
criticalOffensive Tools
Whistleblower Exposes NSO Group's 'Close-Circle Infection' Strategy in New Global Surveillance Leak
Internal NSO Group dashboards leaked by a whistleblower code-named 'Safir' reveal a shift toward targeting the associates of primary targets to bypass high-security mobile device defenses.
18 July 2026Last updated 20 August 20265 min readAmnesty International Security Lab / Forbidden Stories
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Middle East / North Africa
- Confidence:
- High Confidence
- Source:
- Amnesty International Security Lab / Forbidden Stories
- Read Time:
- 5 min
Executive Summary\n\nOn July 16, 2026, a joint investigation by Amnesty International and the Forbidden Stories consortium, supported by testimony from a former Moroccan intelligence operative known as 'Safir,' revealed unprecedented details regarding the current operational state of the Pegasus spyware. The leak includes internal NSO Group marketing materials and targeting dashboards that confirm the deployment of a new tactical methodology dubbed 'Close-Circle Infection.' This strategy involves compromising the devices of family members, friends, and professional associates of a primary target to facilitate indirect surveillance and bridge security gaps in hardened environments. The revelations indicate that despite international sanctions and blacklisting, mercenary spyware remains a primary tool for state-sponsored espionage across North Africa and Europe.\n\n## Threat Analysis\n\nThe 'Close-Circle' methodology marks a significant evolution in offensive mobile operations. As high-value targets adopt more robust security postures—such as Apple’s Lockdown Mode or GrapheneOS—mercenary actors are shifting their focus to the 'weakest link' in the target's social graph. The leaked data shows that NSO Group operators now systematically fingerprint the devices of a target's immediate circle to identify vulnerabilities in older hardware or unpatched software. Once an associate's device is compromised, it is used as a local proxy to monitor the primary target via ambient audio recording and proximity-based tracking, effectively turning the associate into an unwitting human sensor.\n\n## Technical Details\n\nTechnical analysis of the leaked Pegasus dashboards identifies a new infection vector utilizing a zero-click vulnerability in the mobile device's cellular protocol handling (specifically targeting SS7 and Diameter signaling). The spyware performs an initial 'fingerprinting' phase to determine the target device's OS version, hardware model, and installed security applications without triggering a user alert. A key component of this new version is the 'FSSYS' infrastructure, a decentralized network of C2 nodes that utilizes legitimate cloud service providers to mask malicious traffic. The malware maintains persistence by embedding itself within the device's Secure Element (SE) or TrustZone, allowing it to survive factory resets in some hardware configurations. The investigation also confirmed the use of AI-driven social engineering modules that generate personalized phishing lures based on the target's intercepted messaging history.\n\n## Attribution Assessment\n\nEvidence gathered by the Security Lab at Amnesty International links the current campaign to the Direction Générale de la Surveillance du Territoire (DGST), Morocco’s internal intelligence agency. The leaked emails and targeting records corroborate Safir’s testimony that the UAE provided financing for the acquisition of these advanced Pegasus modules. While Morocco has officially denied any relationship with NSO Group, the forensic matches between the leaked NSO dashboard data and confirmed infections on the devices of Spanish cabinet ministers and French diplomats provide high-confidence attribution to these specific state actors and their commercial partners.\n\n## Implications\n\nThe ability of commercial surveillance vendors (CSVs) to continue operating at this level of sophistication despite U.S. and E.U. regulatory pressure suggests a systemic failure in the current export control regime. For organizations, this means that even the most secure employees are vulnerable if their personal contacts are not equally protected. The use of 'close-circle' targeting effectively expands the threat surface for any organization to include the entire social and family network of its leadership.\n\n## Recommendations\n\n1. Enforce Isolation: High-value personnel should utilize dedicated, hardened mobile devices for all sensitive communications and avoid connecting personal accounts to work hardware.\n2. Enable Advanced Protections: Deployment of Apple's Lockdown Mode remains the most effective consumer-grade defense against known Pegasus zero-click vectors.\n3. Signal Monitoring: Mobile service providers should implement stricter filtering for suspicious SS7/Diameter signaling requests originating from high-risk regions.\n4. Counter-Surveillance: Conduct regular forensic audits of devices belonging to both high-value individuals and their immediate support staff (assistants, drivers, and family members).
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room