Researchers say Thai pro-democracy activists hit by spyware

Jul 17, 2022, 8:16 AM | Updated: Jul 18, 2022, 12:16 am

Pro-democracy activist Panusaya Sithijirawattanakul shows her mobile phone during a news conference...

Pro-democracy activist Panusaya Sithijirawattanakul shows her mobile phone during a news conference in Bangkok, Thailand, Monday, July 18, 2022. Cybersecurity researchers say that Thai activists involved in the country's pro-democracy protests had their cellphones or other devices infected and attacked with government-sponsored spyware. (AP Photo/Sakchai Lalit)

(AP Photo/Sakchai Lalit)

BANGKOK (AP) — Cybersecurity researchers reported details Monday of cases where Thai activists involved in the country’s pro-democracy protests had their cell phones or other devices infected and attacked with government-sponsored spyware.

Investigators of the internet watchdog groups Citizen Lab, Thailand’s Internet Law Reform Dialogue, or iLaw, and Digital Reach said at least 30 individuals — including activists, scholars and people working with civil society groups — were targeted by an unnamed government entity or entities for surveillance with Pegasus, a spyware produced by the Israeli-based cybersecurity company NSO Group.

The reports from the two groups named many of those targeted, confirming earlier reports of the surveillance, which John Scott-Railton of Citizen Lab said shows that governments are exploiting their ability to buy technologies designed to fight crime and terrorism to spy on critics and other private citizens.

“Citizen Lab believes there is a fundamental challenge for civil society,” John Scott-Railton of Citizen Lab said in an online presentation at a briefing in Bangkok.

The attacks on the individuals’ devices spanned from Oct. 2020 to Nov. 2021, a timing “highly relevant to specific Thai political events” since they took place over the period of time when pro-democracy protests erupted across the country.

But Scott-Railton said Citizen Lab, which exposes digital espionage campaigns and insecure software, believed there was still an active Pegasus operator in Thailand.

Those whose devices were attacked were either involved in the protests in 2020-2021, or were publicly critical of the Thai monarchy. Lawyers who defended the activists also were under such digital surveillance, the researchers said.

The Pegasus spyware is known for “zero-click exploits,” which means it can be installed remotely onto a target’s phone without the target having to click any links or download software.

The spyware can obtain any data on the devices, including contact lists and group chats, making it highly effective against political groups and movements, Scott-Railton said.

NSO Group’s products, including the Pegasus software, are typically licensed only to government intelligence and law enforcement agencies to investigate terrorism and serious crime, according to the company’s website. Citizen Lab and other cyber security researchers have tracked the spyware to 45 countries.

In a separate report Monday, the human rights group Amnesty International reiterated its call for a global moratorium on the sale of spyware.

“The unlawful targeted surveillance of human rights defenders and civil society is a tool of repression. It is time to clamp down on this industry that continues to operate in the shadows,” Amnesty Tech’s deputy director Danna Ingleton said in a statement.

The company has rejected accusations that its snooping software helped lead to the killing of Saudi journalist Jamal Khashoggi, perhaps the highest-profile case so far. It maintains that its sales undergo a rigorous ethical vetting process and that Pegasus spyware is sold to governments only for security purposes.

In November, the U.S. government blacklisted NSO Group and Apple sued it and notified Pegasus victims. Facebook has sued NSO Group over the use of a somewhat similar exploit that allegedly intruded via its globally popular encrypted WhatsApp messaging app.

The reports by Citizen Lab and iLaw do not accuse any specific government actor but say the use of Pegasus indicates the presence of a government operator. When news that dissidents had been targeted first surfaced in November 2021, the government denied the allegations.

Apple said it sought a permanent injunction to ban NSO Group from using any Apple software, services or devices to “to prevent further abuse and harm to its users.”

Apple’s notifications to customers of spyware infections are a crucial part of a defense strategy against such digital surveillance, Scott-Railton said.

“Apple did something remarkable by notifying the recipients of this suspected targeting. If you look at the infection online, it stopped after Apple’s notification,” he said. “It was a very consequential thing.”

The cybersecurity experts said that turning off and restarting a device can break the spyware’s digital connection. Security updates also have helped to close the loopholes such attackers exploit.

“Layering up defenses on devices is very important,” Scott-Railton said. “Anything is better than nothing.”

But the spyware is constantly being updated and it is designed to be difficult to spot, facilitating surveillance by governments that have found it a useful tool for suppressing dissent.

