Where the shells land: a forensic perspective on in-the-wild exploitation
Donncha Ó Cearbhaill (Amnesty International)
Hexacon 2025 · Day 2 · Main Stage
Overview
Donncha Ó Cearbhaill, head of the Security Lab at Amnesty International, delivered the closing keynote at Hexacon, offering a crucial defender's perspective on the offensive cybersecurity industry. His talk, "Where the shells land," delves into the real-world impact of sophisticated surveillance tools and exploits when they are abused against activists, journalists, and opposition politicians globally. Ó Cearbhaill underscored that while the technical brilliance of exploit developers is undeniable, the downstream misuse of these capabilities poses a severe threat to human rights and democratic institutions.

Key moments
- 0:00 Introduction: A defender's perspective at an offensive conference
- 2:15 Information asymmetry and challenges for offensive researchers
- 3:55 Amnesty's Security Lab: Documenting surveillance tool misuse
- 4:40 First Pegasus case: Saudi activist targeted via WhatsApp
- 5:30 Pioneering on-device mobile forensics for spyware
- 6:00 Detailed forensic findings: Matthew Mjib's device compromise
Where the shells land: a forensic perspective on in-the-wild exploitation
Speakers: Donncha Ó Cearbhaill, Head of Security Lab, Amnesty International
Conference: Hexacon
YouTube: https://www.youtube.com/watch?v=zRSv0Cs4tXY
Overview
Donncha Ó Cearbhaill, head of the Security Lab at Amnesty International, delivered the closing keynote at Hexacon, offering a crucial defender's perspective on the offensive cybersecurity industry. His talk, "Where the shells land," delves into the real-world impact of sophisticated surveillance tools and exploits when they are abused against activists, journalists, and opposition politicians globally. Ó Cearbhaill underscored that while the technical brilliance of exploit developers is undeniable, the downstream misuse of these capabilities poses a severe threat to human rights and democratic institutions.
The presentation provided a sobering look at how tools like NSO Group's Pegasus and Intellexa's Predator spyware, alongside forensic tools such as Celebrite, are weaponized to silence dissent, interfere with elections, and enable state-sponsored espionage. Amnesty International's extensive forensic investigations, often in collaboration with partners like Citizen Lab and Access Now, have uncovered countless instances of such abuse. Ó Cearbhaill's objective was to bridge the information asymmetry between offensive researchers and human rights defenders, urging the community to consider the ethical implications of their work and to collectively find ways to prevent harm.
This article dissects Ó Cearbhaill's findings, highlighting the technical methodologies used to uncover these abuses, the specific exploit chains observed in the wild, and the broader defensive implications for the cybersecurity industry. It serves as a call to action for greater transparency, accountability, and human rights due diligence within the offensive cyber market, emphasizing that even well-intentioned research can contribute to severe human rights violations if not carefully managed.
Background
▶ Watch: Introduction: A defender's perspective at an offensive conference (0:00)
Amnesty International, traditionally focused on issues like torture and political prisoners, recognized over a decade ago that technology had become a potent instrument for human rights abuses. This realization prompted the organization to establish a dedicated team of technologists to investigate technologically facilitated harm. One of the earliest cases involved a Saudi Arabian human rights worker who received a suspicious WhatsApp message with a link to a supposed protest. This incident, initially appearing as a targeted phishing attempt, quickly escalated into a full-scale investigation that mapped over 600 servers linked to NSO Group, exposing a wide-ranging surveillance infrastructure.
This initial success spurred Amnesty to develop robust mobile forensics capabilities. A pivotal moment came with the case of Matthew Mjib, a human rights defender from Morocco, whose device showed multiple SMS messages containing Pegasus one-click links. The challenge was not just to prove targeting but to confirm actual compromise. This led to the development of on-device consensual mobile forensics, a methodology to analyze mobile devices for traces of spyware infection. Early investigations, like Mjib's, revealed patterns: opening of known Pegasus domains (e.g., pre247demo.com) in Safari, IndexDB record creation, crash reporter files (e.g., to throttle crash reporting), and the execution of unknown processes like NSO's first-stage payload, Bridgehead (BH), followed by network-communicating spyware processes. Hints of IndexDB use-after-free vulnerabilities were also observed, indicating sophisticated browser exploitation.
