Understanding the Pegasus Spyware Incident Involving Spain and Morocco

The diplomatic and migratory crisis between Spain and Morocco has ignited a flurry of questions that have significantly influenced the dynamics of their bilateral relations. In a recent episode of 'La Linterna,' Ángel Expósito, alongside journalist Gonzalo Zaballa, delved into the complexities surrounding the cyber-espionage incidents affecting various members of the Spanish government. The discussion laid bare the stark realities and uncertainties tied to the malicious activities associated with the Pegasus spyware.

As highlighted by Zaballa during the radio show, the evidence is irrefutable regarding the targeting of Spain's Prime Minister, Pedro Sánchez, whose phone has reportedly been infected multiple times with the Pegasus program. This invasive software allegedly extracted a staggering 2.7 gigabytes of data from his device. Beyond Sánchez, other high-profile officials, including Defense Minister Margarita Robles and Interior Minister Fernando Grande-Marlaska, also suffered similar intrusions, with an unsuccessful attempt aimed at Agriculture Minister Luis Planas. The primary suspect behind these cyber-attacks is believed to be Moroccan intelligence, although conclusive evidence linking Morocco to any form of blackmail against Sánchez has yet to be established.

The Technical Aspects and Implications of Pegasus

Developed by the Israeli company NSO Group, Pegasus is marketed as a tool to combat terrorism, but its application has come under intense scrutiny. Expert Fernando Rueda clarified that only entities authorized by the Israeli Ministry of Defense can utilize this software, primarily selling it to allied intelligence services. Zaballa elaborated on the sophisticated methodology behind the spyware's infection technique, which has evolved to include so-called 'zero-click' attacks. This means that the software can infiltrate a device without any interaction from the user, taking advantage of previously unknown security vulnerabilities.

The capabilities of Pegasus are alarmingly invasive, granting the operator full access to the victim's privacy. It can intercept calls, read messages, access photos, manage contacts, and even tap into cloud storage. There are concerns that it could activate a device's microphone, enabling eavesdropping on conversations held in close proximity to the phone. Such invasive capabilities raise significant ethical and legal questions regarding privacy and state surveillance.

The timeline of these cyber intrusions traces back to May 2021, coinciding with the controversial entry of Brahim Ghali, the leader of the Polisario Front, into Spain. This event triggered a retaliatory response from Morocco, which eased border controls, leading to a surge of migrants entering Ceuta during an official visit from Spain's Prime Minister and the Interior Minister. Following this, the data extraction from Sánchez's phone occurred between May 19 and 21, 2021, with an additional 130 megabytes extracted by the end of the month. Although the National Cryptologic Center has confirmed these intrusions, the content of the intercepted data remains a mystery; as Zaballa succinctly stated, "we know the weight of the loot but not its content."

The Spanish government's acknowledgment of these cyber-attacks did not surface until May 2022, amidst rising public outcry over surveillance of separatist leaders. The most significant political fallout from this scandal was the dismissal of Paz Esteban, the then-director of the National Intelligence Center, who acted under judicial authorization during the surveillance operations. This incident has sparked ongoing debates about Spain's foreign policy, especially in light of its historical shift concerning Western Sahara and the implications of its relations with Morocco. Attempts by the National Court to investigate the authorship of the attacks have faced challenges due to a lack of international cooperation.

As reported by cope.es.