Unveiling Morocco's Use of Pegasus Software
A recent report from Amnesty International sheds light on Morocco's extensive use of the Pegasus spyware beyond its borders, targeting various individuals, including Moroccan activists, journalists, lawyers, military officials, diplomats, and political leaders across Europe, with a specific focus on France and Spain. The 126-page document meticulously outlines the methods employed by Morocco to surveil and monitor its interests, emphasizing the notable presence of Spain throughout its findings. The Israeli software, Pegasus, which compromised the mobile devices of several ministers, plays a central role in the analysis.
The report reveals that the first Spanish phone targeted by Morocco's General Directorate of Territorial Surveillance (DGST) was linked to Sahrawi human rights defender Aminatou Haidar. Forensic analysis conducted by Amnesty confirmed that her device was infected with Pegasus on May 11, 2018. By the end of that year, the number of Spanish phones infected with Pegasus had also increased significantly, facilitated by a 'zero-click' policy that allowed the software to be installed without requiring the phone owner to click on a malicious link.
Targeted Infiltrations and Rising Concerns
The report details that in 2019, the frequency of incursions into selected phone numbers and profiles considered sensitive by the Moroccan regime surged. On February 25, an activist's phone, who led a pro-independence association for Western Sahara, was targeted, followed by that of Moroccan journalist Hussein Majdoubi, residing in Spain, on March 5. On the same day, Spanish journalist Ignacio Cembrero's device was also selected for infiltration.
Furthermore, a judicial document revealed that WhatsApp identified a range of phone numbers subjected to attacks during this timeframe, including 69 Moroccan, 39 Algerian, 21 Spanish, and 7 French numbers. While the report refrains from definitively linking the hacking of Spanish Prime Minister Pedro Sánchez's phone to Morocco, it does indicate that devices belonging to the Ministers of Defense, Agriculture, and Interior were compromised. Amnesty International even provides a graphic identifying the iMessage link through which the spyware was allegedly installed, attributing it to the email address linakeller2203@gmail.com. The report notes that Amnesty International has never observed the same attacking account or infection domain being used by more than one client, leading researchers to conclude that the recurrence of a single account across multiple phones allows for the grouping of attacks and attribution to the same operator.
The attacks on ministerial phones occurred in 2021, three years after Morocco began infiltrating the mobile devices of Spanish citizens. This timeline coincides with one of the most profound diplomatic crises between Madrid and Rabat, triggered by Spain's decision to host Brahim Ghali, the leader of the Polisario Front, for medical treatment. Morocco's response included a significant surge of around 20,000 individuals crossing the Tarajal border, resulting in a severing of diplomatic relations.
As reported by elmundo.es.