Article Details
Scrape Timestamp (UTC): 2024-03-02 06:31:47.690
Source: https://thehackernews.com/2024/03/us-court-orders-nso-group-to-hand-over.html
Original Article Text
Click to Toggle View
U.S. Court Orders NSO Group to Hand Over Pegasus Spyware Code to WhatsApp. A U.S. judge has ordered NSO Group to hand over its source code for Pegasus and other products to Meta as part of the social media giant's ongoing litigation against the Israeli spyware vendor. The decision, which marks a major legal victory for Meta, which filed the lawsuit in October 2019 for using its infrastructure to distribute the spyware to approximately 1,400 mobile devices between April and May. This also included two dozen Indian activists and journalists. These attacks leveraged a then zero-day flaw in the instant messaging app (CVE-2019-3568, CVSS score: 9.8), a critical buffer overflow bug in the voice call functionality, to deliver Pegasus by merely placing a call, even in scenarios where the calls were left unanswered. In addition, the attack chain included steps to erase the incoming call information from the logs in an attempt to sidestep detection. Court documents released late last month show that NSO Group has been asked to "produce information concerning the full functionality of the relevant spyware," specifically for a period of one year before the alleged attack to one year after the alleged attack (i.e., from April 29, 2018, to May 10, 2020). That said, the company doesn't have to "provide specific information regarding the server architecture at this time" because WhatsApp "would be able to glean the same information from the full functionality of the alleged spyware." Perhaps more significantly, it has been spared from sharing the identities of its clientele. "While the court's decision is a positive development, it is disappointing that NSO Group will be allowed to continue keeping the identity of its clients, who are responsible for this unlawful targeting, secret," said Donncha Ó Cearbhaill, head of the Security Lab at Amnesty International. NSO Group was sanctioned by the U.S. in 2021 for developing and supplying cyber weapons to foreign governments that "used these tools to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers." The development comes as Recorded Future revealed a new multi-tiered delivery infrastructure associated with Predator, a mercenary mobile spyware managed by the Intellexa Alliance. The infrastructure network is highly likely associated with Predator customers, including in countries like Angola, Armenia, Botswana, Egypt, Indonesia, Kazakhstan, Mongolia, Oman, the Philippines, Saudi Arabia, and Trinidad and Tobago. It's worth noting that no Predator customers within Botswana and the Philippines had been identified until now. "Although Predator operators respond to public reporting by altering certain aspects of their infrastructure, they seem to persist with minimal alterations to their modes of operation; these include consistent spoofing themes and focus on types of organizations, such as news outlets, while adhering to established infrastructure setups," the company said. State of AI in the Cloud 2024 Find out what 150,000+ cloud accounts revealed about the AI surge. Goodbye, Atlassian Server. Goodbye… Backups? Protect your data on Atlassian Cloud from disaster with daily backups and on-demand restores.
Daily Brief Summary
A U.S. federal court has ruled that NSO Group must provide Meta with the source code for Pegasus spyware as part of ongoing litigation.
The lawsuit, initiated by Meta in October 2019, accuses NSO Group of exploiting WhatsApp to install Pegasus on roughly 1,400 mobile devices, including those of Indian activists and journalists.
NSO Group exploited a critical zero-day vulnerability in WhatsApp for the distribution of the spyware, which did not require call answer to infect the device.
Though NSO Group must release details on the spyware, it is not required to disclose its server architecture or the identities of its clients.
Amnesty International expressed disappointment that the clientele of NSO Group remains confidential, despite the firm facing U.S. sanctions for supplying cyber tools used in malicious operations against various individuals and entities.
The order comes alongside revelations that the Intellexa Alliance's Predator mobile spyware is part of a new, complex delivery infrastructure involving multiple countries, highlighting ongoing concerns around mercenary spyware and its global implications.