Security

Researchers say they found spyware used in war for the first time

Comment

Azeri service members carry a giant flag during a procession marking the anniversary of the end of the 2020 military conflict over Nagorno-Karabakh breakaway region on November 8, 2021 in Baku, Azerbaijan.
Image Credits: Getty Images under a Aziz Karimov license.

Security researchers and digital rights organizations believe the government of Azerbaijan used spyware produced by NSO Group to target a government worker, journalists, activists and the human rights ombudsperson in Armenia as part of a years long conflict that has at times broken out into an all-out war.

The cyberattacks may be the first public cases where commercial spyware was used in the context of a war, according to Access Now, a digital rights group that investigated some of the cases. The hacks happened between November 2021 and December 2022. The skirmish between Armenia and Azerbaijan — known as the Nagorno-Karabakh conflict — has been going on for years, and it flared up again in May 2021, when Azerbaijani soldiers crossed into Armenia and occupied parts of its territory.

“While a number of infected individuals are also members of the Armenian opposition or are otherwise critical of the current government, the infections took place at critical times in the Nagorno Karabakh conflict and a deep political crisis caused by the conflict, which resulted in a significant uncertainty over the future of the country’s leadership and its position on Karabakh,” Natalia Krapiva, the tech legal counsel at Access Now, told TechCrunch. “Some of the victims worked closely in or with [Armenia’s] Nikol Pashinyan’s administration and were directly involved in the negotiations or investigation of human rights abuses committed by Azerbaijan in the conflict.”

The Azerbaijani embassy in Washington, D.C. did not respond to a request for comment.

NSO Group did not respond to a request for comment.

Access Now was aided by Citizen Lab, another digital rights organization specialized in investigating spyware; Amnesty International; CyberHUB-AM, an Armenian cybersecurity organization that helps civil society; and local cybersecurity researchers.

According to Access Now, the victims include Kristinne Grigoryan, the top human rights defender in Armenia; Karlen Aslanyan and Astghik Bedevyan, two Radio Free Europe/Radio Liberty’s (RFE/RL) Armenian Service journalists; two unnamed United Nations officials; Anna Naghdalyan, a former spokesperson of Armenia’s Foreign Ministry (now an NGO worker); as well as activists, media owners and academics.

Samvel Farmanyan, the former co-founder and host of an opposition television in Armenia, told TechCrunch that the hack he suffered “is a form of terror.”

“It is not only a clear violation of human rights, my rights of privacy and private communication, but it had [an] enormous psychological effect,” he said in an online chat. “It is difficult what you feel when you are sure that you are illegally under surveillance with no knowledge which government may stand behind and what the real purposes are behind that illegal intervention.”

Farmanyan, as well as other victims, realized they were victims of a hack when Apple sent them a notification that they may have been targeted with government spyware, as the company did with several other victims in other countries. They then reached out to Access Now, Citizen Lab or Amnesty International to get their phones checked.

In the case of Armenia’s top human rights defender Grigoryan, Access Now said that her phone “was infected not long after she shared her phone number with her Azerbaijani counterpart.”

Over the last few years, there have been countless cases of abuse of NSO spying tools in Mexico, Saudi Arabia, Bahrain and many other countries, but Access Now considers this a special case.

“Providing Pegasus spyware to either of the sides in the context of a violent conflict carries a substantial risk of potentially contributing to and facilitating serious human rights violations and even war crimes,” the organization wrote in its press release.

There isn’t conclusive evidence that the Azerbaijan government is behind these attacks, but a coalition of media organizations known as the Pegasus Project showed that the country is one of NSO’s customers. Yet, Ruben Muradyan, a mobile security researcher who analyzed the phones of five victims in Armenia, said that some of them believe the government of Armenia could be behind the hacks, since they were being critical of the local government at the time.

The Armenian embassy in Washington, D.C. did not respond to a request for comment.

In any case, it’s unclear whether using spyware such as Pegasus in the context of an armed conflict constitutes a violation of international law, according to Anna Pagnacco, a cybersecurity policy researcher at Oxford Information Labs.

“International law is silent on the topic of peacetime espionage, which is broadly criminalized at the national level; yet all states still conduct espionage. Intelligence activities carried out by members of a belligerent party’s armed forces in uniform during international armed conflict are legitimate — i.e. spying is not a war crime,” Pagnacco told TechCrunch.


Do you have more information about NSO Group? Or another surveillance tech provider? We’d love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Wickr, Telegram and Wire @lorenzofb, or email lorenzo@techcrunch.com. You can also contact TechCrunch via SecureDrop.

More TechCrunch

As part of the update, Reddit also launched a dedicated AMA tab within the web post composer.

