Surveillance Spyware Targeted At Journalists In Mexico

The messages arrived at a familiar moment of crisis for Mexico’s fragile journalist community, another reporter killed in the line of duty.

Javier Valdez, a prominent investigative reporter, had been shot dead only a day earlier. Then came a sudden breakthrough: According to a text message received by his colleagues, his killers had been detained.

Despite the tragedy, his co-workers were suspicious. More than 90 percent of murders go unsolved in Mexico. How did the authorities solve the case so soon?

More likely, they worried, the text messages were an attempt to infiltrate their smartphones, part of a pattern of hacking attempts involving sophisticated spying technology bought by the Mexican government.

They were Right

The messages were infected with a spyware known as Pegasus, which the Mexican government purchased from an Israeli cyber arms dealer called the NSO Group, according to a forensic analysis by the Citizen Lab at the Munk School at the University of Toronto.

A simple click on the links embedded in the messages would have infected the cellphones with spyware powerful enough to break through encrypted messaging, monitor emails and remotely activate the camera and microphone.

Someone was trying to spy on Mr. Valdez’s closest friends and colleagues the day after he was killed last year, most likely the Mexican government, according to those targeted.

“I believe they wanted to search our conversations and messages for clues to the murder of Javier, but we are absolutely against this,” said Ismael Bojórquez, the co-founder and news director of Rio Doce, the news organization where Mr. Valdez worked. 

“Nothing obtained illegally should be used in an investigation, and especially not from those who are involved professionally and emotionally to the victim.”

The illegal use of the surveillance technology in Mexico first emerged during the administration of Mr. Peña Nieto, which bought the spyware on the condition that it be used only to target terrorists and criminals.

But in the last year and a half, the Citizen Lab has confirmed nearly two dozen highly questionable targets, including some of Mexico’s most prominent journalists, human rights lawyers and anticorruption activists.

When news of the surveillance erupted last year, the Mexican government denounced the spying and opened a federal investigation into any misuse of the technology.

But the federal investigation has gone nowhere. Not a single individual has been punished for abusing the system.

Well aware of the scandal, Mr. Bojórquez said he had little faith in the messages he was receiving. He and another target, the news director, Andres Villareal, refused to click on the links. They had reason to be suspicious.

The men were running one of the few independent news groups in the nation, dedicated to covering organized crime and exposing the underbelly of Mexico’s vast nexus of crime and corruption.

Their work made them few friends. Threats came with the territory, and not just from organised crime. Government data show that public officials are responsible for the greatest number of assaults and attacks on journalists.

But Mr. Valdez’s work and international profile, they figured, protected him. He was known and beloved by local and foreign journalists alike, and was the recipient of awards and recognition globally.

His death and the subsequent targeting of newsroom leaders exposed two of the most devastating risks to the freedom of expression in Mexico today.

One is the physical threats to journalists and, by extension, freedom of speech in Mexico. More than 47 journalists have been killed since Mr. Peña Nieto took office in late 2012, 15 of them after Mr. Valdez’s death in May of last year, according to Article 19, a journalist protection group.

“We believed that a journalist as prestigious as Javier was untouchable,” Mr. Bojórquez said.

“When they killed Javier, we understood from that point on that they could kill anyone,” he added. “We understood that the paradigm had been broken.”

The second risk is a separate but connected facet of the rule of law in Mexico: There is essentially near total impunity when it comes to how it is broken or applied, a dynamic underscored by the use of illegal spyware to intimidate and spy on pro-democracy voices.

Dating back to 2016, the target list has been a who’s who of Mexico’s most prominent voices aiming to bring accountability to the nation, including the directors at Rio Doce.

Mr. Bojórquez said he and others had become aware of the government’s potent spyware in February 2017, when the Citizen Lab and The New York Times published articles outlining its illicit use against backers of a nationwide soda tax.

The investigations detailed the purchase of the spyware by the Mexican government, and included details about its proper use. The Israeli company claimed it had sold the software only to governments, and said it had measures in place to ensure that its clients followed the ethical guidelines stipulated in purchasing agreements.

Mexico’s government was deeply embarrassed by the scandal. And yet months after the attempted hacking of doctors and activists promoting a tax on sugary drinks in Mexico, which is suffering a diabetes crisis, the targeting did not stop.

Mexico has become an emblem of problematic use of spyware. In a series of articles in 2017, The Times and the Citizen Lab detailed the extensive use of the malware against journalists, minors, human rights lawyers, politicians and anticorruption activists. It also included critics of the president.

The NSO Group claimed that it monitored abuses of its software and intervened to stop clients from targeting people who did not fall within the permitted categories.

But even after suspicious targeting was unveiled in February 2017, operators in Mexico continued their illicit spying.

A new government comes into office in the next week, arriving on a wave of popular support. But whether the status of journalists will change in the country, and whether their targeting and abuse, and state overreach will subside, is an open question.

“A change in government does not mean there will be a change in the context of impunity or aggressions against journalists,” Mr. Bojórquez said. “If there is no change to the impunity, the murder of journalists will continue.” 

New York Times:

You Might Also Read:

Spyware Proliferates To 45 Countries

« GCHQ Doesn't Always Tell Vendors If Their Software Is Vulnerable
Artificial Intelligence Or Deep Learning? What's The Difference? »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

CyberArk Software

CyberArk Software

CyberArk is an established leader in privileged access management and offers the most complete set of Identity Security capabilities.

TCDI

TCDI

TCDI specializes in computer forensics, eDiscovery and cybersecurity services.

Maticmind

Maticmind

Maticmind is an ICT System Integrator providing solutions and specialized skills in Networking, Security, Unified Communications & Collaboration, Datacenter & Cloud and Application.

authUSB

authUSB

authUSB Safe Door is a tool that provides secure access to the content of USB devices that circulate in organizations.

Cybersec Infohub

Cybersec Infohub

Cybersec Infohub is a Hong Kong government programme to enhance the exchange of cyber security information with industry and enterprises to jointly defend against cyber attacks.

AttackIQ

AttackIQ

AttackIQ delivers continuous validation of your enterprise security program so you can strengthen your security posture and your response capabilities.

Cybil

Cybil

Cybil is a publicly-available portal where members of the international cyber capacity building community can find and share information to support the design and delivery of programs and projects.

Techfusion

Techfusion

Techfusion is a cyber security research and consulting firm focusing on digital forensics and data recovery.

AdaCore

AdaCore

AdaCore is focused on helping developers build safe, secure and reliable software.

Skyhawk Security

Skyhawk Security

Skyhawk Security is the originator of Cloud threat Detection and Response (CDR), helping hundreds of users map and remediate sophisticated threats to cloud infrastructure in minutes.

Emantra

Emantra

Emantra specialises in the enablement of Secure Cloud services through it’s comprehensive Sovereign Cloud Hosting, Secure Access Service Edge, and managed services.

Orca Tech

Orca Tech

Orca Tech brings together a portfolio of complimentary vendor in the IT security industry to help provide a complete solution to meet the requirements of our Partners across all sectors.

Triovega

Triovega

Triovega are a leading provider for production security and efficiency. Our solutions enhance OT security, and reduce production downtime.

403Tech Inc.

403Tech Inc.

403Tech is a Calgary based IT Solutions Provider, specializing in small & medium business.

Synechron

Synechron

Synechron is a leading global digital consulting firm, providing innovative technology solutions for business.

AFINE

AFINE

AFINE is a trusted advisor in the field of cybersecurity and pentesting.