The realization that zero-click attacks were becoming prevalent, bypassing user interaction entirely, necessitated a more proactive approach. Amnesty began screening dozens, then hundreds, of phones, a painstaking process akin to vulnerability research where bugs are known to exist but hard to find. To scale these efforts, Amnesty developed Mobile Verification Toolkit (MVT), an open-source tool designed to automate forensic data extraction and analysis for indicators of compromise (IoCs). Despite these efforts, the scale of abuse remained largely underestimated by the public and industry, often dismissed as isolated incidents.
Everything changed with the "Pegasus Project" in 2021. A leaked list of 50,000 phone numbers, identified as potential Pegasus targets globally, confirmed Amnesty's worst fears. This list provided unprecedented insight into the scale and nature of targeting, revealing that widespread abuse was not an exception but a "feature" of these systems. It demonstrated that many governments used these tools on a massive scale, targeting journalists, activists, opposition figures, and even family members of targets, as seen in the case of Azerbaijani investigative journalist Khadija Ismayilova, who was hacked almost weekly for years via iMessage zero-click and other chains. The list also exposed the targeting of senior political figures, including French President Emmanuel Macron, and the use of spyware by democracies like Spain (against Catalan and Basque opposition) and Poland (to interfere with elections by targeting an opposition campaign head). These revelations underscored that the misuse of surveillance technology undermines fundamental democratic principles and human rights globally, transcending the traditional "good guys vs. bad guys" narrative.
Key Findings
▶ Watch: Amnesty's Security Lab: Documenting surveillance tool misuse (3:55)
Donncha Ó Cearbhaill's presentation unveiled several critical findings regarding the landscape of in-the-wild exploitation and its impact:
- Widespread and Systemic Abuse: The "Pegasus Project" list of 50,000 targets confirmed that the abuse of surveillance tools is not incidental but a pervasive, systemic issue. Many government customers of spyware vendors engage in massive-scale targeting, viewing journalists, activists, and opposition figures as threats, rather than exclusively focusing on terrorists or criminals as vendors often claim.
- Targeting Beyond "Bad Guys": The talk unequivocally demonstrated that high-profile spyware like Pegasus and Predator are routinely used against non-criminal targets, including world leaders (e.g., Emmanuel Macron), senior politicians, investigative journalists (e.g., Khadija Ismayilova), human rights defenders, and even their families and associates.
- Abuse by Democracies: The notion that only authoritarian regimes misuse these tools was debunked. Cases in Spain (targeting Catalan and Basque opposition), Hungary (against journalists and business leaders), and Poland (interfering with an election by targeting an opposition campaign manager) highlighted that even countries with ostensible rule of law can weaponize surveillance technology to subvert democratic processes.
- Proliferation and Reuse of Exploits: There is a significant challenge posed by the reuse and proliferation of exploit chains across different threat actors and companies. A single exploit, such as a Chrome sandbox escape or an Android LPE, can be observed in use by multiple sophisticated groups like NSO Group, Intellexa, and Russian APT29, making attribution and accountability difficult. This suggests a vibrant, interconnected market for vulnerabilities and exploit development, often with opaque resale or leakage channels.
- Creative Use of Available Tools: Attackers demonstrate creativity in combining various tools, from advanced remote zero-click exploits to physical access forensic tools, with basic, homegrown spyware. The Serbian cases illustrate this, where sophisticated exploits from Celebrite were used to install a "shitty Android spyware" called Novi spy, highlighting that even non-remote capabilities can contribute to significant human rights abuses.
- Evolving Defensive Capabilities: While the threat is severe, there's an observed improvement in defensive capabilities. Mitigations are becoming more layered, increasing the cost and difficulty for attackers to develop full chains. Furthermore, defenders, including Google TAG and Project Zero, are getting better at finding and patching in-the-wild exploits more quickly, often aided by vendors like Apple, WhatsApp, and Google proactively notifying victims.
- Increased Scrutiny and Accountability for the Industry: The offensive cyber industry is no longer operating entirely "under the radar." Governments and international bodies are beginning to take action, including placing companies like NSO Group and Candiru on the US Commerce Entity List, imposing financial sanctions on Intellexa executives, and initiating criminal prosecutions in countries like Greece. This signals a growing push for financial, criminal, and regulatory accountability for actors contributing to human rights violations.
