Sign in

Donncha Ó Cearbhaill

@donncha.is
1.9K followers 225 following 61 posts

Head of Security Lab - Amnesty International Hunting spyware and unlawful surveillance targeting activists and civil society. For help with digital forensics or suspect spyware threats contact: securitylab.amnesty.org/get-help

PostsRepliesMedia
Reposted by Donncha Ó Cearbhaill
WIRED @wired.com · 02/10/2026
See what it’s like to travel in the occupied West Bank, for the nearly 3.5 million Palestinians who live there. 🔗 www.wired.com/story/experi...
619088
Reposted by Donncha Ó Cearbhaill
BOJΛN_PΞRKOV 🌐🌍 @bojanperkov.bsky.social · 01/10/2026
Amazing new publication on the lengths of digital autocracy and repression. Kudos to @donncha.is and other @amnesty.org folks working on this! www.amnesty.org/en/latest/ne...
amnesty.org
Whistleblower reveals how Morocco used a web of surveillance to silence journalists and activists
An ex-security agent provides a rare first hand insight into how Morocco's surveillance system works and how it was used to silence journalists and activists.
021
Donncha Ó Cearbhaill @donncha.is · 12/05/2026
See more from @lorenzofb.bsky.social bsky.app/profile/lore...
010
Donncha Ó Cearbhaill @donncha.is · 12/05/2026
The feature is opt-in for Pixel devices on Android 16+ with Advanced Protection Mode enabled. As it rolls out beyond Pixel, it should help protect more Android users who are often underserved and cannot afford the most expensive devices. blog.google/security/wha...
blog.google
What’s New in Android Security and Privacy in 2026
Android elevates mobile security with new AI-powered protections and advanced safeguards to help keep you safe.
120
Donncha Ó Cearbhaill @donncha.is · 12/05/2026
Credit to the teams at Google and Android who engaged deeply on this work over the past two years, taking onboard a lot of feedback on what civil society forensic work needs. We hope this can be a starting point for more proactive efforts to support spyware accountability.
140
Donncha Ó Cearbhaill @donncha.is · 12/05/2026
Spyware forensic work has so far relied on incidental logs that were never designed for security analysis and are too often partial and short-lived. Now we have the possibility to detect advanced spyware, exploits and unauthorised physical access, even months after the fact.
140
Donncha Ó Cearbhaill @donncha.is · 12/05/2026
To help defenders and civil society leverage this tool to further accountability efforts we have released a forensic methodology guide. With colleagues at @rsf.org's Digital Security Lab we have built Intrusion Log support into the latest version of MVT and AndroidQF github.com/mvt-project/...
github.com
Release v2026.5.12 · mvt-project/mvt
This release adds support for the newly launched Intrusion Logging feature available as part of Android Advanced Protection Mode. What's Changed Revise breaking changes notice in README by @besend...
141
Donncha Ó Cearbhaill @donncha.is · 12/05/2026
Excited to see Google publicly launch Intrusion Logging, the first purpose-built system to enable forensic investigations of advanced digital attacks on mobile. We @amnesty.org have collaborated with Android Security on it's design over the past two years securitylab.amnesty.org/latest/2026/...
securitylab.amnesty.org
Android Intrusion Logging as a new source of data for consensual forensic analysis  - Amnesty International Security Lab
Google has today announced the launch of a new ‘Android Intrusion Logging’ feature as part of Android Advanced Protection Mode (AAPM). The new intrusion logging feature promises to be a major aid to d...
12312
Reposted by Donncha Ó Cearbhaill
Amnesty Deutschland @amnesty.de · 08/05/2026
Pech für die Angreifer: Auch der Leiter unseres Amnesty Security Labs, @donncha.is, erhielt eine der Signal-Attacken - er und sein Team konnten diese mit einer russischen Gruppe, die unter dem Kürzel »UNC5792« bekannt ist, in Verbindung bringen.👇 www.spiegel.de/politik/deut...
spiegel.de
(S+) Signal-Angriff und Killerteams: So unverfroren agieren russische Agenten in Deutschland
Der Angriff auf Signal-Nutzerkonten deutscher Spitzenpolitiker versetzt Berlin in Alarm. Russlands Agenten spionieren immer dreister. Moskau sieht Deutschland inzwischen als »Feind Nummer eins«. Die S...
