Amazon kicks NSO off cloud after cyber spy reports

By Laura Berrill
Pegasus hacking tool used AWS as part of its cyber spyware services to government clients

Amazon has now deactivated the cloud computing accounts that researchers say have been associated with NSO Group, a cyber hacking tools company that reportedly used Amazon Web Services as part of spyware systems. These were in turn used by governments to surveil phones.

The removal came about as a result of research by forensic investigators at Amnesty International, who discovered the Israeli company’s Pegasus software on journalists’ and activists’ phones and at times using AWS systems to operate. The researchers at Citizen Lab, which analyses spyware at the University of Toronto, confirmed Amnesty’s discovery that the hacking tools were operating on AWS’ CloudFront - a content delivery network product.

Amnesty’s report reveals Amazon had told its researchers back in May that it had moved fast to get the hacking activity off its systems. According to a report in the New York Times, the Pegasus spyware can access and record texts, videos, photos and web activity; as well as recording and scraping passwords on a device. It is designed to work both on iPhones and some Android.

Cyber spyware aimed at targeting journalists and activists

An NSO Group spokesperson said that the claims were false then added it referred to the claim that AWS had removed its accounts. NSO added it would investigate the findings that its products had been used to spy on activists and journalists. Some phones which were reviewed showed signs they had been breached with the spyware multiple times.

The spyware worked by redirecting the phones’ owners to websites that would automatically download the spyware, away from the original common website they had initially visited. Some targets’ devices were infected when they received a text message containing a ‘zero-click’ attack, meaning the owner doesn’t have to click on a malicious link for the hack to take place. The reported attacks took place through iMessage, a method previously reported to have been used to hack the phones of Al-Jazeera journalists. The NSO had denied these claims.

Amazon’s decision to end support for the hacking activity comes in the same year that AWS removed accounts belonging to social media service, Parler which it said had contained various slurs.

Share

Featured Articles

Orange cyber report: highest number of victims ever recorded

Orange Cyberdefense's Security Navigator 2024 reveals the highest number of cyber extortion victims recorded, with an increase of 46% worldwide in 2023

ChatGPT turns one: How AI chatbot has changed the tech world

One year on from its launch, OpenAI's groundbreaking language model ChatGPT continues to transform and evolve with ever-increasing capabilities

AWS announces AI tool Amazon Q to reimagine future of work

AWS has announced Amazon Q, a generative AI-powered assistant empowering businesses unlock the potential of AI for every employee

Deloitte & IBM: Data solutions driving tech sustainability

Data & Data Analytics

Carlsberg Group is using IoT to make data-driven decisions

Data & Data Analytics

Capgemini: Gen AI accelerating software-led transformations

Enterprise IT