Reuters, BELGRADE and LONDON
Serbian officials installed homegrown spyware on the phones of dozens of journalists and activists, Amnesty International said in a report released yesterday, citing digital forensic evidence and testimony from activists who said they were hacked.
In two cases, software provided by Israeli surveillance company Cellebrite DI Ltd was used to unlock phones prior to infection, the report said.
The Serbian spyware, dubbed “NoviSpy” by Amnesty, then took covert screenshots of mobile devices, copied contacts and uploaded them to a government-controlled server, the report said.
Women look at a mobile phone in Belgrade, Serbia, on May 3 last year.
Photo: AP
“In multiple cases, activists and a journalist reported signs of suspicious activity on their mobile phones directly following interviews with Serbian police and security authorities,” it said.
The Serbian Ministry of the Interior, the Serbian Ministry of Foreign Affairs and intelligence agency BIA did not respond to requests for comment made on Thursday last week.
Cellebrite products are widely used by law enforcement, including the FBI, to unlock smartphones and scour them for evidence.
Cellebrite chief marketing officer David Gee said it was investigating the Amnesty allegations.
“Should those accusations be accurate, that could potentially be in violation of our end user license agreement,” Gee said.
If that were the case, Cellebrite could suspend the use of its technology by Serbian authorities, he said.
Putting surveillance software on devices “is absolutely not what we do,” Gee said, adding that Cellebrite had begun contacting Serbian officials, but declined to provide further details.
One of the activists featured in the report said that they had noticed the contacts on their phone had been exported immediately after a meeting with the BIA.
The activist said that they showed their phone to digital forensic experts, who discovered the NoviSpy spyware had exported their contacts and sent private photos from their device to a BIA-controlled server.
Amnesty said that Serbia received phone-cracking devices from Cellebrite as part of a broader package of assistance designed to help Serbia meet the requirements for integration into the EU.
That package, which was funded by the Norwegian government and administered by the UN Office for Project Services (UNOPS), was provided to the interior ministry from 2017 to 2021 to help Serbia fight organized crime, the report said.
The Norwegian government temporarily ceased delivery of Cellebrite devices to Serbia in 2018, Amnesty said.
The Norwegian embassy in Belgrade also raised concerns about the program, the report added, but UNOPS eventually delivered the devices in June 2019.
“The claims made in the report are alarming and, if correct, unacceptable,” Norwegian Deputy Minister of Foreign Affairs Maria Varteressian said. “We will meet Serbian authorities as well as UNOPS later this month to get further information on the matter. We expect UNOPS to investigate the allegations.”
UNOPS in a statement said that it welcomed the report and that the agency had since 2017 “further enhanced mechanisms to assess and mitigate potential adverse effects.”