02011
Donncha Ó Cearbhaill @donncha.is · 07/05/2026
My recommendation for every Signal user: turn on Registration Lock to defend against this account-takeover technique. This is a clever campaign, but its reliance on social engineering reflects the strong core security of systems like Signal.
26027
Donncha Ó Cearbhaill @donncha.is · 07/05/2026
Some in the German government have suggested moving away from Signal to other "secure" messengers. That's the wrong lesson. Signal's core security remains excellent. This would be like banning email just because some people got phished.
1458
Donncha Ó Cearbhaill @donncha.is · 07/05/2026
The tactics are consistent with what Google's Threat Intelligence Group has reported on UNC5792, a Russian state-aligned actor previously documented running Signal phishing operations against Ukrainian military and government users.
1252
Donncha Ó Cearbhaill @donncha.is · 07/05/2026
Today's Der Spiegel cover story (by Marcel Rosenbach and team) reveals the wider impact of the campaign. Among the victims are multiple German ministers and the President of the Bundestag. The story also includes the findings from my independent investigation. www.spiegel.de/politik/deut...
1327
Donncha Ó Cearbhaill @donncha.is · 07/05/2026
The scale is far wider than Germany. The view I had into the attacks shows more than 13,700 Signal users had been targeted by January 2026, and the campaign has continued since. A small sample of targets includes senior politicians and journalists across Europe.
1296
Donncha Ó Cearbhaill @donncha.is · 07/05/2026
If the victim forwards that code back to "Support," the attackers gain access to the account and to all future messages, including group chats. In January the system was already at version v0.2.0.3, suggesting active, ongoing development.
1292
Donncha Ó Cearbhaill @donncha.is · 07/05/2026
The attackers use the open-source signal-cli tool to control Signal accounts that send phishing messages in bulk. When a victim accepts the message request, the attackers attempt to re-register the target's Signal account, triggering Signal to send an SMS verification code to the target.
1284
Donncha Ó Cearbhaill @donncha.is · 07/05/2026
The automated system powering the campaign is named ApocalypseZ by its operators. Its codebase and operator interface are written exclusively in Russian. The attackers were also translating victim communications into Russian.
1344
Donncha Ó Cearbhaill @donncha.is · 07/05/2026
In January, a phishing message arrived on my Signal account, supposedly from "Signal Support." I was able to turned the tables on the attackers and get a unique view of the wide-scale campaign by the attacker's targeting journalists and politicians I was target #13,730 in their database.
Signal phishing attempt from Signal Support
314690
Reposted by Donncha Ó Cearbhaill
Etienne - Tek @tek.randhome.io · 23/04/2026
Morpheus: A new Spyware linked to IPS Intelligence - Osservatorio Nessuno osservatorionessuno.org/blog/2026/0…
osservatorionessuno.org
Morpheus: A new Spyware linked to IPS Intelligence
Morpheus: A new Spyware linked to IPS Intelligence
054
Reposted by Donncha Ó Cearbhaill
Vas Panagiotopoulos @vaspanagiotopoulos.com · 09/04/2026
“We analyzed a 2025 sample of the Spyrtacus #spyware, version 8.71. …We confirm attribution to 🇮🇹SIO S.p.A. and provide a small set of IoCs to detect infections of this malware family.” osservatorionessuno.org/blog/2026/04...
osservatorionessuno.org
Italian spyware maker SIO still developing and distributing Spyrtacus
Italian spyware maker SIO still developing and distributing Spyrtacus
043
Reposted by Donncha Ó Cearbhaill
Wolfie Christl @wchr.bsky.social · 09/04/2026
We publish a major @citizenlab.ca report on Webloc, an ad-based mass surveillance system that monitors the movements and personal characteristics of hundreds of millions people globally based on data obtained from mobile apps and digital advertising. Customers include ICE, El Salvador, and Hungary.
