{"id":42292,"date":"2021-07-20T15:31:56","date_gmt":"2021-07-20T15:31:56","guid":{"rendered":"http:\/\/icloud.pe\/blog\/?guid=522ca652f4e70e3eee902c3c75bd4394"},"modified":"2021-07-20T15:31:56","modified_gmt":"2021-07-20T15:31:56","slug":"aws-shuts-down-nso-group-infrastructure","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/aws-shuts-down-nso-group-infrastructure\/","title":{"rendered":"AWS shuts down NSO Group infrastructure"},"content":{"rendered":"<p><span class=\"field field-name-field-author field-type-node-reference field-label-hidden\"><br \/>\n      <span class=\"field-item even\"><a href=\"https:\/\/www.cloudpro.co.uk\/authors\/sabina-weston\">Sabina Weston<\/a><\/span><br \/>\n  <\/span><\/p>\n<div class=\"field field-name-field-published-date field-type-datetime field-label-hidden\">\n<div class=\"field-items\">\n<div class=\"field-item even\"><span class=\"date-display-single\">20 Jul, 2021<\/span><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"short-teaser\">\n<a href=\"https:\/\/www.cloudpro.co.uk\/\" title=\"\" class=\"combined-link\"><\/a><\/p>\n<div class=\"field field-name-body\">\n<p><a href=\"https:\/\/www.itpro.co.uk\/amazon-web-services-aws\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/amazon-web-services-aws\">Amazon Web Services (AWS)<\/a> has shut down infrastructure and accounts linked to Israeli firm <span class=\"scayt-misspell-word\" data-scayt-word=\"NSO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7hz3co851b4840\">NSO<\/span> Group.<\/p>\n<p>The news comes after\u00a0<a href=\"https:\/\/www.itpro.co.uk\/security\/spyware\/360276\/journalists-human-rights-activists-targeted-with-pegasus-spyware\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/security\/spyware\/360276\/journalists-human-rights-activists-targeted-with-pegasus-spyware\">an investigation<\/a> found that the company\u2019s Pegasus <a href=\"https:\/\/www.itpro.co.uk\/spyware\/30001\/what-is-spyware\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/spyware\/30001\/what-is-spyware\">spyware<\/a> was used to target at least 50,000 journalists, government and union officials, human rights activists, business executives, religious figures, academics, <span class=\"scayt-misspell-word\" data-scayt-word=\"NGO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i2yi2lrbhmb9a\">NGO<\/span> employees, and lawyers.<\/p>\n<p>Pegasus was used to extract messages, photos, and <a href=\"https:\/\/www.itpro.co.uk\/network-internet\/email-providers\/358887\/the-most-secure-email-services-of-2021\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/network-internet\/email-providers\/358887\/the-most-secure-email-services-of-2021\">emails<\/a>, as well as to record calls and activate microphones on <a href=\"https:\/\/www.itpro.co.uk\/operating-systems-software\/ios\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/operating-systems-software\/ios\">iOS<\/a> and <a href=\"https:\/\/www.itpro.co.uk\/google-android\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/google-android\">Android<\/a> devices.<\/p>\n<p><span class=\"scayt-misspell-word\" data-scayt-word=\"NSO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i3yp5g85iwsto\">NSO<\/span> Group denied the accusations, stating that its tools are used \u201cfor the sole purpose of saving lives through preventing crime and terror acts\u201d.<\/p>\n<p>\u201cOur technologies are being used every day to break up <span class=\"scayt-misspell-word\" data-scayt-word=\"pedophilia\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i4hvldg4ngxj5\">pedophilia<\/span> rings, sex and drug-trafficking rings, locate missing and kidnapped children, locate survivors trapped under collapsed buildings, and protect airspace against disruptive penetration by dangerous drones,\u201d the company announced.<\/p>\n<p>However, <span class=\"scayt-misspell-word\" data-scayt-word=\"AWS\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i5hw6me5j70cz\">AWS<\/span> has branded <span class=\"scayt-misspell-word\" data-scayt-word=\"NSO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i5hwxbx9fnpek\">NSO<\/span> Group\u2019s actions as \u201chacking activity\u201d.<\/p>\n<p>A spokesperson for the cloud computing provider told I<em>T Pro<\/em> that it had shut down <span class=\"scayt-misspell-word\" data-scayt-word=\"NSO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i69l29wxi1qu1\">NSO<\/span> Group\u2019s infrastructure as it \u201cwas confirmed to be supporting the reported hacking activity\u201d.<\/p>\n<p>This was \u201cin accordance with [<span class=\"scayt-misspell-word\" data-scayt-word=\"AWS\u2019\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i71av4eq3zbkw\">AWS\u2019<\/span>] terms of use\u201d, they added.