Amnesty International has attributed the espionage incident involving the Pegasus spyware in 2021 to the Moroccan intelligence services, specifically targeting the official phones of Spain's Minister of Defense, Margarita Robles, and Minister of the Interior, Fernando Grande-Marlaska. The 126-page report, released recently and titled 'We Start with the Verdict', identifies the Direction Générale de Surveillance du Territoire (DGST), Morocco's internal intelligence agency, as the client of the NSO Group that operated the spyware system. It further claims that the same attack infrastructure assigned to Rabat was utilized against activists, journalists, and politicians in France, in addition to compromising the devices of the two Spanish ministers.

The organization, while cautious about definitively linking Rabat to the information theft from Prime Minister Pedro Sánchez’s mobile device due to missing key data, concludes that the findings provide "solid material evidence that Morocco was ultimately responsible" for an extensive cross-border campaign using Pegasus against critical journalists, activists, lawyers, and politicians. This conclusion is among the most compelling assertions made by Amnesty regarding one of the significant uncertainties surrounding the Pegasus case in Spain: who was behind the massive information theft from government officials’ phones.

The report asserts that independent investigations conducted in France and Spain determined that "the attacking accounts assigned to Morocco's Pegasus system" were the same used to infect the devices of high-ranking Spanish officials during the diplomatic crisis with Rabat in May and June of 2021. During this period, Sánchez experienced two infections with Pegasus, although these did not have the same forensic traceability as those of Robles and Marlaska.

At the core of the technical details lies a specific account: linakeller2203@gmail.com. This iMessage account, linked by investigators to the attack infrastructure of the Moroccan Pegasus client, appears in the infections suffered in 2021 by French activist Claude Mangin and exiled Moroccan journalist Hicham Mansouri. Amnesty highlights the significance of this coincidence, noting that the NSO Group created a separate infrastructure for each client. A team within the company known as "White Services" specifically registered distinct email addresses, Apple accounts, domains, and servers for each operator.

This architecture has now become a critical fingerprint. According to the report, "Amnesty International has never observed that a particular attacking account or infection domain was used by more than one client." Thus, the repetition of the same account across multiple phones allows investigators to group the attacks and attribute them to a single operator. The French investigation provides a second confirmation pathway. The French cybersecurity agency ANSSI examined attacked devices in France and identified the same group of Apple accounts used to launch Pegasus. This information later reached Spain through a European Investigation Order.

Amnesty asserts that the forensic evidence and independent findings from French authorities show that many individuals selected for surveillance under the Pegasus Project were ultimately infected using a common set of iMessage accounts. The same account used in 2021 against Mangin and Mansouri, linakeller2203@gmail.com, was also identified in Spanish judicial documentation as the Apple account used in zero-click attacks that compromised the phones of Spain's Minister of the Interior and Minister of Defense.

However, the report exercises caution regarding Pedro Sánchez. His phone was also compromised with Pegasus during the same timeframe, but Spanish judicial documentation does not specify the iMessage account that enabled the infection. Thus, the report does not establish a direct forensic link for Sánchez as it does for Robles and Marlaska. His phone suffered the extraction of 2.6 gigabytes and 130 megabytes of information.

The attacks occurred during the most critical period of relations between Madrid and Rabat in decades. In April 2021, Spain had hosted the leader of the Polisario Front, Brahim Ghali, for medical treatment. On May 17 and 18, thousands crossed from Morocco into Ceuta. Sánchez's phone was infected on May 19 and 31, leading to the aforementioned data breaches. Robles was targeted in June, resulting in the extraction of nine megabytes, while Grande-Marlaska experienced two infections that month, with one resulting in over six gigabytes of data theft.

Amnesty explicitly distinguishes between being targeted and being infected. The Pegasus Project database contains thousands of numbers entered by program clients as potential targets, but "only forensic analysis of the target devices can confirm with certainty that a number selected for attack with Pegasus was infected." In the Spanish case, the organization argues that the evidentiary leap is provided precisely by those forensic analyses, the temporal coincidence between the selection of specific targets, and, importantly, the reuse of specific attack accounts from the Moroccan client.

Amnesty identifies the DGST with a "high degree of confidence" as the "end user responsible for the use of Pegasus" against Moroccan and Sahrawi civil society and for surveillance operations conducted outside of Morocco and Western Sahara. The investigation cross-references internal NSO Group material made public during the litigation of WhatsApp and Meta against the Israeli company, leaked surveillance records, forensic analyses, and the testimony of a former DGST member identified by the pseudonym Safir. "We never started with Pegasus. It is the weapon of the monster," this former agent stated, describing the use of the program as the last rung of a much broader surveillance system.

Amnesty maintains that each NSO client utilized their own infrastructure, allowing for the technical attribution of attacks. By reanalyzing the original records of the Pegasus Project, Amnesty located nearly 13,000 unique numbers selected as potential targets by the Moroccan client, identified as the DGST. This was the largest client found in that database by the number of unique targets. Between September and December 2017, researchers linked 103 Moroccan phones to specific individuals, of which 65 belonged to civil society: 34 human rights defenders, 22 journalists or media workers, five lawyers, and four academics.

Amnesty notes that the numbers of prominent human rights defenders and journalists were among the first entered into the Pegasus system, indicating that monitoring civil society members "was a central and not incidental purpose" of the DGST's acquisition of the program. The deployment soon crossed borders, with the first foreign number located in the Moroccan system appearing in April 2018, followed by French and Spanish phones. The first Spanish number selected by the DGST, according to the report, was on May 11, 2018, and was associated with Sahrawi activist Aminatou Haidar, whose device Amnesty later confirmed had been infected by Morocco.

Amnesty's investigation has uncovered leads that had already emerged in the Spanish investigation. Reports revealed that information sent from France had detected the account linakeller2203@gmail.com in the attacks against Robles and Marlaska, as well as in those suffered by Mangin, Mansouri, Sahrawi diplomat Oubi Buchraya Bachir, and Philippe Bouyssou, mayor of Ivry-sur-Seine and activist for the Sahrawi cause. The analyses conducted at that time by the National Cryptologic Center noted "multitudes" of parallels, but the judicial investigation continued without being able to identify a specific responsible party.

The Spanish National Court provisionally shelved the case for the second time on January 22. Judge José Luis Calama explained that the "frustration of execution" of the rogatory commissions sent to Israel, the headquarters of NSO Group, "prevents investigation into the attribution of responsibility for the investigated facts to any specific person." The case had already been closed in July 2023 due to a lack of Israeli cooperation and was reopened in April 2024 following the arrival of new data from France.

As reported by elcorreo.com.