Oct 05, 2026 · 8 min read
Morocco's DGST Put 22 Journalists in Its Pegasus System
On October 1, 2026, Amnesty International published a 126 page report built on testimony from a former Moroccan intelligence officer. It describes Pegasus, bugged light fixtures, rigged phones and targets up to Spain's ministers and France's president.
"We infected so many internet cafés with Remote Controlled Spyware." That line comes from a man Amnesty International calls Safir, who spent about a decade inside Morocco's Direction Générale de la Surveillance du Territoire (DGST). His testimony anchors We start with the verdict: Inside Morocco's surveillance machine, published October 1 after a collaboration with 14 media organizations coordinated by Forbidden Stories.
Pegasus is only one layer of what the report describes. Underneath sit wiretaps, bugged cafés, hidden cameras and informant neighbours. For human rights defenders in Morocco, Amnesty concludes, "there is nowhere to hide."
Key Takeaways
- Amnesty International matched 103 Moroccan phone numbers entered in the Moroccan Pegasus system between September and December 2017 to named people, and 22 of them were journalists and media workers.
- Morocco's DGST is the agency Amnesty says ran Pegasus against activists and journalists between 2017 and 2021, and possibly later.
- Safir, a former DGST officer, described microphones in journalist Omar Radi's light fixtures and phones sold to protesters already infected with spyware.
- Pegasus Project records show the DGST selecting French numbers from April 2018 and Spanish numbers from May 2018, including President Emmanuel Macron's on March 13, 2019.
- NSO Group's iPhone attack accounts were often Gmail addresses registered with iCloud, and Amnesty used those reused accounts to tie infections in Morocco, France and Spain to the Moroccan customer.
What Did Amnesty's Morocco Report Find?
Amnesty found that the DGST aimed Pegasus at civil society from the first weeks it had the system. The Amnesty Security Lab puts it plainly: "The Moroccan authorities used Pegasus spyware between 2017 and 2021, and possibly later."
Excluding test and internal numbers, Amnesty matched 103 Moroccan phone numbers entered between September and December 2017 to specific people:
- 65 civil society members: 34 human rights defenders, 22 journalists and media workers, 5 lawyers and 4 academics
- 25 political representatives or officials
- 5 diplomats or representatives of international organizations
- 8 others, including business people and religious figures
That makes civil society 63% of the named targets, and journalists alone about one in five. Selection is not infection, and the report stresses that only forensics can confirm a phone was hit. But the order matters. "These records show the phone numbers of prominent human rights defenders and journalists were among the first to be entered into the Pegasus system," Donncha Ó Cearbhaill, head of Amnesty's Security Lab, told Al Jazeera.
Who Is the Whistleblower Behind the Report?
The whistleblower is a former DGST officer, given the pseudonym Safir, who took part in numerous surveillance operations during a decade long career at the agency. The full report says Amnesty verified his identity, employment history and "many key aspects" of his testimony, and checked his claims against technical evidence and two other former Moroccan intelligence officials. Exiled journalist Hicham Mansouri, now in France, has spent hundreds of hours since 2023 interviewing Safir and other sources.
How Did the DGST Get Pegasus Onto Phones?
The DGST used one click links, zero click exploits and network injection through Maroc Telecom, the partially state owned carrier. Amnesty saw one click links in Morocco from October 2017 to January 2018, and zero click infections from February 2018.
Network injection is the most alarming route. In 2020, Amnesty documented a live injection attempt against journalist Omar Radi while he was on Maroc Telecom's 4G network, pointing his phone to the Pegasus domain urlpush[.]net. Safir says the carrier allowed the injection equipment to be installed, though the report notes this does not mean it knew of specific attacks. He also says a telecom provider gave the DGST device identifiers such as IMEI numbers and handed targets unlimited data packages, so Pegasus uploads would not trip their data caps.
Within weeks of Amnesty's June 2020 finding that Radi was targeted, he was arrested. In July 2021 he was sentenced to six years in a trial Amnesty says was "marred by due process violations." A royal pardon freed him in July 2024.
The Low Tech Half of the Machine
Spyware was the last resort. "Once we have arrived at Pegasus, we have taken all the other steps," Safir said. "It comes after the tapping, in their apartment, in their car." The Amnesty press release and report describe those steps:
- Bugged homes. Coin sized microphones transmitting over encrypted radio were implanted in the light fixtures of Radi's apartment.
- Bugged cafés. Waiters were bribed to seat targets at tables fitted with microphones and cameras.
- Rigged phones. During the 2016 and 2017 Rif protests, a secondhand phone shop sold devices preinfected with Hacking Team's RCS spyware to Hirak activists.
- Airports and detention. Agents used Cellebrite's UFED extraction tool and physical infection when targets transited airports or sat in custody.
