Al Jazeera Arabic contacted many alleged victims of these spyware hacks. They declined to appear in the film for fear of their and their family's safety. Rania is a London-based journalist working with Al-Arabi TV. Her phone was hacked by Pegasus spyware between October 29 and July 2020.
[Music] [Music]
"There's lots of journalists that get targeted and hacked, but far fewer of them are willing to come forward and tell their stories. So I think that, you know, if you were to look at some of the top media organizations in the world, maybe you'd find other, other instances of people getting hacked or targeted. Um, you know, we had a case, of course, back in 2018, where the Beirut bureau chief of The New York Times, Ben Hubbard, received a text message linked to Pegasus spyware on his phone."
So the question is, with this advanced technology, how can people ensure their devices are safe from hacking?
"With Pegasus, for, for example, um, it would have been very hard to find out that your phone had been hacked. The best thing you can do is keep your phone up to date. If you haven't always install the updates when your phone says it's time to update. Um, if you get a text message with a link that you're not expecting, don't click on that link. If you get an email with a link or a file that you're not expecting, don't click on that link, don't open that file. If you do have something very sensitive to talk about, the best thing to do is to leave your phone at home and go on a walk."
"Old files have vulnerabilities on them, and if they're known, they will get patched by Apple and Android and so on. But there are going to be vulnerabilities on those devices that are unknown yet, and therefore any device is, or that will have a weakness that can be exploited. I, I am sure there are organizations all over the world looking for those vulnerabilities to exploit in the future, and no doubt it will happen again. It's just a case of when."
The Electronic Frontier Foundation (EFF) is a US-based organization whose goal is to technically and legally defend journalists and civil society activists who face cybercrimes committed by governments. EFF has documented a rise in the number of Pegasus-associated cybercrimes against journalists and activists working on sensitive cases.
"We fight against government abuse of surveillance powers, abuses that are inconsistent with human rights standards, and that was using Mexico to target like Carmen Aristegui, which is a very famous investigative journalist in the country. And we have seen also the use of NSO Pegasus in Mexico targeting activists who were fighting corruption or who are fighting, for instance, a campaign advocacy against corporations for the use of, of sugar. And so we have seen this also against many other journalists who are doing just their work. In my work, uh, we have studied similar, uh, mobile phone hacks against journalists in, um, Kazakhstan and, and human rights defenders and opposition politicians in Kazakhstan, in Lebanon, and on the border of Lebanon and Syria, being spied upon by their various governments."
In Israel, lawyer Allah Mahajna represents a number of phone hacking victims who have decided to file lawsuits against the Israeli NSO Group.
"A towards victims of hacking lies with the manufacturer or the purchaser of the spyware. These companies are saying that they only sell these to governments and that they only sell it to investigate terrorists and organized crime. But, and they don't sell it to governments who don't respect human rights. But that's not true. You know, and that inconsistency, it's legal under international law. It's inconsistent, in our opinion, also with the constitution of many of the countries. We have reviewed the laws. I personally know about dozens of events. The terrible terrorist attacks were intercepted only due to the availability of such a, uh, intelligence capability."
In 2020, an Israeli court banned the media from publishing any details about these cases in the interests of protecting Israel's national security.
Al Jazeera Arabic contacted the NSO Group requesting an interview with senior management to give them the right to reply to allegations made against the company in this film. The company sent a short reply declining the interview request. Al Jazeera English contacted the NSO Group to give them the right to reply to allegations made against the company in this film. They did not respond.
"Is, Amnesty International also took legal action against Pegasus. The accused party, this time, was the Israeli Defense Ministry itself, being the official body that approves and authorizes the selling of spyware."
"We are disappointed. We will have to see what the court decides with the ruling on the case itself. Now, we hope that the court will decide the way it should and revoke NSO's security license."
An Israeli court dismissed the case. Amnesty International said, "A mountain of evidence was ignored," and called the court a "rubber stamp to the Defense Ministry's impunity to human rights violations."
"My reaction to the court's decision was obviously disappointment. It was a, it was a very strong judgment that didn't take into consideration the evidence that we put forward or the legal arguments that, that we felt were important. And while we were disappointed in the judgment, we still think it was a very important case, uh, in the growing evidence of NSO's misuse of technology or the misuse of NSO's technologies by our clients. And we hope that by bringing this case and supporting this case, we're bringing to attention the very serious issues and potential human rights impacts for technologies like NSO's Pegasus and others that are being used with impunity around the world by repressive governments and governments who have a terrible human rights record."
Pegasus contacted the governments of Israel, the Kingdom of Saudi Arabia, and the United Arab Emirates and offered them the opportunity to respond to all the allegations made in the film. They did not respond.
"I actually would also like to know a little bit more about what happened in the rejection. I think there's a few different things at play here. One is that it's very difficult to know the relationship between the Ministry of Defense and NSO. There seems to be a lot of crossover at high-level staff. The Ministry of Defense in Israel is the, is the ministry that approves all exports. And basically, our case was saying, either the Ministry of Defense is not giving export licenses in line with international human rights standards, or they are giving exports in line with international human rights standards, but they have, they have a company in, in their jurisdiction who is acting outside of the, the legal export license."
And others whose phones have been hacked, the question is, what recourse, if any, do they have?
"This sort of evidence does show that your phone was hacked and shows that there was a connection to NSO Group. If you wanted to bring a legal action, I will say that there are other targets that have been engaged in the legal process in Israel, in Cyprus, and most recently in the UK."
Our smartphones have become an inevitable necessity of modern life. However, they have also turned into a window through which security services can access our private information. They can become a weapon used by unscrupulous governments to spy on us with little legal or moral deterrence. There is still much to be uncovered in this secretive world of hacking and advanced spyware. For Tamar Mishal, this investigation into his own phone's hacking has been both revealing and alarming.