These agencies also still rely on classic methods of spying through informants linked to embassies who
infiltrate activist groups and attend events involving members of the diaspora. Using these different
channels, regime authorities are able to follow closely the activities of dissidents abroad and prepare
interventions of control and repression.
In addition to these forms of “silent” monitoring and harvesting of intelligence, interviewees reported they
occasionally received signals that monitoring was taking place. A Syrian journalist and an Egyptian activist
in Germany, for instance, both reported that state agents in their home countries questioned their parents
or colleagues after they appeared on the Arabic television program of Deutsche Welle. Other Syrian
journalists interpreted the swift filtering of any new online publication as a sign that regime authorities
kept a close eye on the media activities of exiles. Smear campaigns in state-controlled media referring to
recent activities, as well as comments and trolling on social media profiles, made activists from all three
countries understand they were being watched. Such forms of not-so-hidden monitoring clearly aim to
have a silencing effect, shaping and restricting the behavior of targeted communities by making it known
that state authorities have taken an interest in their actions.
ACCOUNT AND DEVICE HACKING
Hacking into computers, mobile devices, and personal accounts such as email and social media has
become a common technique for targeted surveillance in repressive contexts.57 This proliferation of more
aggressive information gathering tactics can be seen as a response to the heightened security awareness
among activists who increasingly resort to email encryption and other protections against surveillance.
As a result, threat actors seek to compromise devices and accounts to gain access to a trove of private
information, communications, and contacts.58
Such attacks often involve some form of social engineering, with perpetrators working to trick targets into
opening a malicious link or attachment by impersonating a friend or an organization linked to their field
of expertise (or offering otherwise interesting information). The malware, once successfully executed,
provides access to a target’s device or reveals confidential passwords. As noted in the prior section of this
report, threat actors tied to the governments of Egypt, Syria, and Iran have engaged in phishing campaigns
against civil society on a large scale, both inside and outside their territories. Respondents reported
attempts to compromise their devices and accounts as one of the most common threats they face. As a
leading editor in an Iranian exile media organization explained:
“There is no day when I open my email and I don’t have a phishing email. Yesterday I received a message
from Google telling me that they couldn’t deliver one of my messages. For more details I should click.”59
Interviews revealed attackers attempt to deliver malware in multiple ways, using not only email but also
messages on Facebook, WhatsApp, and Telegram. Iranian digital security experts explained that threat
actors often try to compromise the accounts of low profile and inexperienced users in activist networks—
or even family members—in order to gain access to approach more valuable targets. Iranian intelligence
agencies have also used the identities of individuals arrested inside the country to swiftly approach the
arrested individual’s list of contacts before the arrest became public. Other respondents mentioned
phishing attempts carried by invitations to seminars, files on human rights violations, and information on
recent bombing raids in Syria, among others.
57
Citizen Lab (2014). Communities @ Risk: Targeted Digital Threats against Civil Society. https://targetedthreats.net.
58
Guarnieri, C. (2015, August 16). Helping the Helpless: Targeted Threats to Civil Society. Talk at the Chaos Communication
Camp. https://media.ccc.de/v/camp2015-6848-helping_the_helpless.
59
Interview I11, January 2019.
18