Exiled, then spied on: Civil society in Latvia, Lithuania, and Poland tar...
2 of 3
https://www.accessnow.org/publication/civil-society-in-exile-pegasus/
• Evgeny Pavlov, a Latvian journalist, former correspondent for Novaya Gazeta Baltija,
an independent news media covering the Baltic countries, and former freelance journalist for
Current Time’s Baltia program. Pavlov’s device was targeted with Pegasus on or around
November 28, 2022, and on or around April 24, 2023; however, we were unable to confirm if
the attempts were successful.
• Maria Epifanova, general director of Novaya Gazeta Europe and director of Novaya
Gazeta Baltija. Epifanova’s iPhone was infected on or around August 18, 2020 — the earliest
known use of Pegasus to target Russian civil society. Epifanova was chief editor of Novaya
Gazeta Baltija at the time, and the attack occurred shortly after she received accreditation to
attend exiled Belarusian democratic opposition leader Svetlana Tikhanovskaya’s first press
conference in Vilnius.
Two Belarusian civil society members currently living in Warsaw, Poland, also received Apple
notifications on October 31, 2023:
• Andrei Sannikov is a prominent Belarusian opposition politician and activist, who ran for
President of Belarus in 2010, receiving the second highest vote count after incumbent
Alexander Lukashenko. After the election he was arrested by the Belarusian KGB and
held as a prisoner of conscience. Authorities also threatened to take away his three-year
old son. According to the Citizen Lab, Sannikov’s iPhone was infected with Pegasus on
or around September 7, 2021.
• Natallia Radzina is editor-in-chief of independent Belarusian media website
Charter97.org and a recipient of the Committee to Protect Journalists (CPJ) International
Press Freedom Award. Radzina was persecuted for journalistic activities in Belarus,
imprisoned, and forced to flee the country. Access Now’s Digital Security Helpline, as
confirmed by the Citizen Lab, also identified that Radzina’s device was infected with
Pegasus spyware on or around December 2, 2022, December 7, 2022, and January 16, 2023.
The first infection took place the day after Radzina’s participation in the Third Anti-War
Conference in Vilnius, organized by the Free Russia Forum.
// New patterns emerge
Our investigation shows that the use of Pegasus spyware to target Russian- and Belarusianspeaking journalists and activists dates back until at least 2020, with more attacks following
Russia’s full-scale invasion of Ukraine in February 2022.
Access Now and the Citizen Lab also confirmed that five of the victims’ phones contained Apple IDs
used by Pegasus operators in their attempts to hack the devices. We know that targeting via
various exploits that take advantage of bugs in HomeKit can leave a record of the attacker’s
Apple ID email address on the victim’s device. The Citizen Lab believes that each Apple ID is used
by a single Pegasus operator, though a single Pegasus operator might use multiple Apple IDs. We
found the same Apple ID email address present on Pavlov, Radzina, and the second anonymous
victim’s phones. A separate email account was used to target both Erlikh and Pavlov’s phones on
November 28, 2022. Artifacts from Andrei Sannikov and Natallia Radzina’s phones contained
another separate identical email, according to the Citizen Lab. This suggests that a single
Pegasus spyware operator may be behind the targeting of at least three of the victims and possibly
all five.
// Who is responsible?
Access Now and the Citizen Lab are not publicly naming a specific operator at this time. Given that
7/5/2024, 3:46 PM