BRUSSELS — As the number of politicians, activists and journalists hacked with spyware grew to include prime ministers and prominent dissidents from the European Union, the world’s largest democratic club, the European Parliament began in April to check the phones of its members.
About 200 devices, it reached its first positive.
A high-level Greek member of the European Parliament and leader of a major opposition party was the target of malicious spyware last year, a scan of his phone by the parliament’s technology experts has revealed.
Politician Nikos Androulakis, who late last year became the leader of Greece’s third-largest political party, the centre-left PASOK-KINAL, submitted his personal mobile device to the new software detection technology lab European Parliament spies in Brussels.
Late last month, experts informed Mr Androulakis that in September 2021, weeks after he said he would be a candidate to lead the opposition party at home, he received a text message with a link that allegedly installed Predator spyware, more clumsy software. version of the famous Pegasus spyware, on his phone, he had clicked on it.
“Let’s take a serious look mate, there’s something to be gained,” read the text in Greek, followed by the link.
Mr. Androulakis, not recognizing the sender, did not take the bait and his phone was therefore not infected.
The discovery of the attempt, following cases in Spain, Hungary and Poland, has heightened concerns that even in a bloc that claims to be the global standard bearer for democracy and the rule of law, this technology is used for nefarious political purposes.
The European Commission, the executive arm of the EU, has referred the matter to national authorities, but pressure on it to act has intensified, not least because its own staff have been targeted by spyware.
In a letter to a member of the European Parliament dated July 25 and seen by The New York Times, the European Commission said its top justice official Didier Reynders and a number of his aides had received alerts from Apple in November stating that their phones had been compromised by Spyware. The infection alert and letter were first reported by Reuters.
In the letter to Sophie in ‘t Veld, a Dutch lawmaker who chairs the European Parliament’s special committee on spyware, the European Commission said its own experts were unable to confirm the infection but had found “several indicators of compromise” and couldn’t find out who was behind them.
“Governments buy this material and it is very, very difficult for them to resist the temptation to use it for political purposes,” Ms in ‘t Veld said.
“It’s too early to tell what’s going on here, but it doesn’t look good, does it?” she said of the case of Mr. Androulakis. “It doesn’t matter if the phone was not compromised, the political fact is that there was an attempt,” she added.
The Greek government said in a statement on Monday that authorities should urgently investigate the case. He strongly denied using Predator.
The Predator software is marketed by a company called Cytrox, based in North Macedonia. The company’s website is outdated, and no one immediately responded to an email request for comment.
Meta and Google have documented the use of realistic links, which mimic traditional Greek websites, used to infect personal mobile devices with the spyware. The link sent to Mr. Androulakis came from one of the fake websites registered by Meta. The attempt came shortly after a similar effort to infect the phone of Thanasis Koukakis, a Greek investigative journalist, although a text message was successful after Mr Koukakis clicked on the link.
The Greek government in April denied being the source of Mr Koukakis’ phone infection.
Mr Androulakis, the Greek opposition leader, filed a complaint with Greece’s highest court on Monday in an attempt to compel the Greek authorities to investigate.
“Revealing who is behind these appalling practices and for whom they are acting is not a personal matter, it is a democratic duty,” Mr Androulakis said after filing the lawsuit in Athens.
Citizen Lab, the world’s leading spyware experts, based at the University of Toronto, said in a report on Predator that the governments of Egypt, Greece, Indonesia, Madagascar and Saudi Arabia , among others, “are likely among Cytrox’s customers”. The lab said it is highly unlikely that companies or individuals could have purchased the spyware, which costs hundreds of thousands of dollars.
Predator spyware is a less sophisticated version of Pegasus, software that was developed by the Israeli company NSO Group, supposedly to help governments catch criminals and terrorists. The software allows users to monitor all aspects of a target’s phone including calls, messages, photos and videos. Predator asks the target to click on a link; Pegasus no.
In November, the Biden administration blacklisted the NSO Group, saying it knowingly provided spyware that has been used by foreign governments to target dissidents, human rights activists, journalists and others. Around the same time, Apple sued NSO to prevent it from infecting iPhones; Meta (then Facebook) also sued NSO in 2019 for attempting to infect users via WhatsApp.
Last year, a forensic investigation by Citizen Lab, Amnesty International and an international consortium of media organizations revealed that several governments, including members of the European Union, had deployed Pegasus to spy on dozens of their own citizens.
The European Parliament began investigating the allegations and, during a visit to Israel, discovered that at least 14 EU governments had purchased Pegasus, with two of those contracts terminated by the NSO Group. Chaim Gelfand, NSO’s general counsel and chief compliance officer, said at least one of those dismissals was because the government was using the software for “purposes other than fighting serious crime and terrorism. “.
“Every customer we sell to, we do due diligence in advance to assess the rule of law in that country,” Gelfand told the committee last month.
Citizens of at least six EU countries have been targeted by spyware, according to a recent study commissioned by EU lawmakers. Among those hacked were Spain’s prime minister, Pedro Sánchez, and the country’s defense minister. Others targeted include Charles Michel, Belgian Prime Minister at the time, Mr Reynders, a senior EU justice official, and French President Emmanuel Macron.
In Hungary, the authorities targeted at least 39 people, including journalists, with the Pegasus software, according to the investigative newspaper Direkt36. An official investigation concluded that the Hungarian government acted lawfully.
The Polish government confirmed in January that it had acquired Pegasus, but denied accusations that it was using it to spy on government critics, despite local media reports of dozens of hacks.
In Spain, a Citizen Lab report, confirmed by Amnesty International forensic research, found that several Catalan public figures had been targeted by surveillance software, mainly after the failed 2017 independence referendum. of Catalonia.