Security researchers have reported the first known case of NSO Group spyware being used in a military conflict. Journalists, human rights defenders, a United Nations official, and members of civil society in Armenia were allegedly hacked by a government using NSO Group's Pegasus spyware

The hacking campaign targeted at least a dozen victims from October 2020 to December 2022, and according to researchers, appears to be closely linked to the long-running military conflict between Armenia and Azerbaijan.
Previous investigations into spyware abuses by NSO Group customers have shown that Azerbaijan is likely a government customer of the company.
See also: Did the Hellenic Police spy on Meta's director with Predator Spyware?
This news is significant because the use of Pegasus spyware has never been detected in a military conflict before. This spyware infects devices and allows its operators to control them remotely. It is a dangerous piece of software that governments can use to spy on individuals. Since it is highly sophisticated and can remain undetected, it is easy for governments to use it to undermine their adversaries.
The research was conducted by researchers from Access Now, CyberHUB-AM, Citizen Lab, Munk School of Global Affairs at the University of Toronto, Amnesty International , and Ruben Muradyan, an independent security researcher.
The breach of the victims' devices based in Armenia was discovered for the first time in November 2021, two months after a series of clashes along the Armenia-Azerbaijan border that cost 200 lives.
Apple has sent notifications to mobile phone users who were targeted with Pegasus spyware. Anna Naghdalyan , a former spokeswoman for the Armenian Foreign Ministry, was hacked at least 27 times from October 2020 to July 2021. At the time, she was serving as a spokeswoman for the ministry.
The investigators say the attacks took place during discussions and negotiations related to the Nagorno-Karabakh crisis, including mediation efforts and efforts to find a solution by France, Russia and the United States, as well as during official visits to Moscow and Karabakh.
See also: Thai activists hacked by NSO Group's Pegasus spyware
Naghdalyan said to Access Now that, during the hacking, she had on her phone all the information regarding the developments of the war and that she now finds it difficult to feel completely safe.

“Even if you have the most secure system on your phone, you can’t be safe,” he said.
“This raises significant questions about the safety of international organizations, journalists, humanitarians and others working around conflicts. It should also be of concern to any foreign government whose diplomatic service has been involved in the conflict,” said John Scott-Railton, senior researcher at Citizen Lab.
Other victims of Pegasus spyware include Karlen Aslanyan, a Radio Azatutyun journalist who covered the Armenian political crisis that erupted after Armenia’s defeat in the 2020 conflict. At least one guest on Aslanyan’s popular Armenian show – Kristinne Grigoryan – was also affected a month after appearing on the program. Another journalist, Astghik Bedevyan, who covered the conflict closely, was also hacked in May 2021. The report names several other journalists, professors, and human rights defenders whose work focused on the military conflict.
Access Now said that five of the 12 individuals who have been breached want to remain anonymous.
Access Now and its partners stated that they believe the intrusion was carried out by a client of the NSO Group, although the data could not be linked to a specific client.
See also: Pedro Sánchez: Pegasus spyware detected on Spanish Prime Minister's phone
Even the Armenian government would be interested in hacking some people, but according to researchers there is no other evidence to suggest that Armenia has ever been a user of Pegasus. The country is believed to be using another spyware called Predator.
Other evidence points to Azerbaijan as a customer of NSO Group. For example, domains linked to Azerbaijan have been identified, suggesting the country may be a user of the Pegasus spyware.
NSO said it was investigating credible reports of abuse of its spyware by government customers. NSO Group was blacklisted by the Biden administration in 2021 after the Commerce Department found that the company had supplied its technology to foreign governments that used it to target government officials, journalists, businesspeople, activists and embassy workers
Source: www.theguardian.com
