Exiled, then spied on: Civil society in Latvia, Lithuania, and Poland tar... 2 of 3 https://www.accessnow.org/publication/civil-society-in-exile-pegasus/ • Evgeny Pavlov, a Latvian journalist, former correspondent for Novaya Gazeta Baltija, an independent news media covering the Baltic countries, and former freelance journalist for Current Time’s Baltia program. Pavlov’s device was targeted with Pegasus on or around November 28, 2022, and on or around April 24, 2023; however, we were unable to confirm if the attempts were successful. • Maria Epifanova, general director of Novaya Gazeta Europe and director of Novaya Gazeta Baltija. Epifanova’s iPhone was infected on or around August 18, 2020 — the earliest known use of Pegasus to target Russian civil society. Epifanova was chief editor of Novaya Gazeta Baltija at the time, and the attack occurred shortly after she received accreditation to attend exiled Belarusian democratic opposition leader Svetlana Tikhanovskaya’s first press conference in Vilnius. Two Belarusian civil society members currently living in Warsaw, Poland, also received Apple notifications on October 31, 2023: • Andrei Sannikov is a prominent Belarusian opposition politician and activist, who ran for President of Belarus in 2010, receiving the second highest vote count after incumbent Alexander Lukashenko. After the election he was arrested by the Belarusian KGB and held as a prisoner of conscience. Authorities also threatened to take away his three-year old son. According to the Citizen Lab, Sannikov’s iPhone was infected with Pegasus on or around September 7, 2021. • Natallia Radzina is editor-in-chief of independent Belarusian media website Charter97.org and a recipient of the Committee to Protect Journalists (CPJ) International Press Freedom Award. Radzina was persecuted for journalistic activities in Belarus, imprisoned, and forced to flee the country. Access Now’s Digital Security Helpline, as confirmed by the Citizen Lab, also identified that Radzina’s device was infected with Pegasus spyware on or around December 2, 2022, December 7, 2022, and January 16, 2023. The first infection took place the day after Radzina’s participation in the Third Anti-War Conference in Vilnius, organized by the Free Russia Forum. // New patterns emerge Our investigation shows that the use of Pegasus spyware to target Russian- and Belarusianspeaking journalists and activists dates back until at least 2020, with more attacks following Russia’s full-scale invasion of Ukraine in February 2022. Access Now and the Citizen Lab also confirmed that five of the victims’ phones contained Apple IDs used by Pegasus operators in their attempts to hack the devices. We know that targeting via various exploits that take advantage of bugs in HomeKit can leave a record of the attacker’s Apple ID email address on the victim’s device. The Citizen Lab believes that each Apple ID is used by a single Pegasus operator, though a single Pegasus operator might use multiple Apple IDs. We found the same Apple ID email address present on Pavlov, Radzina, and the second anonymous victim’s phones. A separate email account was used to target both Erlikh and Pavlov’s phones on November 28, 2022. Artifacts from Andrei Sannikov and Natallia Radzina’s phones contained another separate identical email, according to the Citizen Lab. This suggests that a single Pegasus spyware operator may be behind the targeting of at least three of the victims and possibly all five. // Who is responsible? Access Now and the Citizen Lab are not publicly naming a specific operator at this time. Given that 7/5/2024, 3:46 PM

Select target paragraph3