<\/p>\n<p>Amnesty International, a partner of the Pegasus Project, a collective of 17 media organisations investigating the spyware, found evidence to suggest that <span class=\"scayt-misspell-word\" data-scayt-word=\"NSO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i7t7a7muh2efb\">NSO<\/span> Group had only been an <span class=\"scayt-misspell-word\" data-scayt-word=\"AWS\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i7t6viubgsit0\">AWS<\/span> customer for a few months.<\/p>\n<p>One\u00a0Pegasus-infected phone\u00a0that was dissected by the organisation sent data &#8220;to a service fronted by Amazon <span class=\"scayt-misspell-word\" data-scayt-word=\"CloudFront\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7hzvempz09pzzt\">CloudFront<\/span>, suggesting <span class=\"scayt-misspell-word\" data-scayt-word=\"NSO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7hzvdoehc4csme\">NSO<\/span> Group has switched to using <span class=\"scayt-misspell-word\" data-scayt-word=\"AWS\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7hzvd3jr2v7ne1\">AWS<\/span> services in recent months\u201d.<\/p>\n<p><a href=\"https:\/\/www.itpro.co.uk\/cloud\/cloud-computing\/359498\/aws-makes-cloudfront-functions-generally-available\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/cloud\/cloud-computing\/359498\/aws-makes-cloudfront-functions-generally-available\">Amazon CloudFront<\/a> is a content delivery network (<span class=\"scayt-misspell-word\" data-scayt-word=\"CDN\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i0lya0i9tmfqs\">CDN<\/span>) that provides customers with the ability to deliver content, including data, videos, and <a href=\"https:\/\/www.itpro.co.uk\/application-programming-interface-api\/33557\/the-api-economy-what-your-business-needs-to-know\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/application-programming-interface-api\/33557\/the-api-economy-what-your-business-needs-to-know\">APIs<\/a>, securely with low latency and at a high speed.<\/p>\n<p>\u201cAmnesty International suspects the shutting down of the V4 infrastructure coincided with <span class=\"scayt-misspell-word\" data-scayt-word=\"NSO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i1ivn91ze2oag\">NSO<\/span> Group\u2019s shift to using cloud services such as Amazon <span class=\"scayt-misspell-word\" data-scayt-word=\"CloudFront\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i1iv73wr58z00\">CloudFront<\/span> to deliver the earlier stages of their attacks,\u201d <a href=\"https:\/\/www.amnesty.org\/en\/latest\/research\/2021\/07\/forensic-methodology-report-how-to-catch-nso-groups-pegasus\/\" data-cke-saved-href=\"https:\/\/www.amnesty.org\/en\/latest\/research\/2021\/07\/forensic-methodology-report-how-to-catch-nso-groups-pegasus\/\">said<\/a> the human rights <span class=\"scayt-misspell-word\" data-scayt-word=\"NGO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i1ivoq312tay2\">NGO<\/span>, adding that \u201cthe use of cloud services protects <span class=\"scayt-misspell-word\" data-scayt-word=\"NSO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i1ivzn1f2rn6b\">NSO<\/span> Group from some Internet scanning techniques\u201d.<\/p>\n<p><span class=\"scayt-misspell-word\" data-scayt-word=\"AWS\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i2gpb13c59bnj\">AWS<\/span> didn\u2019t elaborate on whether the decision to ban <span class=\"scayt-misspell-word\" data-scayt-word=\"NSO\" data-wsc-lang=\"en_GB\" data-wsc-id=\"krc7i2gpfjlk6cn1v\">NSO<\/span> Group from its services could be reconsidered in the future. <\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>      Sabina Weston<\/p>\n<p>        20 Jul, 2021    <\/p>\n<p>      Amazon Web Services (AWS) has shut down infrastructure and accounts linked to Israeli firm NSO Group.<br \/>\nThe news comes after\u00a0an investigation found that the company\u2019s Pegasus spyware was used to &#8230;<\/p>\n","protected":false},"author":627,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-42292","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/42292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/627"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=42292"}],"version-history":[{"count":1,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/42292\/revisions"}],"predecessor-version":[{"id":42293,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/42292\/revisions\/42293"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=42292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=42292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=42292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}