The take fed smear campaigns. In 2021, activist Fouad Abdelmoumni was covertly filmed at home with his fiancée, and the video circulated on WhatsApp. "The tools they use are wide-ranging, but the goal is clear: to blackmail, discredit, shame and, if necessary, unjustly imprison those who speak out in defence of human rights in Morocco," said Rebecca White of Amnesty's Security Lab.
How Far Did the Targeting Reach Into Spain and France?
It reached the top of both governments. Pegasus Project records show the DGST's first French selection on April 23, 2018, exiled Moroccan journalist Aboubakr Jamai. Its first Spanish selection, on May 11, 2018, was Sahrawi activist Aminatou Haidar, whose phone Amnesty later confirmed was infected.
In March 2019, Spanish journalist Ignacio Cembrero was selected, and his number reappeared 25 times over two months. On March 13, a French number for former UN envoy Lakhdar Brahimi was selected, and one minute later so was President Emmanuel Macron's, whose number Amnesty first flagged in its 2021 Pegasus Project release. A filing in WhatsApp's US lawsuit against NSO separately lists 69 Moroccan, 39 Algerian, 21 Spanish and 7 French numbers targeted that spring, without naming the customer.
Then came 2021. A Spanish court document identifies linakeller2203[@]gmail.com, an iCloud account used that year against Mansouri and French activist Claude Mangin, as the account behind the zero click attacks that compromised the phones of Spain's Interior and Defence ministers.
The Email Angle: Gmail Accounts Were the Attack Infrastructure
The iPhone attacks ran through ordinary webmail accounts. Citing NSO employee testimony, the report says a team called "White Services" created anonymous Google or Outlook accounts, then registered them with iCloud to send zero click exploits over iMessage. "This is why many of the malicious Apple accounts used for Pegasus attacks and detailed in this section are also Gmail addresses," Amnesty writes.
That design is also what exposed Morocco. NSO builds separate infrastructure for each customer, so one attacker address on many phones points to one operator. Amnesty found bergers.o79[@]gmail.com used against Radi in Morocco and lawyer Joseph Breham in France, and French investigators independently documented the same cluster of Apple accounts. Even the DGST's internal email domain, tersim.ma, was registered with a Gmail address.
The other half of the email story is collection. NSO's Pegasus dashboard sorts stolen data by type, "including calls, messages, email, calendar, contacts, browsing, files, applications, and photos." An infected phone means a read inbox, plus every source who ever wrote to it. We covered what that meant for one newsroom in El Faro's Pegasus lawsuit against NSO.
Why Does WhatsApp's Lawsuit Matter Here?
WhatsApp's lawsuit matters because it supplied much of the evidence. The report draws on "previously unpublished internal NSO Group marketing material and technical materials" disclosed in the case WhatsApp and Meta brought against NSO, showing that Pegasus "relies on maintenance and support by NSO Group."
On September 30, a day before this report, a US judge dismissed the El Faro journalists' case against NSO for lack of jurisdiction. Journalists keep losing in court, yet discovery won by a platform now yields the most detailed public account of a Pegasus customer. If those documents can map Morocco, they can map others.
Morocco has not engaged. Amnesty wrote to the authorities four weeks before publication and got no response, and CPJ says the Ministry of Interior ignored its email too. Rabat has repeatedly denied using spyware against its citizens, and in July 2021 it sued Amnesty International France in Paris over the Pegasus Project. CPJ regional director Sara Qudah called the findings "a chilling picture of the scale and methods of surveillance targeting journalists in Morocco."
What Should Journalists Covering Morocco Do Now?
Journalists should harden their phones and treat physical access as part of the threat, because the DGST relies on it. Amnesty itself warns this ecosystem "can be almost impossible to escape." Practical steps:
- Turn on Lockdown Mode and update. Apple calls Lockdown Mode "an optional, extreme protection" for people targeted "because of who they are or what they do." It sits under Settings, Privacy & Security. Our guide to Apple's spyware threat notifications covers what to do if an alert arrives.
- Treat a phone that left your hands as suspect. Our advice, given the airport and detention findings: after a seizure or a checkpoint, get it checked before using it for sources.
- Buy devices new and sealed. Safir described a secondhand shop selling preinfected phones. A sealed box from a major retailer closes that route.
- Keep source accounts off shared computers. The DGST seeded internet cafés with spyware.
- Get a forensic check. Amnesty's Mobile Verification Toolkit supports "consensual forensic analysis of Android and iOS devices," and Access Now's Digital Security Helpline offers 24/7 help in ten languages, including Arabic, French and Spanish.
- Rotate credentials from a clean device. If you suspect infection, change email and cloud passwords and sign out other sessions from hardware you trust.
None of this defeats a microphone in a ceiling lamp. That is why Amnesty's demands are political: an end to surveillance of journalists and rights defenders, an independent investigation into the DGST, and no spyware export licences for Morocco until that happens and safeguards exist. For a parallel case, see our coverage of Pegasus targeting in Serbia.