1111108
Reposted by Donncha Ó Cearbhaill
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 25/02/2026
NEW: For months, I’ve been working on the story of Peter Williams, the former U.S. defense contractor who stole several hacking tools and then sold them to a Russian broker. Here’s what we know about the case, what we still don’t know, and a peek behind the scenes at how I reported this story.
techcrunch.com
Inside the story of the US defense contractor who leaked hacking tools to Russia | TechCrunch
The former boss of a U.S. hacking tools maker was jailed for selling highly sensitive software exploits to a Russian broker. This is how we first learned of his arrest, reported the story, and some of...
13729
Reposted by Donncha Ó Cearbhaill
George Monbiot @georgemonbiot.bsky.social · 07/01/2026
If the Palestine Action hunger strikers die - which they could do at any moment, as they are now very close to the end - it will be the government that killed them. Today’s column explains why. Please share, and write urgently to your MP. www.theguardian.com/commentisfre...
theguardian.com
Let’s be clear: if the Palestine Action hunger strikers die, the government will bear moral responsibility | George Monbiot
The three remaining hunger strikers have been convicted of nothing. Yet with astonishing cruelty, ministers refuse to listen to their reasonable demands, says Guardian columnist George Monbiot
10028541587
Reposted by Donncha Ó Cearbhaill
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 27/12/2025
NEW: Meet the folks at AccessNow's Digital Security Helpline, who have been investigating government spyware for more than a decade, helping journalists and dissidents all over the world. I spoke to Hassen Selmi, who heads the incident response team, to learn how his team fights spyware abuses.
techcrunch.com
Meet the team that hunts government spyware
For years, Access Now’s Digital Security Helpline has been aiding journalists and dissidents who have been targeted with government spyware. This is how they operate.
111845
Reposted by Donncha Ó Cearbhaill
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 04/12/2025
NEW: Staffers at notorious spyware maker Intellexa had live remote access to their customers' surveillance systems. This allowed them to see the personal data of targets hacked with Intellexa's spyware Predator, according to research based on a leaked training video. Needless to say, this is bad.
techcrunch.com
Sanctioned spyware maker Intellexa had direct access to government espionage victims, researchers say | TechCrunch
Based on a leaked video, security researchers alleged that Intellexa staffers have remote live access to their customers' surveillance systems, allowing them to see hacking targets’ personal data.
13021
Reposted by Donncha Ó Cearbhaill
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 04/12/2025
1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...
recordedfuture.com
Intellexa’s Global Corporate Web
22618
Reposted by Donncha Ó Cearbhaill
Jurre van Bergen @jurrevanbergen.nl · 04/12/2025
Our full report can be found here: securitylab.amnesty.org/latest/2025/... Haaretz - www.haaretz.com/israel-news/... InsideStory - insidestory.gr/article/inte... Inside-IT - www.inside-it.ch/intellexa-le...
securitylab.amnesty.org
To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab
Drawing on leaked internal company documents, sales and marketing material, as well as training videos, the “Intellexa Leaks” investigation gives a never-before-seen glimpse of the internal operations...
185
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
bsky.app/profile/jurr...
010
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
Check out the create reporting today from our wonderful colleagues and partners! bsky.app/profile/etri...
121
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
Significantly Google has also announced threat notifications today, first time ever alerts sent for Predator, to "several hundred accounts across various countries, including Pakistan, Kazakhstan, Angola, Egypt, Uzbekistan, Saudi Arabia, and Tajikistan". 🔥🔥🔥 cloud.google.com/blog/topics/...
cloud.google.com
Intellexa’s Prolific Zero-Day Exploits Continue | Google Cloud Blog
Commercial surveillance vendor Intellexa continues to thrive and exploit mobile zero-day vulnerabilities.
