Donncha Ó Cearbhaill @donncha.is · 07/05/2026Today's Der Spiegel cover story (by Marcel Rosenbach and team) reveals the wider impact of the campaign. Among the victims are multiple German ministers and the President of the Bundestag. The story also includes the findings from my independent investigation. www.spiegel.de/politik/deut... 1327
Donncha Ó Cearbhaill @donncha.is · 07/05/2026In January, a phishing message arrived on my Signal account, supposedly from "Signal Support." I was able to turned the tables on the attackers and get a unique view of the wide-scale campaign by the attacker's targeting journalists and politicians I was target #13,730 in their database. 314690
Donncha Ó Cearbhaill @donncha.is · 04/12/2025The level of remote access is more extensive and lax than previously thought. Intellexa staff simply logged in with TeamViewer (!) to a remote Predator customer system. The video shows staff could see live targeting and infection attempts from EAGLE_2, a customer in Kazakhstan. 120
Donncha Ó Cearbhaill @donncha.is · 04/12/2025A leaked training video show a client list (by codename): Dragon, Eagle, Falcon, Flamingo, Fox & more. Our investigation confirms Eagle is Kazakhstan; Phoenix, the 2023 Predator Files investigation found, was Libya. www.haaretz.com/israel-news/... 110
Donncha Ó Cearbhaill @donncha.is · 04/12/2025Shockingly, the leaks shows that Intellexa kept REMOTE ACCESS to Predator systems deployed on government clients’ premises — meaning the company had the potential to see data about surveillance victims in real time.. 141
Donncha Ó Cearbhaill @donncha.is · 04/12/2025🚨 A huge leak exposes the new targets and internal operations of Intellexa, the secretive and murky company behind the notorious Predator spyware. Introducing #IntellexaLeaks, a joint investigation with partners @insidestory.gr, @haaretzcom.bsky.social & WAV Research Collective 🧵👇 198
Donncha Ó Cearbhaill @donncha.is · 09/09/2025Great Firewall Export: A new investigation by @amnesty.org and partners reveals how Geedge Networks, a Chinese company is commercializing the tech behind China's notorious "Great Firewall". A huge leak of Geedge data reveal their products, deployed in China, Pakistan, and Myanmar among others. 11914
Donncha Ó Cearbhaill @donncha.is · 27/03/2025The two investigative journalist - who focus heavily on corruption by public officials and connected business figures - received infection links from an unknown number over Viber. Amnesty was able to confirm with high-confidence that these were Pegasus infection links. 210
Donncha Ó Cearbhaill @donncha.is · 21/01/2025📢 LAST CHANCE: Apply for @amnesty.org's Digital Forensic Fellowship! Working with our team at the Security Lab, you'll learn the tech and investigative skills needed to expose how governments abuse advanced spyware and other surveillance tech against activists and civil society. 11518
Donncha Ó Cearbhaill @donncha.is · 16/12/20247/ There is much more tech info including Android forensic traces, Cellebrite exploit analysis, and possible Android zero-click spyware traces in the report. We also have recommendations for mobile devices vendors on how to harden against these threats. 141
Donncha Ó Cearbhaill @donncha.is · 16/12/20245/ We documented seven individual spyware cases - three with NSO Group's Pegasus spyware, and with the newly discovered NoviSpy. We found that NoviSpy has been active since at least 2019, and there are indications hundreds of devices may have been targeted in recent years. 141
Donncha Ó Cearbhaill @donncha.is · 16/12/20244/ We found that NoviSpy infections often occur during police encounters. In one shocking case, an activist went to BIA (Serbia's domestic intelligence service) to fill a complaint as a victim of a crime. During the 2 hour interview, BIA infected their phone 141
Donncha Ó Cearbhaill @donncha.is · 16/12/20242/ Our forensic investigation found a pattern where Cellebrite zero-day exploits were used to first bypass Android device lock screens and encryption before infection. Cellebrite UFED has also been used widely to extract data from phones of youth activists and protestors 141
Donncha Ó Cearbhaill @donncha.is · 16/12/20241/ In February 2024, During a supposedly routine police traffic stop, Serbian journalist Slaviša Milanov had his phone unlocked with Cellebrite and covertly hacked and infected with the #NoviSpy spyware by Serbian authorities 152