Surveillance Spyware Targeted At Journalists In Mexico

The messages arrived at a familiar moment of crisis for Mexico’s fragile journalist community, another reporter killed in the line of duty.

Javier Valdez, a prominent investigative reporter, had been shot dead only a day earlier. Then came a sudden breakthrough: According to a text message received by his colleagues, his killers had been detained.

Despite the tragedy, his co-workers were suspicious. More than 90 percent of murders go unsolved in Mexico. How did the authorities solve the case so soon?

More likely, they worried, the text messages were an attempt to infiltrate their smartphones, part of a pattern of hacking attempts involving sophisticated spying technology bought by the Mexican government.

They were Right

The messages were infected with a spyware known as Pegasus, which the Mexican government purchased from an Israeli cyber arms dealer called the NSO Group, according to a forensic analysis by the Citizen Lab at the Munk School at the University of Toronto.

A simple click on the links embedded in the messages would have infected the cellphones with spyware powerful enough to break through encrypted messaging, monitor emails and remotely activate the camera and microphone.

Someone was trying to spy on Mr. Valdez’s closest friends and colleagues the day after he was killed last year, most likely the Mexican government, according to those targeted.

“I believe they wanted to search our conversations and messages for clues to the murder of Javier, but we are absolutely against this,” said Ismael Bojórquez, the co-founder and news director of Rio Doce, the news organization where Mr. Valdez worked. 

“Nothing obtained illegally should be used in an investigation, and especially not from those who are involved professionally and emotionally to the victim.”

The illegal use of the surveillance technology in Mexico first emerged during the administration of Mr. Peña Nieto, which bought the spyware on the condition that it be used only to target terrorists and criminals.

But in the last year and a half, the Citizen Lab has confirmed nearly two dozen highly questionable targets, including some of Mexico’s most prominent journalists, human rights lawyers and anticorruption activists.

When news of the surveillance erupted last year, the Mexican government denounced the spying and opened a federal investigation into any misuse of the technology.

But the federal investigation has gone nowhere. Not a single individual has been punished for abusing the system.

Well aware of the scandal, Mr. Bojórquez said he had little faith in the messages he was receiving. He and another target, the news director, Andres Villareal, refused to click on the links. They had reason to be suspicious.

The men were running one of the few independent news groups in the nation, dedicated to covering organized crime and exposing the underbelly of Mexico’s vast nexus of crime and corruption.

Their work made them few friends. Threats came with the territory, and not just from organised crime. Government data show that public officials are responsible for the greatest number of assaults and attacks on journalists.

But Mr. Valdez’s work and international profile, they figured, protected him. He was known and beloved by local and foreign journalists alike, and was the recipient of awards and recognition globally.

His death and the subsequent targeting of newsroom leaders exposed two of the most devastating risks to the freedom of expression in Mexico today.

One is the physical threats to journalists and, by extension, freedom of speech in Mexico. More than 47 journalists have been killed since Mr. Peña Nieto took office in late 2012, 15 of them after Mr. Valdez’s death in May of last year, according to Article 19, a journalist protection group.

“We believed that a journalist as prestigious as Javier was untouchable,” Mr. Bojórquez said.

“When they killed Javier, we understood from that point on that they could kill anyone,” he added. “We understood that the paradigm had been broken.”

The second risk is a separate but connected facet of the rule of law in Mexico: There is essentially near total impunity when it comes to how it is broken or applied, a dynamic underscored by the use of illegal spyware to intimidate and spy on pro-democracy voices.

Dating back to 2016, the target list has been a who’s who of Mexico’s most prominent voices aiming to bring accountability to the nation, including the directors at Rio Doce.

Mr. Bojórquez said he and others had become aware of the government’s potent spyware in February 2017, when the Citizen Lab and The New York Times published articles outlining its illicit use against backers of a nationwide soda tax.

The investigations detailed the purchase of the spyware by the Mexican government, and included details about its proper use. The Israeli company claimed it had sold the software only to governments, and said it had measures in place to ensure that its clients followed the ethical guidelines stipulated in purchasing agreements.

Mexico’s government was deeply embarrassed by the scandal. And yet months after the attempted hacking of doctors and activists promoting a tax on sugary drinks in Mexico, which is suffering a diabetes crisis, the targeting did not stop.

Mexico has become an emblem of problematic use of spyware. In a series of articles in 2017, The Times and the Citizen Lab detailed the extensive use of the malware against journalists, minors, human rights lawyers, politicians and anticorruption activists. It also included critics of the president.

The NSO Group claimed that it monitored abuses of its software and intervened to stop clients from targeting people who did not fall within the permitted categories.

But even after suspicious targeting was unveiled in February 2017, operators in Mexico continued their illicit spying.

A new government comes into office in the next week, arriving on a wave of popular support. But whether the status of journalists will change in the country, and whether their targeting and abuse, and state overreach will subside, is an open question.

“A change in government does not mean there will be a change in the context of impunity or aggressions against journalists,” Mr. Bojórquez said. “If there is no change to the impunity, the murder of journalists will continue.” 

New York Times:

You Might Also Read:

Spyware Proliferates To 45 Countries

« GCHQ Doesn't Always Tell Vendors If Their Software Is Vulnerable
Artificial Intelligence Or Deep Learning? What's The Difference? »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Lloyd's

Lloyd's

As an insurance market, Lloyd’s can provide access to more than 65 expert cyber risk insurers in one place.

Hedgehog Security

Hedgehog Security

The key objective of Hedgehog is to provide simple, effective and affordable information security improvements that support your drive to increase productivity and profitability.

ESL Bangladesh

ESL Bangladesh

ESL is the Largest IT Infrastructure & Telecom Service Provider in Bangladesh.

Garland Technology

Garland Technology

Garland Technology specializes in network access points (TAPs) for 100% visibility allowing you to see every bit, byte, and packet flowing through your network.

Trusted Objects

Trusted Objects

Trusted Object's mission is to provide state of the art security solutions and services enabling a strong root of trust for the IoT ecosystem.

LogicHub

LogicHub

LogicHub is built on the principle that every decision process for threat detection and response can and should be automated.

Blaick Technologies

Blaick Technologies

Blaick is an Israeli cyber-security company which deploys proprietary Artificial Intelligence threats detection technology for early prevention of online cyber crime.

Alacrinet

Alacrinet

Alacrinet is an IT and cyber security consultancy. From penetration testing to fully managed MSSP, our team is focused on knowing the latest threats, preventing vulnerabilities, and providing value.

Sentrium Security

Sentrium Security

Sentrium is committed to helping organisations protect their technology, information and people. Our range of bespoke services provide solutions to tackle a broad range of cyber security challenges.

NetBlocks

NetBlocks

NetBlocks is a global internet monitor working at the intersection of digital rights, cyber-security and internet governance.

eCapital

eCapital

eCAPITAL is a leading venture capital firm that provides early to growth stage funding to technology companies in fields including software & information technology, cybersecurity and industry 4.0.

Deloitte

Deloitte

Deloitte is a multinational professional services firm providing audit, consulting, financial advisory, risk management, tax, and related services to clients.

NetRise

NetRise

NetRise was founded as a direct result of the many shortcomings currently in the device security market, specifically targeting the firmware of devices.

Cytex

Cytex

Cytex is the All-in-One solution for SMB data protection & compliance needs.

Synergy ECP

Synergy ECP

Synergy ECP has a talented, dedicated staff to provide a broad range of services to the defense and intelligence industries.

Algoritha

Algoritha

Algoritha is a pioneering entity in the realm of security and forensic services.