122
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
Toadya our research partners at Google TAG and Recorded Future (@julianferdinand.bsky.social) ) have published their own deep investigations into Intellexa bsky.app/profile/juli...
121
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
The leaked materials also forensically confirm Predator’s use in previously documented attacks in Greece and Egypt - validating years of investigations by Amnesty, Citizen Lab & others.
110
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
The level of remote access is more extensive and lax than previously thought. Intellexa staff simply logged in with TeamViewer (!) to a remote Predator customer system. The video shows staff could see live targeting and infection attempts from EAGLE_2, a customer in Kazakhstan.
120
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
A leaked training video show a client list (by codename): Dragon, Eagle, Falcon, Flamingo, Fox & more. Our investigation confirms Eagle is Kazakhstan; Phoenix, the 2023 Predator Files investigation found, was Libya. www.haaretz.com/israel-news/...
110
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
Shockingly, the leaks shows that Intellexa kept REMOTE ACCESS to Predator systems deployed on government clients’ premises — meaning the company had the potential to see data about surveillance victims in real time..
141
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
We've found first evidence of active Predator spyware in Pakistan 🇵🇰 - where a human rights lawyer in Balochistan was targeted amid intensified repression against civil society in the country. securitylab.amnesty.org/latest/2025/...
securitylab.amnesty.org
To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab
Drawing on leaked internal company documents, sales and marketing material, as well as training videos, the “Intellexa Leaks” investigation gives a never-before-seen glimpse of the internal operations...
120
Donncha Ó Cearbhaill @donncha.is · 04/12/2025
🚨 A huge leak exposes the new targets and internal operations of Intellexa, the secretive and murky company behind the notorious Predator spyware. Introducing #IntellexaLeaks, a joint investigation with partners @insidestory.gr, @haaretzcom.bsky.social & WAV Research Collective 🧵👇
198
Reposted by Donncha Ó Cearbhaill
Matthew Green @matthewdgreen.bsky.social · 14/10/2025
This is amazing research by Nadia Heninger and her co-authors Wenyi Morty Zhang, Annie Dai, Keegan Ryan, Dave Levin and Aaron Schulman. TL;DR a huge number of satellite links over our heads are totally unencrypted. satcom.sysnet.ucsd.edu
satcom.sysnet.ucsd.edu
🛰️ SATCOM Security
Research project homepage for SATCOM Security: papers, source code, and recent satellite communications vulnerabilities.
514768
Reposted by Donncha Ó Cearbhaill
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 10/10/2025
SCOOP: Spyware maker NSO Group confirmed to us that the company has been acquired by a U.S. investment group. NSO's spokesperson said the group "has invested tens of millions of dollars in the company and has acquired controlling ownership," but declined to say who is behind the investment.
techcrunch.com
Spyware maker NSO Group confirms acquisition by US investors | TechCrunch
NSO Group confirmed to TechCrunch that an unnamed group of American investors has taken “controlling ownership” of the surveillance tech maker.
4170134
Reposted by Donncha Ó Cearbhaill
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 28/09/2025
If you're based in Berlin, there's an event this Tuesday on spyware, hosted by @amnestyuk.bsky.social and @papertrailmedia.de. It includes workshops by @donncha.is, @jurrevanbergen.nl, and others, drop-in sessions, and a panel. Tickets are still available: www.hebbel-am-ufer.de/programm/pde...