Technical Deep Dive
▶ Watch: First Pegasus case: Saudi activist targeted via WhatsApp (4:40)
The talk provided compelling technical detail through several in-the-wild case studies from Serbia, illustrating the diverse methods and exploit chains employed by state actors.
1. Pegasus One-Click Links (Serbia)
Even after numerous scandals, Pegasus remains active. Two investigative journalists in Serbia were targeted via Viber messages containing one-click links, disguised as legitimate source communication. While these journalists were not compromised due to their suspicion, the incident demonstrated the continued use of Android and iOS exploit chains by NSO Group's customers. This highlights the persistent threat of sophisticated, remote exploitation via social engineering, even for well-informed targets.
2. Physical Access Exploitation via Celebrite (Slavasa Milanov Case)
Investigative journalist Slavasa Milanov was subjected to a fabricated police checkpoint and detention. During his questioning, his phone was taken without consent or a warrant. Forensic analysis revealed a precise timeline of compromise:
- The phone was turned on.
- Evidence of a "non-standard boot" suggested tampering with the bootloader.
- A crash associated with a Celebrite product was identified. Celebrite tools, typically used for legal forensics, were repurposed.
- The Celebrite product successfully gained root privileges on the phone.
- The attacker then extracted the phone's PIN code.
- After a reboot, the phone was unlocked, a file manager was opened, and prompts to install an Android APK from outside the Play Store were observed.
- A sample of this installed APK was later identified as Novi spy, a homegrown spyware used by Serbian secret intelligence services.
This case underscores that even seemingly basic spyware can be delivered via advanced, physical-access exploits, challenging the perception that only remote zero-days pose significant threats. The attackers creatively leveraged a powerful forensic tool for surreptitious spyware installation.
3. Qualcomm ADSP RPC Driver Zero-Day (Ivan Belch Case)
Environmental activist Ivan Belch, targeted for his activism against lithium mines, had his phone seized during a detention. Although no spyware traces were found, forensic logs indicated a zero-day exploit had been run. Specifically, crash logs showed a binary named Falcon (attributed to Celebrite EUD) making numerous calls to octals on the ADSP RPC driver. This driver, a custom Qualcomm memory mapping driver, was being exploited to gain root access.
Amnesty shared these logs with Google Project Zero. Seth Jenkins of Project Zero conducted an audit of the driver, discovering multiple exploitable memory corruption bugs. One of these, CVE-43047, was identified as the vulnerability likely exploited in the wild as part of the Celebrite chain. This demonstrates the discovery of sophisticated kernel-level vulnerabilities being actively exploited for privilege escalation in physical access scenarios.
4. Emulated USB Device Exploitation (Student Protester Case)
A student protester, picked up by plainclothes police, had his phone confiscated. Forensic analysis revealed an attempt to install Android APK spyware after gaining root access. The key technical detail here was the use of emulated USB devices to unlock the Android device. The logs showed a sequence of USB device connections:
- HID mouse with a specific Vendor ID (VID) and Product ID (PID). This VID/PID combination triggered a specific "quirk code" in the Linux kernel for device loading, suggesting its use in vulnerability checking or initial setup.
- A USB hub was connected, followed by another HID mouse device.
- A UVC webcam (Linux webcam device) with a unique VID/PID was connected. Collaborating with Benwis Stevens of Google Project Zero, an "out-of-bounds write" vulnerability was found in the UVC driver associated with this specific device, allowing memory corruption.
- Finally, XCG sound card and FastTrack Pro sound card devices were connected. Forensic logs indicated successful exploitation involving these devices. The observation that two different devices were connected, but then both appeared as the same device upon disconnection, suggested USB descriptor corruption. Stevens confirmed a quirk in the XG kernel code that allowed an attacker to overwrite the original USB device descriptor with a new one, causing memory corruption and ultimately unlocking the device. This chain of vulnerabilities, patched last year, showcased a complex, multi-stage physical access exploit leveraging multiple kernel drivers.
These cases collectively illustrate the technical sophistication of state-backed actors and the diverse attack surfaces they target, ranging from remote browser exploits to deeply technical kernel vulnerabilities leveraged through physical access. The collaboration with Google Project Zero and other researchers was instrumental in dissecting these complex in-the-wild exploit chains.
