13.3 C
Canberra
Wednesday, February 18, 2026

Citizen Lab Finds Cellebrite Software Used on Kenyan Activist’s Telephone in Police Custody


Ravie LakshmananFeb 18, 2026Cellular Safety / Spy ware

Citizen Lab Finds Cellebrite Software Used on Kenyan Activist’s Telephone in Police Custody

New analysis from the Citizen Lab has discovered indicators that Kenyan authorities used a industrial forensic extraction software manufactured by Israeli firm Cellebrite to interrupt right into a outstanding dissident’s telephone, making it the most recent case of abuse of the expertise concentrating on civil society.

The interdisciplinary analysis unit on the College of Toronto’s Munk Faculty of International Affairs & Public Coverage mentioned it discovered the indications on a private telephone belonging to Boniface Mwangi, a Kenyan pro-democracy activist who has introduced plans to run for president in 2027.

Particularly, it has emerged that Cellebrite’s forensic extraction instruments had been used on his Samsung telephone whereas it was in police custody following his arrest in July 2025.

The telephone was returned to him almost two months later, in September, at which level Mwangi discovered that the telephone was now not password-protected and could possibly be unlocked with out requiring a password. It has been assessed with excessive confidence that Cellebrite’s expertise was used on the telephone on or round July 20 and July 21, 2025.

“Using Cellebrite may have enabled the complete extraction of all supplies from Mwangi’s gadget, together with messages, non-public supplies, private information, monetary data, passwords, and different delicate data,” the Citizen Lab mentioned.

The most recent findings comply with a separate report launched final month, wherein the researchers mentioned officers in Jordan doubtless used Cellebrite to extract data from the cell phones of activists and human rights defenders who had been vital of Israel and spoke out in help of Palestinians in Gaza.

The gadgets had been seized by Jordanian authorities throughout detentions, arrests, and interrogations, and subsequently returned to them. The documented incidents passed off between late 2023 and mid-2025, the Citizen Lab mentioned.

In response to the findings, a spokesperson for Cellebrite informed The Guardian that the corporate’s expertise is used to “entry non-public information solely in accordance with authorized due course of or with applicable consent to assist investigations legally after an occasion has occurred.”

The 2 instances add to a rising physique of proof documenting the misuse of Cellebrite expertise by authorities purchasers. It additionally displays a broader ecosystem of surveillance abuses by varied governments world wide to allow highly-targeted surveillance utilizing mercenary spyware and adware like Pegasus and Predator.

Predator Spy ware Targets Angolan Journalist

The event additionally coincides with one other report from Amnesty Worldwide, which found proof that the iPhone belonging to Teixeira Cândido, an Angolan journalist and press freedom advocate, was efficiently focused by Intellexa’s Predator spyware and adware in Could 2024 after he opened an an infection hyperlink acquired through WhatsApp.

The iPhone was operating iOS 16.2, an outdated model of the working system with recognized safety points. It is at present not recognized what exploit was used to set off the an infection. In a number of experiences printed final yr, Recorded Future revealed that it has noticed suspected Predator operations in Angola relationship again to 2024.

“That is the primary forensically confirmed case of the Predator spyware and adware getting used to focus on civil society in Angola,” the worldwide human rights group mentioned. “As soon as the spyware and adware was put in, the attacker may achieve unrestricted entry to Teixeira Cândido’s iPhone.”

“The Predator spyware and adware an infection seems to have lasted lower than at some point, with the an infection being eliminated when Teixeira Cândido’s telephone was restarted within the night of 4 Could 2024. From that point till 16 June 2024, the attackers made 11 new makes an attempt to re-infect the gadget by sending him new malicious Predator an infection hyperlinks. All of those subsequent assault makes an attempt seem to have failed, doubtless because of the hyperlinks merely not being opened.”

In accordance with an evaluation printed by French offensive safety firm Reverse Society, Predator is a industrial spyware and adware product “constructed for dependable, long-term deployment” and permits operators to selectively allow or disable modules primarily based on the right track exercise, granting them real-time management over surveillance efforts.

Predator has additionally been discovered to include varied undocumented anti-analysis mechanisms, together with a crash reporter monitoring system for anti-forensics and SpringBoard hooking to suppress recording indicators from victims when the microphone or digital camera is activated, illustrating the sophistication of the spyware and adware. On high of that, it has specific checks to keep away from operating in U.S. and Israeli locales.

“These findings display that Predator’s operators have granular visibility into failed deployments, […] enabling them to adapt their approaches for particular targets,” Jamf Risk Labs researchers Shen Yuan and Nir Avraham mentioned. “This error code system transforms failed deployments from black packing containers into diagnostic occasions.” 

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles