Pegasus spyware, developed by Israel-based NSO Group, has been revealed through a Moroccan intelligence insider to have been used extensively by the country's domestic security service against journalists, human rights defenders, and foreign politicians. The whistleblower, known as Safir, provided unprecedented testimony detailing how the DGST deployed this powerful hacking tool from 2017 onward, targeting everything from French politicians to Spanish cabinet ministers and police officers.
Pegasus spyware allows operators to remotely access a target's mobile phone, reading emails, text messages, and photos, while also activating the device's microphone and camera to turn it into a live listening device. NSO Group claims the software is sold exclusively to governments for tracking criminals and terrorists, yet multiple countries have been accused of using it to silence dissidents and journalists. Morocco has consistently denied any involvement, but the evidence from Safir, combined with technical analysis from Amnesty International's Security Lab, paints a different picture.
Get the #1 Wireless Door Camera
REOLINK Bestseller: 2K Weatherproof Video Doorbell, No Monthly Fees.
How Pegasus Spyware Works and Its Impact
Pegasus spyware operates by exploiting vulnerabilities in smartphone operating systems, often requiring no user interaction to install. Once installed, it can exfiltrate data in real-time, making it one of the most dangerous surveillance tools available. The Moroccan case highlights how governments can abuse such technology to suppress free speech and target political opponents.
The investigation, coordinated by Forbidden Stories and involving 14 media organizations including Le Monde and The Guardian, analyzed leaked emails, targeting records, and victim testimonies. This collaborative effort has shed light on the scale of surveillance, revealing that Moroccan intelligence targeted not only domestic critics but also foreign officials, raising serious diplomatic concerns.
Key Takeaways from the Investigation
- Pegasus spyware was used by Moroccan intelligence from 2017 to 2021 against a wide range of targets.
- Victims included journalists, human rights defenders, French politicians, and Spanish cabinet ministers.
- The whistleblower, Safir, worked for the DGST for nearly a decade before revealing the details.
- Technical support from Amnesty International's Security Lab confirmed the spyware's deployment.
- Morocco continues to deny any relationship with NSO Group, despite mounting evidence.
Comparison of Spyware Capabilities
| Feature | Pegasus Spyware | Other Commercial Spyware |
|---|---|---|
| Remote Installation | Yes, via zero-click exploits | Often requires user action |
| Data Access | Emails, texts, photos, microphone, camera | Limited to specific apps |
| Targeting | Governments claim counter-terrorism | Often used for corporate espionage |
| Detection | Extremely difficult | Some detectable by security software |
The comparison shows that Pegasus spyware is uniquely invasive, with capabilities that far exceed typical surveillance tools. This makes it a preferred choice for governments seeking to monitor high-value targets without leaving traces.
FAQ
What is Pegasus spyware?
Pegasus spyware is a mobile surveillance tool developed by NSO Group that allows operators to remotely access a target's phone, including emails, messages, photos, and even the microphone and camera.
How did the Moroccan insider reveal Pegasus use?
A former DGST member, using the pseudonym Safir, provided testimony to journalist Hicham Mansouri, detailing how Morocco used Pegasus from 2017 to target journalists, politicians, and human rights defenders.
Is Pegasus spyware legal?
While NSO Group sells Pegasus only to governments for legal purposes like counter-terrorism, its use against journalists and dissidents is widely considered illegal and a violation of human rights.
This revelation underscores the urgent need for stronger cybersecurity measures and international regulations to prevent the abuse of spyware like Pegasus. Individuals can protect themselves by keeping software updated, avoiding suspicious links, and using end-to-end encryption for sensitive communications.