Demo / Proof of Concept
▶ Watch: Pioneering on-device mobile forensics for spyware (5:30)
While Donncha Ó Cearbhaill's talk did not feature a live demonstration or a proof of concept developed by Amnesty International in the traditional sense of an offensive security conference, the entire presentation served as a robust "proof of concept" of in-the-wild exploitation through detailed forensic evidence. The methodologies and findings presented are, in essence, the results of Amnesty's forensic "demos" of how these attacks unfold on real-world devices.
The talk meticulously detailed the forensic artifacts and timelines observed on compromised devices, effectively demonstrating how spyware like Pegasus and Novi spy are deployed and operate. For instance, the Matthew Mjib case provided a step-by-step reconstruction of a Pegasus one-click infection, tracing the opening of a malicious webpage, IndexDB record creation, crash reporter files, and the execution of NSO's Bridgehead payload. This forensic timeline acted as a "demo" of the exploit chain in action.
Similarly, the Serbian case studies provided compelling evidence of physical access attacks. The Slavasa Milanov incident, where Celebrite tools were used to extract a PIN and install Novi spy, was reconstructed through boot logs, crash reports, and file system modifications, illustrating the attacker's operational procedure. The Ivan Belch case, with its specific crash logs pointing to a Qualcomm ADSP RPC driver zero-day (CVE-43047), and the student protester case, detailing the sequence of emulated USB devices and USB descriptor corruption for Android unlocking, offered deep technical insights into the exploit primitives and their effects.
These forensic reconstructions, supported by collaborations with researchers like Seth Jenkins and Benwis Stevens from Google Project Zero, effectively served as "proofs of concept" of the attackers' capabilities. They illustrated the technical mechanisms of compromise, the specific vulnerabilities targeted, and the post-exploitation activities, providing concrete, real-world examples of how these "shells land" on target devices. Amnesty's MVT (Mobile Verification Toolkit), though not demonstrated live, is the foundational tool that enables these forensic investigations, allowing for scalable and reliable detection of such compromises.
Defensive Implications
▶ Watch: Detailed forensic findings: Matthew Mjib's device compromise (6:00)
The insights shared by Donncha Ó Cearbhaill carry profound implications for defenders, emphasizing the need for a multi-faceted approach to combat the pervasive threat of state-sponsored surveillance and exploit misuse.
- Prioritize Transparency and Accountability: The "information asymmetry" between offensive developers and defenders must be addressed. Companies developing and selling exploits must implement rigorous human rights due diligence, including auditing potential customers, having strict contractual agreements on use, and ongoing monitoring for abuse. When exploits are leaked or misused, companies should proactively report it to vendors for patching and publicly name/shame bad actors or customers who violate terms. Without this, all players in the offensive market risk being painted with the same brush as NSO or Intellexa.
- Bolster Device Hardening and Mitigation Layers: The increasing difficulty and cost of developing full exploit chains against modern, well-hardened devices (e.g., latest iOS/Android) is a positive trend. Defenders, including OS vendors like Apple and Google, must continue to invest heavily in mitigation bypasses, memory safety, kernel hardening, and sandboxing to raise the bar for attackers. The observed shift towards more layered mitigations suggests that continuous investment in defensive security engineering is effective.
- Enhance In-the-Wild Exploit Detection: Google TAG and Project Zero's increasing success in finding and patching in-the-wild exploits is crucial. Defenders should leverage threat intelligence from these groups and civil society organizations like Amnesty to understand current attack vectors. Tools like Amnesty's MVT provide a framework for organizations to conduct their own forensic analysis for indicators of compromise (IoCs), moving beyond reactive patching to proactive detection.
- Recognize and Address Physical Access Threats: The Serbian cases highlight that sophisticated physical access attacks, often leveraging advanced forensic tools like Celebrite in conjunction with zero-day exploits (e.g., Qualcomm ADSP RPC driver CVE-43047, USB descriptor corruption via emulated devices), are a significant vector. Defenders must educate high-risk individuals about the dangers of device seizure, implement strong device encryption, and consider policies for handling devices during travel or interactions with authorities. Strong PINs/passwords and device lock-down features are critical.
