Apple Drops Spyware Case Against NSO Group, Citing Risk of Threat Intelligence Exposure

Omega Balla
Apple has filed a motion to “voluntarily” dismiss its lawsuit against commercial spyware vendor NSO Group, citing a shifting risk landscape that could lead to exposure of critical “threat intelligence” information. The development was first reported by The Washington Post on Friday. The iPhone maker said its efforts, coupled with those of others in the industry and national governments to tackle

Apple has filed a motion to “voluntarily” dismiss its lawsuit against commercial spyware vendor NSO Group, citing a shifting risk landscape that could lead to exposure of critical “threat intelligence” information.

The development was first reported by The Washington Post on Friday.

The iPhone maker said its efforts, coupled with those of others in the industry and national governments to tackle the rise of commercial spyware, have “substantially weakened” the defendants.

“At the same time, unfortunately, other malicious actors have arisen in the commercial spyware industry,” the company said. “It is because of this combination of factors that Apple now seeks voluntary dismissal of this case.”

“While Apple continues to believe in the merits of its claims, it has also determined that proceeding further with this case has the potential to put vital security information at risk.”

Apple originally filed the lawsuit against the Israeli company in November 2021 in an attempt to hold it accountable for illegally targeting users with its Pegasus surveillance tool.

It described NSO Group, a subsidiary of Q Cyber Technologies Limited, as “amoral 21st century mercenaries who have created highly sophisticated cyber-surveillance machinery that invites routine and flagrant abuse.”

Earlier this January, a federal judge denied a motion from NSO Group to dismiss the lawsuit under the grounds that the company is “based in Israel and Apple should have sued them there,” with the court stating that “the anti-hacking purpose of the [Computer Fraud and Abuse Act] fits Apple’s allegations to a T, and NSO has not shown otherwise.”

The global spyware market

In its motion for voluntary dismissal, Apple said three major developments have been a contributing factor: The risk that the threat intelligence information it has developed to protect users against spyware attacks could be exposed, pointing to a July 25, 2024, report from The Guardian.

The British newspaper revealed that Israeli officials had seized documents from NSO Group in July 2020 in an apparent effort to stop the handover of information about the notorious hacking tool as part of the company’s ongoing legal tussle with Meta-owned WhatsApp, which filed a similar lawsuit in 2019.

“The seizures were part of an unusual legal maneuver created by Israel to block the disclosure of information about Pegasus, which the government believed would cause ‘serious diplomatic and security damage’ to the country,” The Guardian noted at the time.

Apple also cited as reasons the changing dynamics in the commercial spyware industry and the proliferation of different spyware companies, as well as the possibility of revealing to third-parties “the information Apple uses to defeat spyware while defendants and others create significant obstacles to obtaining an effective remedy.”

The development comes as the Atlantic Council divulged that the individuals behind some of the spyware vendors in Israel, Italy, and India that have come under the scanner for enabling authoritarian regimes to spy on human rights advocates, opposition leaders, and journalists have sought to rename them, start new ones, or undertake strategic jurisdiction hopping.

Case in point, Intellexa, the now-sanctioned company behind the Predator spyware, has resurfaced with new infrastructure in connection with its ongoing use by likely customers in countries such as Angola, the Democratic Republic of the Congo (DRC), and Saudi Arabia.

“Predator’s operators have significantly enhanced their infrastructure, adding layers of complexity to evade detection,” cybersecurity company Recorded Future’s Insikt Group said.

“The new infrastructure includes an additional tier in its multi-tiered delivery system, which anonymizes customer operations, making it even harder to identify which countries are using the spyware.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.

 The Hacker News 

Total
0
Shares
Previous Post

Cybercriminals Exploit HTTP Headers for Credential Theft via Large-Scale Phishing Attacks

Next Post

North Korean Hackers Target Cryptocurrency Users on LinkedIn with RustDoor Malware

Related Posts