Skip to content
Make AI Good

Graph · Campaign

iLaw / DigitalReach Asia / Citizen Lab GeckoSpy and Parasite That Smiles — Pegasus spyware civil society accountability campaign, Thailand (2021–ongoing)

01 · In focus

One campaign, in the field.

The structured facts the source records about iLaw / DigitalReach Asia / Citizen Lab GeckoSpy and Parasite That Smiles — Pegasus spyware civil society accountability campaign, Thailand (2021–ongoing), the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.

campaign

4 declared connections

Kind
Campaign
Status
active
Confidence
high
Start
2021-11
End
ongoing
Entity ID
camp-ilaw-pegasus-civil-society-thailand-2022
Network
View in network

Tags thailand, southeast-asia, bangkok, spyware, pegasus, nso-group, mercenary-spyware, surveillance, ai-surveillance, civil-society, coalition, strategic-litigation, digital-rights, pro-democracy, freedom-of-assembly, freedom-of-expression, zero-click-exploit, forensic-investigation, legal-accountability, lese-majeste

iLaw / DigitalReach Asia / Citizen Lab GeckoSpy and Parasite That Smiles — Pegasus spyware civil society accountability campaign, Thailand (2021–ongoing) · 2 direct neighbours visible

02 · Connections

4 adjacencies, by relation.

Split by direction. Direct links are the ones iLaw / DigitalReach Asia / Citizen Lab GeckoSpy and Parasite That Smiles — Pegasus spyware civil society accountability campaign, Thailand (2021–ongoing)’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity.

Direct from this record

4 links

Links named in this entity's structured fields.

03 · Background

From the source record.

Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.

On 17 July 2022, Citizen Lab published the GeckoSpy report and, simultaneously, Internet Law Reform Dialogue (iLaw) and DigitalReach Asia published the companion report Parasite That Smiles: Pegasus Spyware Targeting Dissidents in Thailand — together the first technically confirmed documentation of NSO Group's Pegasus mercenary spyware deployed against a Thai civil society population. The joint investigation, triggered by Apple state-sponsored-attack notifications to Thai activists in November 2021, forensically confirmed at least 30 infections among pro-democracy activists, lawyers, academics, and NGO workers during the 2020–2021 Thai protest wave, and attributed the targeting on circumstantial grounds to one or more Thai government operators. The campaign is the corpus's first Thailand entry and its principal case of mercenary spyware deployed against a grassroots democratic movement in Southeast Asia — a Thai-civil-society-led accountability effort that ran from forensic investigation through regional court litigation over three years.

The November 2021 Apple notifications and the launch of the investigation

The campaign's effective start was November 2021, when Apple sent state-sponsored-attack notifications to six Thai activists whose iPhones had been compromised, alerting them that state-sponsored attackers may have targeted their devices. Multiple recipients contacted DigitalReach Asia and Citizen Lab in the days that followed — the intersection between Apple's notification infrastructure and an established regional digital-rights lab and local civil society intermediary that the campaign's partners had spent years building. Citizen Lab's technical analysts, led by John Scott-Railton and Bill Marczak, performed mobile device forensics on the notified targets' iPhones; iLaw conducted a wider field survey of Thai civil society from March to June 2022 to identify additional potential victims, collect devices for examination, and provide local civil society knowledge about the targets' roles, movements, and political activities that contextualised the forensic findings. Amnesty International's Security Lab independently confirmed five of the identified infections through its own forensic methodology, supplying the cross-lab verification standard that the global Pegasus Project investigative consortium had established as the baseline for credible spyware-infection claims.

The July 2022 reports: GeckoSpy and Parasite That Smiles

The two companion reports published on 17–18 July 2022 documented 30 forensically confirmed Pegasus infections among Thai civil society members, with infections observed from October 2020 to November 2021 — a window coinciding with the peak of Thailand's largest pro-democracy protest wave since the 2010 Red Shirt demonstrations and with the period during which the Thai government was prosecuting protest leaders under lèse-majesté (Section 112), sedition, and computer-crime charges. The Citizen Lab GeckoSpy technical report — named "GeckoSpy" for the threat actor label assigned to the Thai government Pegasus operator — provided the mobile forensics, exploit identification, and attribution analysis. The iLaw/DigitalReach Asia Parasite That Smiles companion provided the Thai political and legal context, named the individuals affected, and carried the legal-reform recommendations directed at the Thai legislature. The reports were the culmination of an eight-month joint investigation distributed across three organisations — Citizen Lab's technical forensics, DigitalReach Asia's regional coordination, and iLaw's local civil society embeddedness — and represented the campaign model the global Pegasus accountability community had developed since the July 2021 Pegasus Project revelations: a technical research lab confirming what a frontline local NGO shaped and a regional digital-rights organisation bridging between the two.