- Understand Exploit Proliferation: The reuse of exploit primitives (e.g., a Chrome sandbox escape) across multiple state-backed actors (NSO, Intellexa, APT29) indicates a robust and often opaque market for vulnerabilities. Defenders should be aware that a patch for one actor's exploit may impact others. Vigilance against common attack patterns and rapid deployment of patches are essential, as widely shared bugs can quickly resurface in new campaigns.
- Support Legal and Policy Frameworks: The growing international pressure, including US entity list designations (NSO Group, Candiru), Treasury sanctions (Intellexa executives), and criminal prosecutions (Greece), signals a global shift towards holding the offensive cyber industry accountable. Defenders, particularly those in critical infrastructure or human rights, should advocate for stronger national and international regulations, export controls, and human rights impact assessments for surveillance technology.
- Foster Cross-Community Collaboration: Ó Cearbhaill's presence at Hexacon underscores the importance of dialogue between offensive and defensive communities. Offensive researchers, with their deep technical expertise, have a unique opportunity to contribute to defense by reporting vulnerabilities responsibly, scrutinizing their clients, and refusing to work with entities known for abuse. Collaborations between civil society, academic researchers, and commercial vendors (e.g., Google's Advanced Protection Mode) are vital for developing robust defenses against these evolving threats.
Key Takeaways
- The abuse of surveillance technology, including advanced spyware like Pegasus and Predator, is widespread and systemic, disproportionately targeting journalists, activists, and opposition politicians globally.
- Even democratic nations and their law enforcement agencies (e.g., Spain, Poland, Hungary, ICE in the US) have been implicated in misusing these tools, challenging the narrative that they are only sold to "good guys."
- Exploits, whether remote zero-clicks or those leveraging physical access tools like Celebrite, are often reused and proliferate across various state-backed threat actors, demonstrating an opaque and interconnected market for vulnerabilities.
- Detailed forensic investigations, as conducted by Amnesty International's Security Lab using tools like MVT, are critical for uncovering the technical specifics of in-the-wild exploit chains, including complex kernel-level vulnerabilities (e.g., Qualcomm ADSP RPC driver CVE-43047, USB descriptor corruption).
- The offensive cyber industry faces increasing scrutiny and accountability, with governments imposing sanctions and initiating criminal prosecutions against companies and individuals involved in human rights abuses, signaling a shift in the regulatory landscape.
- Offensive security researchers and companies have a significant ethical responsibility to conduct rigorous human rights due diligence, demand transparency from clients, and proactively report misuse or leaked exploits to vendors to mitigate harm.
About the Speaker(s)
Donncha Ó Cearbhaill is the Head of the Security Lab at Amnesty International. In this role, he leads deep technical investigations and forensic research to document and expose the misuse of surveillance tools against human rights defenders, journalists, and other civil society actors worldwide. His work involves analyzing compromised devices, attributing attacks to specific spyware vendors and state actors, and publishing findings to raise awareness and push for accountability. Ó Cearbhaill's expertise is rooted in understanding the offensive cyber industry from a defensive perspective, driven by a commitment to protect vulnerable populations from technology-facilitated human rights abuses. His experience includes uncovering early cases of NSO Group's Pegasus spyware and developing forensic methodologies and tools like MVT to scale these investigations.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Donncha Ó Cearbhaill delivers something increasingly rare at offensive security conferences: a talk grounded in real forensic casework that forces the technical community to confront where their craft actually lands. The Serbia case studies alone — Celebrite-chained Qualcomm ADSP RPC driver exploitation, multi-stage emulated USB device attacks tracing through HID, UVC, and XCG driver vulnerabilities — are genuine technical contributions, not recycled awareness talking points. This isn't a human rights lecture dressed up with screenshots; it's forensic reverse engineering of in-the-wild exploit chains that led to real CVE discoveries in collaboration with Project Zero. The ethical framing…
Heather Calloway (CISO) — STRONG ACCEPT
Donncha Ó Cearbhaill delivers something rare in offensive security conference culture: a technically grounded, forensically rigorous account of what happens downstream when exploit capabilities are sold without accountability. The talk earns its place not because it is technically spectacular — though the USB descriptor corruption chain and the Qualcomm ADSP RPC driver findings are substantive — but because it forces a room full of offensive researchers to confront the institutional consequences of their work. The governance and accountability framing is genuine, not performative. The cases are specific, documented, and cross-validated with Google Project Zero. Where it falls short is in…