Reddit introduces new tools for ‘Ask Me Anything,’ its Q&A feature

Here are quick hits of the biggest news from the keynote as they are announced.

Google I/O 2024: Here’s everything Google just announced

LearnLM is already powering features across Google products, including in YouTube, Google’s Gemini apps, Google Search and Google Classroom.

LearnLM is Google’s new family of AI models for education

The official launch comes almost a year after YouTube began experimenting with AI-generated quizzes on its mobile app. 

Google is bringing AI-generated quizzes to academic videos on YouTube

Around 550 employees across autonomous vehicle company Motional have been laid off, according to information taken from WARN notice filings and sources at the company.  Earlier this week, TechCrunch reported…

Motional cut about 550 employees, around 40%, in recent restructuring, sources say

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: Watch all of the AI, Android reveals

It ran 110 minutes, but Google managed to reference AI a whopping 121 times during Google I/O 2024 (by its own count). CEO Sundar Pichai referenced the figure to wrap…

Google mentioned ‘AI’ 120+ times during its I/O keynote

Google Play has a new discovery feature for apps, new ways to acquire users, updates to Play Points, and other enhancements to developer-facing tools.

Google Play preps a new full-screen app discovery feature and adds more developer tools

Soon, Android users will be able to drag and drop AI-generated images directly into their Gmail, Google Messages and other apps.

Gemini on Android becomes more capable and works with Gmail, Messages, YouTube and more

Veo can capture different visual and cinematic styles, including shots of landscapes and timelapses, and make edits and adjustments to already-generated footage.

Google Veo, a serious swing at AI-generated video, debuts at Google I/O 2024

In addition to the body of the emails themselves, the feature will also be able to analyze attachments, like PDFs.

Gemini comes to Gmail to summarize, draft emails, and more

The summaries are created based on Gemini’s analysis of insights from Google Maps’ community of more than 300 million contributors.

Google is bringing Gemini capabilities to Google Maps Platform

Google says that over 100,000 developers already tried the service.

Project IDX, Google’s next-gen IDE, is now in open beta

The system effectively listens for “conversation patterns commonly associated with scams” in-real time. 

Google will use Gemini to detect scams during calls

The standard Gemma models were only available in 2 billion and 7 billion parameter versions, making this quite a step up.

Google announces Gemma 2, a 27B-parameter version of its open model, launching in June

This is a great example of a company using generative AI to open its software to more users.

Google TalkBack will use Gemini to describe images for blind people

Firebase Genkit is an open source framework that enables developers to quickly build AI into new and existing applications.

Google launches Firebase Genkit, a new open source framework for building AI-powered apps

This will enable developers to use the on-device model to power their own AI features.

Google is building its Gemini Nano AI model into Chrome on the desktop

Google’s Circle to Search feature will now be able to solve more complex problems across psychics and math word problems. 

Circle to Search is now a better homework helper

People can now search using a video they upload combined with a text query to get an AI overview of the answers they need.

Google experiments with using video to search, thanks to Gemini AI

A search results page based on generative AI as its ranking mechanism will have wide-reaching consequences for online publishers.

Google will soon start using GenAI to organize some search results pages

Google has built a custom Gemini model for search to combine real-time information, Google’s ranking, long context and multimodal features.

Google is adding more AI to its search results

At its Google I/O developer conference, Google on Tuesday announced the next generation of its Tensor Processing Units (TPU) AI chips.

Google’s next-gen TPUs promise a 4.7x performance boost

Google is upgrading Gemini, its AI-powered chatbot, with features aimed at making the experience more ambient and contextually useful.

Google’s Gemini updates: How Project Astra is powering some of I/O’s big reveals

Veo can generate few-seconds-long 1080p video clips given a text prompt.

Google’s image-generating AI gets an upgrade

At Google I/O, Google announced upgrades to Gemini 1.5 Pro, including a bigger context window. .

Google’s generative AI can now analyze hours of video

The AI upgrade will make finding the right content more intuitive and less of a manual search process.

Google Photos introduces an AI search feature, Ask Photos

Apple released new data about anti-fraud measures related to its operation of the iOS App Store on Tuesday morning, trumpeting a claim that it stopped over $7 billion in “potentially…

Apple touts stopping $1.8B in App Store fraud last year in latest pitch to developers

Online travel agency Expedia is testing an AI assistant that bolsters features like search, itinerary building, trip planning, and real-time travel updates.

Expedia starts testing AI-powered features for search and travel planning

Welcome to TechCrunch Fintech! This week, we look at the drama around TabaPay deciding to not buy Synapse’s assets, as well as stocks dropping for a couple of fintechs, Monzo raising…

Inside TabaPay’s drama-filled decision to abandon its plans to buy Synapse’s assets