hebbel-am-ufer.de
Amnesty International
Digital Surveillance: How States Are Spying on the Resistance
055
Reposted by Donncha Ó Cearbhaill
Amnesty Deutschland @amnesty.de · 27/09/2025
Danke Berlin! #AllEyesOnGaza
23748202
Reposted by Donncha Ó Cearbhaill
Lena Rohrbach @artepovera.bsky.social · 26/09/2025
Join us? 💥Workshops w/ @papertrailmedia.de @amnesty.de @interseclab.bsky.social 💥Dig. Security Clinic w/ @accessnow.org, @pressefreiheit.bsky.social&Tact. Tech 💥Panel w/ @donncha.is @sophieintveld.bsky.social @davidyambio.bsky.social @anjaosterhaus.bsky.social &Art by @forensicarchi.bsky.social
Weißer Text auf schwarzem Grund: Digital Surveillance: How States are Spying on the Resistance, mit Logos von HAU und Amnesty International
13121
Reposted by Donncha Ó Cearbhaill
Margi Murphy @margimurphy.bsky.social · 19/09/2025
For more than a year I’ve spoken with Scattered Spider “caller” Noah Urban from a Florida jail. I wanted to know how they chose victims, their methods and how Noah became entangled in a virtually and physically violent world. We’re publishing his story today: www.bloomberg.com/news/feature...
bloomberg.com
‘I Was a Weird Kid’: Jailhouse Confessions of a Teen Hacker
Noah Urban’s role in the notorious Scattered Spider gang was talking people into unwittingly giving criminals access to sensitive computer systems.
33615
Reposted by Donncha Ó Cearbhaill
Amnesty Deutschland @amnesty.de · 17/09/2025
Staatliche digitale Überwachung der Zivilgesellschaft: Am 30.9. bringen Amnesty und das HAU in Berlin Journalist*innen, Aktivist*innen, Technolog*innen, politische Entscheidungsträger*innen und die von Spionageprogrammen Betroffenen zusammen. Infos & Anmeldung 👇 www.hebbel-am-ufer.de/programm/pde...
hebbel-am-ufer.de
Amnesty International
Digital Surveillance: How States Are Spying on the Resistance
12310
Reposted by Donncha Ó Cearbhaill
Amnesty International @amnesty.org · 16/09/2025
There is no more time for excuses: as the evidence of Israel’s genocide continues to mount the international community cannot claim they didn’t know.
It's genocide.
14299167
Reposted by Donncha Ó Cearbhaill
Osservatorio Nessuno OdV @osservatorionessuno.org · 06/09/2025
We are announcing Bugbane, an open-source Android app that makes consensual mobile forensics more accessible. It's compatible with MVT and AndroidQF. Now in an open-beta, we are calling for community feedbacks before a general public release by EOY! osservatorionessuno.org/blog/2025/09...
osservatorionessuno.org
Bugbane: Simplifying consensual Android forensics
Bugbane: Simplifying consensual Android forensics
044
Reposted by Donncha Ó Cearbhaill
Lena Rohrbach @artepovera.bsky.social · 09/09/2025
🚨Out today: In Pakistan können jederzeit über 4 Mill. Menschen gleichzeitig willkürlich überwacht werden. Die Technik („LIMS“) stammt vom deutschen Unternehmen Utimaco und ist eigentlich im Export kontrolliert. Unsere neue, einjährige Recherche von @amnesty.de @amnesty.org & Partner*innen zeigt:
24422
Donncha Ó Cearbhaill @donncha.is · 09/09/2025
Highly recommend reading the excellent technical analysis from @interseclab.bsky.social. They mined the huge Geedge Networks leak to understand how techniques powering their surveillance and censorship products. bsky.app/profile/inte... interseclab.org/research/the...
interseclab.org
The Internet Coup: A Technical Analysis on How a Chinese Company is Exporting The Great Firewall to Autocratic Regimes - InterSecLab
This research reveals groundbreaking findings on how Geedge Networks is selling an extensive suite of next-generation digital repression tools to client governments around the world.
033
Donncha Ó Cearbhaill @donncha.is · 09/09/2025
bsky.app/profile/just...
111
Donncha Ó Cearbhaill @donncha.is · 09/09/2025
bsky.app/profile/jame...
100