Thailand’s student-led pro-democracy movement ramped up activities in 2020, largely in reaction to the continuing influence of the military in government and hyper-royalist sentiment.

The movement was able to attract crowds of as many as 20,000-30,000 people in Bangkok in 2020 and had followings in major cities and universities.

“There is longstanding evidence showing Pegasus presence in Thailand, indicating that the government would likely have had access to Pegasus during the period in question,” researchers said in the report. The over 30 individuals targeted were also “of intense interest to the Thai government.”

The army in 2014 overthrew an elected government, and Prayuth Chan-ocha, the coup leader, was named prime minister after a 2019 general election put in power a military-backed political party. Protesters have campaigned for Prayuth and his government to step down and demanded reforms to make the monarchy more accountable and to amend the constitution to make it more democratic.

___

AP Technology Writer Zen Soo reported from Hong Kong.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Margrethe Vestager, Executive Vice-President for A Europe Fit for the Digital Age and Competition, ...

Associated Press

US, Europe working on voluntary AI code of conduct as calls grow for regulation

The United States and Europe are drawing up a voluntary code of conduct for artificial intelligence as the developing technology triggers warnings

12 hours ago

FILE - Idaho Attorney General candidate Rep. Raul Labrador speaks during the Idaho Republican Party...

Associated Press

Families sue to block Idaho law barring gender-affirming care for minors

The families of two transgender teenagers filed a lawsuit Thursday to block enforcement of Idaho's ban on gender-affirming medical care for minors.

1 day ago

Amazon agreed Wednesday to pay a $25 million civil penalty to settle Federal Trade Commission alleg...

Associated Press

Amazon fined $25M for violating child privacy with Alexa

Amazon agreed Wednesday to pay a $25 million civil penalty to settle Federal Trade Commission allegations it violated a child privacy law

1 day ago

FILE - Candles are lit on a memorial wall during an anniversary memorial service at the Holy Trinit...

Associated Press

Pain and terror felt by passengers before Boeing Max crashed can be considered, judge rules

Families of passengers who died in the crash of a Boeing 737 Max in Ethiopia can seek damages for the pain and terror suffered by victims in the minutes before the plane flew nose-down into the ground, a federal judge has ruled.

2 days ago

OpenAI's CEO Sam Altman, the founder of ChatGPT and creator of OpenAI speaks at University College ...

Associated Press

Artificial intelligence threatens extinction, experts say in new warning

Scientists and tech industry leaders issued a new warning Tuesday about the perils that artificial intelligence poses to humankind.

2 days ago

Amazon agreed Wednesday to pay a $25 million civil penalty to settle Federal Trade Commission alleg...

Associated Press

Hundreds of Amazon workers protest company’s climate impact, return-to-office mandate

SEATTLE (AP) — Telling executives to “strive harder,” hundreds of corporate Amazon workers protested what they decried as the company’s lack of progress on climate goals and an inequitable return-to-office mandate during a lunchtime demonstration at its Seattle headquarters Wednesday. The protest came a week after Amazon’s annual shareholder meeting and a month after a […]

3 days ago

Sponsored Articles

Internet Washington...

Major Internet Upgrade and Expansion Planned This Year in Washington State

Comcast is investing $280 million this year to offer multi-gigabit Internet speeds to more than four million locations.

Compassion International...

Brock Huard and Friends Rally Around The Fight for First Campaign

Professional athletes are teaming up to prevent infant mortality and empower women at risk in communities facing severe poverty.

Emergency Preparedness...

Prepare for the next disaster at the Emergency Preparedness Conference

Being prepared before the next emergency arrives is key to preserving businesses and organizations of many kinds.

SHIBA volunteer...

Volunteer to help people understand their Medicare options!

If you’re retired or getting ready to retire and looking for new ways to stay active, becoming a SHIBA volunteer could be for you!

safety from crime...

As crime increases, our safety measures must too

It's easy to be accused of fearmongering regarding crime, but Seattle residents might have good reason to be concerned for their safety.

Comcast Ready for Business Fund...

Ilona Lohrey | President and CEO, GSBA

GSBA is closing the disparity gap with Ready for Business Fund

GSBA, Comcast, and other partners are working to address disparities in access to financial resources with the Ready for Business fund.

Researchers say Thai pro-democracy activists hit by spyware