Morocco Uses Pegasus Spyware to Target Dissidents and Media

Morocco Uses Pegasus Spyware to Target Dissidents and Media

The Moroccan state’s response to surveillance allegations involves a coordinated disinformation campaign through pro-government media outlets like Al Barlamane and Le 360. This effort masks a reality where the Direction Générale de la Surveillance du Territoire (DGST) has successfully weaponized digital tools to maintain an iron grip on information flow. For years, the government has refined a repressive ecosystem that views journalists and human rights defenders as existential threats rather than vital components of a healthy democracy. By integrating high-end cyber-intelligence into its standard operating procedures, Morocco has transformed its security apparatus into a global leader in digital espionage. This strategy does not merely monitor communications; it creates a pervasive atmosphere of fear that discourages dissent and forces self-censorship among activists. The transition toward total digital dominance reflects a broader trend of authoritarian regimes leveraging private sector innovation to bypass legal and ethical safeguards.

The Proliferation and Evolution of Digital Surveillance

Technical Mastery: The Shift to Zero-Click Tactics

At the heart of modern Moroccan espionage is the Pegasus spyware, a high-end tool developed by the Israeli firm NSO Group. Unlike earlier forms of malware that required a user to click a suspicious link, Pegasus utilizes zero-click exploits to compromise smartphones without any victim interaction. Forensic evidence reveals that the DGST transitioned to these invisible methods several years ago, allowing the state to gain total access to a target’s messages, location data, and microphone without leaving any obvious traces of a breach. This technological leap means that even the most security-conscious individuals are vulnerable, as the infection occurs at the system level before the user can even detect an anomaly. The sheer efficiency of zero-click delivery has rendered traditional digital hygiene practices largely ineffective against state-sponsored actors, marking a significant shift in the power dynamic between the Moroccan government and its perceived domestic adversaries.

Beyond the technical mechanics, the deployment of such tools signals a departure from traditional surveillance toward total information dominance. When a device is compromised via Pegasus, the state essentially possesses a digital twin of the target’s life, including encrypted chats, private photos, and real-time audio. This level of access allows the DGST to preempt protests, identify confidential sources, and gather personal leverage that can be used for blackmail or public smear campaigns. The psychological impact on the victim is profound, as the realization that their most private space has been invaded creates a lasting sense of insecurity. As the Moroccan state continues to refine these methods through 2026, the barrier between public activism and personal safety has effectively vanished. The use of such invasive technology underscores a calculated policy where the privacy of the citizen is entirely subordinate to the perceived security needs of the ruling elite.

Forensic Attribution: Tracking the Digital Fingerprints

The scale of these operations is evidenced by forensic analysis of Apple iCloud accounts and server infrastructures linked to the Moroccan state. Investigative reports have identified a lack of discrimination in the targeting process, which has affected journalists like Hicham Mansouri and Sahrawi activists who have long been in the crosshairs of the administration. Because NSO Group typically assigns specific digital signatures and infrastructure to its clients, technical researchers have been able to attribute these attacks to Moroccan intelligence with high confidence. This centralized campaign of state-sponsored hacking is further characterized by the use of dedicated VPN server ranges that overlap across different target groups. Such technical markers provide an undeniable paper trail that connects the digital intrusion directly to the doors of the DGST. These findings illustrate that the government is not an amateur user of imported technology but a highly active operator.

Furthermore, the consistency of these digital fingerprints across various campaigns suggests a highly organized and long-term surveillance strategy. Researchers discovered that the infrastructure used to target domestic dissidents was identical to the systems used against international figures, confirming a unified command structure. This evidence contradicts the state’s official denials, as the technical complexity required to maintain these servers points to a sophisticated government agency rather than a rogue actor or an unidentifiable third party. The data logs recovered from compromised devices showed a pattern of regular updates and maintenance, indicating that the Moroccan intelligence services were deeply involved in the day-to-day management of the spyware. By analyzing the timestamps and geolocation data of the exploits, investigators mapped out a clear timeline of repression that aligned perfectly with periods of civil unrest and political sensitivity.

Evolutionary Tactics: From Eagle to Pegasus

The use of Pegasus is not an isolated event but the latest stage in a twenty-year legacy of digital surveillance that has evolved alongside the internet itself. Before adopting NSO Group’s technology, Morocco utilized several other international spyware systems, including the mass surveillance platform Eagle and the Remote Control System from the Italian vendor Hacking Team. Records indicate that from 2026 to 2028, the Moroccan state will likely continue expanding its licenses to infect thousands of devices across multiple operating systems, demonstrating an industrial-scale commitment to monitoring the communications of its citizens. This historical context is vital because it shows that the state’s appetite for surveillance is structural rather than reactionary. Each new software acquisition represents a step up in capability, moving from basic data collection to the complete remote control of personal devices, ensuring that no pocket of digital resistance remains unmonitored.

To maintain a degree of plausible deniability, the Moroccan government has frequently used private intermediary firms to handle contracts with foreign spyware vendors. This middleman strategy was specifically designed to obscure the paper trail between the state and controversial tech firms, protecting the government from legal or diplomatic backlash in the international arena. Testimony from whistleblowers suggests that the DGST is a highly proactive operator, often testing new surveillance tools on its own officers’ phone numbers before deploying them against high-value political targets and dissidents. This cautious yet aggressive approach ensures that the tools are effective before they are unleashed on activists. By utilizing these layers of separation, the Moroccan state has managed to navigate the complex world of international arms and software regulations while simultaneously building one of the most intrusive surveillance machines in the region.

Strategic Outcomes: Strengthening Global Cyber Norms

The international community responded to these documented abuses by proposing much stricter regulations on the export of dual-use technologies to countries with poor human rights records. Organizations advocated for a global moratorium on the sale of spyware until a comprehensive framework for accountability was established. This proactive approach suggested that the only way to curb the proliferation of tools like Pegasus was through unified diplomatic pressure and the implementation of robust transparency requirements for private vendors. Journalists and activists were encouraged to adopt end-to-end encryption and hardware-based security keys to mitigate the risks posed by zero-click exploits. By focusing on these actionable defenses, civil society aimed to reclaim a degree of digital autonomy in an environment dominated by state-sponsored actors. The shift toward specialized legal frameworks provided a path for victims to seek redress in international courts.

Ultimately, the exposure of Morocco’s surveillance machine served as a catalyst for a broader movement toward digital sovereignty and the protection of human rights in the cyber domain. Tech companies faced increased pressure to patch vulnerabilities more quickly and to notify users when state-sponsored targeting was detected. This created a new layer of protection that made it more difficult and expensive for intelligence agencies to maintain their exploits over long periods. Future considerations for activists involved the use of air-gapped devices for sensitive communications and the decentralization of digital networks to prevent single points of failure. While the Moroccan state attempted to hide behind a veil of disinformation, the global reaction proved that technical evidence could be a powerful tool for accountability. By fostering a culture of digital resilience and demanding international oversight, the victims of Pegasus began to turn the tide against the repressive systems that sought to silence them.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later