The discovery of technical fingerprints across multiple platforms confirms that Morocco’s use of Pegasus was not limited to criminal investigations but extended to political leverage. For over a decade, the Moroccan government has meticulously constructed a pervasive digital surveillance apparatus, transforming the North African nation into a prominent example of how states can weaponize commercial spyware. This effort is largely orchestrated by the General Directorate for Territorial Surveillance, an agency that has shifted from traditional monitoring to a high-tech “state-as-service” model of digital warfare. By embedding these intrusive tools into the very fabric of its national security framework, the state has created an environment where dissent is not only monitored but actively suppressed. This systematic campaign seeks to silence critics and maintain a rigid grip on the narrative, affecting everyone from domestic activists to international observers who monitor the region’s human rights landscape closely.
Institutional Infrastructure: Tactical Deployment of Spyware
To preserve a facade of legality and maintain plausible deniability, the Moroccan intelligence community has historically operated through a labyrinthine network of private intermediary firms and offshore financial arrangements. By utilizing these third-party conduits to procure software from vendors like NSO Group, the state successfully obscured the direct paper trail that would otherwise link government coffers to the suppression of civil society. This logistical obfuscation was intended to shield the administration from international sanctions and diplomatic fallout. However, forensic analysts eventually pierced this veil of secrecy by identifying NSO Group VPN servers operating within IP ranges specifically assigned to Moroccan intelligence services. These technical bridges provided irrefutable evidence of a direct pipeline between the spyware manufacturer and the Moroccan state. Such a complex procurement strategy highlights the lengths to which modern regimes will go to hide their digital footprints.
The internal administration of the Pegasus system within Morocco appears to be a highly disciplined and centralized operation rather than a series of isolated incidents by rogue agents. Evidence suggests that intelligence officers conducted rigorous testing of the software on their own personal devices before initiating deployment against high-value targets, ensuring the exploits were functioning correctly. This level of bureaucratic oversight indicates that the surveillance of journalists and activists was a formal, state-sanctioned policy. Forensic investigations into compromised devices revealed consistent “technical fingerprints,” such as specific Apple iCloud accounts and email addresses that were reused across multiple targeting operations. These shared identifiers link various attacks together, proving that the same state infrastructure used for domestic political control was also utilized for international espionage. This centralized command structure allowed for a seamless transition between monitoring internal critics and tracking foreign officials.
Target Identification: The Human Impact of Surveillance
The victims of this digital dragnet represent the core of Morocco’s independent civil society, including investigative journalists and outspoken media activists who strive to provide transparent reporting. Figures like Hicham Mansouri and the members of the Mamfakinch collective have faced relentless digital intrusion designed to harvest their private communications and intimidate their sources. By compromising the smartphones of these individuals, the state effectively dismantled the safety of anonymous whistleblowing, leading to a profound chilling effect across the Moroccan media landscape. The impact of such surveillance extends beyond the immediate loss of privacy; it often precedes physical harassment, legal prosecution, and social isolation. When a journalist’s every movement and conversation is monitored in real-time, the ability to perform independent watchdog functions is severely compromised. This systematic targeting ensures that the government can anticipate and neutralize potential scandals before they ever reach the public.
Moreover, the Moroccan government’s use of Pegasus has transcended domestic borders, evolving into a potent instrument for international leverage and geopolitical maneuvering. High-profile foreign political figures, including members of the Spanish cabinet and prominent French politicians, were identified as potential targets of interest for the Moroccan security services. This expansion of the surveillance scope suggests that the General Directorate for Territorial Surveillance views digital espionage as a primary tool of foreign policy, allowing them to gather sensitive intelligence on diplomatic rivals and allies alike. By gaining access to the private data of international leaders, the state can exert clandestine influence and anticipate foreign policy shifts that might affect its interests. This aggressive posture has strained diplomatic relations with European neighbors, highlighting the risks of allowing unregulated spyware to become a standard component of statecraft. The use of such technology against foreign sovereigns marks a significant escalation.
Defensive Tactics: State Narratives and Forensic Accountability
In the face of overwhelming forensic evidence and international condemnation, the Moroccan government has refined a strategy of aggressive denial and sophisticated disinformation. State-aligned media outlets frequently serve as the primary vehicles for this counter-offensive, publishing articles that dismiss technical findings as “fragile” or entirely fabricated. These platforms often frame investigative reports from non-governmental organizations as biased narratives aimed at sabotaging Morocco’s economic growth or its standing on the global stage. By characterizing objective technical data as a form of political “incitement,” the state attempts to rally domestic public opinion against external critics and international human rights bodies. This rhetorical strategy avoids addressing the specific technical proofs—such as server logs and infection timestamps—and instead focuses on questioning the motives of the investigators. This environment of total denial makes legal accountability nearly impossible within the current domestic framework.
The sustained campaign of digital espionage carried out by the Moroccan state demonstrated how unregulated private surveillance technology could be seamlessly integrated into a broader machinery of repression. This historical evolution from simple phishing to complex zero-click exploits reflected a deliberate investment in tools that bypassed traditional security measures. Moving forward, the international community must prioritize the establishment of a global moratorium on the sale and transfer of intrusive spyware until a robust human rights framework is implemented. Civil society organizations should consider adopting advanced hardware-based security keys and end-to-end encrypted communication platforms that are less susceptible to standard mobile exploits. Furthermore, judicial systems in democratic nations where these software companies operate must hold vendors accountable for the actions of their clients. Only through a combination of technical resilience and international legal pressure can the cycle of state-sponsored digital intimidation be effectively curtailed.