Infection targets: activists, lawyers, and academics

The GeckoSpy report named four individuals among the most heavily targeted. Panusaya Sithijirawattanakul — a University of Thammasat Student Union member and UFTD (United Front of Thammasat and Demonstration) spokesperson whose August 2020 speech formulating the protest movement's ten-point monarchy-reform agenda made her one of the most publicly visible targets of the Thai state's Section 112 prosecution campaign — was forensically confirmed infected six times between June and September 2021 and faced at least ten lèse-majesté charges and 85 days of detention. Arnon Nampa — the human rights lawyer and protest co-organiser who was among the first to publicly call for constitutional monarchy reform at a Bangkok rally in August 2020 — was confirmed infected five times across 2020 and 2021; by the time of the report's publication Nampa had faced fourteen or more lèse-majesté charges and been detained 339 days. Jatupat Boonpattararaksa — a Thalufah movement leader known by his protest name Pai Dao Din — was confirmed infected three times in June and July 2021. Jutatip Sirikhan, a FreeYOUTH member, was confirmed infected six times starting October 2020. Beyond these named cases the reports documented infections across WEVO and UFTD network activists, academics who had publicly commented on the protests, artists, journalists, and civil society workers — a targeting pattern that mapped directly onto the Thai government's prosecution and suppression campaign against the 2020–2021 protest movement. Circumstantial evidence cited for Thai government attribution included the alignment of infection timing with specific protest events, court hearings, and arrest decisions in individual targets' cases; the targeting of individuals of known interest to the domestic surveillance apparatus; and Citizen Lab's historical evidence of Pegasus deployment in Thailand extending back to 2014.

Zero-click exploits: KISMET and FORCEDENTRY

The technical finding at the centre of the GeckoSpy investigation was that the Thai government Pegasus operator deployed two successive generations of zero-click exploits against the targets' iPhones: KISMET — a zero-click exploit transmitted via malicious image files, active from October 2020 to early 2021 — and FORCEDENTRY — a zero-click iMessage exploit using malicious PDF files, active from February to November 2021 until Apple patched the vulnerability in iOS 14.8 following Citizen Lab's disclosure to Apple in September 2021. Zero-click exploits require no action by the target — no link to click, no file to open — and leave minimal traces, requiring the specialised mobile-device forensics the investigation applied. FORCEDENTRY was, at the time of its use, the most sophisticated commercially sold spyware exploit then known; NSO Group had charged governments a premium for access to it. The campaign's finding that the Thai government had deployed both exploits — the top tier of NSO's commercial catalogue across the relevant window — against student protest leaders and human rights lawyers is the corpus's primary documented case of a state spending premium mercenary-spyware capabilities against domestic democratic civil society rather than against foreign intelligence targets or violent non-state actors, as NSO had publicly stated was the product's intended use.

The legal response: class action, individual lawsuit, and dismissal

The campaign's legal phase ran from November 2022 to November 2024 across two parallel tracks. On 15 November 2022, eight Pegasus victims — including Jatupat Boonpattararaksa and Yingcheep Atchanont, iLaw's manager — jointly filed a class-action lawsuit against NSO Group at the Bangkok Civil Court seeking damages and a halt to NSO's operations against Thai citizens; the court dismissed the joint case on the grounds that the infections had not occurred simultaneously and therefore did not constitute a single class. On 13 July 2023, Jatupat filed an individual lawsuit against NSO Group seeking 2.5 million Thai baht in damages for privacy violation, access to and deletion of his data from NSO's systems, and a court order halting NSO's use of Pegasus against Thai citizens. Separately, in June 2023 pro-democracy lawyer Arnon Nampa and Yingcheep Atchanont filed a civil lawsuit against nine Thai government agencies for unlawful surveillance — the track targeting the state directly rather than NSO. In June 2024, mediation between Jatupat and NSO failed: NSO declined to disclose which Thai government entity purchased Pegasus and offered a partial settlement — half the requested amount, approximately 1,250,000 Thai baht — conditioned on a non-disclosure agreement, which Jatupat rejected. Witness hearings were held at the Ratchada Civil Court in Bangkok in September 2024. On 21 November 2024, the Bangkok Civil Court dismissed Jatupat's individual case, ruling he had not adequately presented the forensic investigation's details to the court's satisfaction. Amnesty International characterised the ruling as "a critical and alarming setback in fight against unlawful use of spyware" and stated the dismissal would not deter the ongoing fight. The lawsuit by Nampa and Atchanont against Thai government agencies was still pending as of late 2024.

Place in the make-AI-good movement

The campaign matters to the wider make-AI-good corpus on three connected counts. First, it is the corpus's first Thailand campaign entry and closes a major Southeast Asian civil society gap: the corpus had campaign entries for Indonesia, the Philippines, and Pakistan, but Thailand — one of the most heavily surveilled non-authoritarian societies in Asia per Freedom House's reporting — had no grassroots AI-accountability campaign anchor. The GeckoSpy/Parasite That Smiles investigation fills that gap as a canonical case study in civil society resistance to AI-enabled state surveillance: iLaw's local civil society embeddedness, DigitalReach Asia's regional coordination, and Citizen Lab's technical forensic capacity operated as a mutually reinforcing triad that no single organisation could have replicated alone, demonstrating the researcher–civil-society partnership model Citizen Lab's corpus entry identifies as its principal contribution to the make-AI-good field. Second, the campaign is the corpus's primary documented case of mercenary spyware — NSO Group's Pegasus, a commercial AI-enhanced surveillance product sold by an Israeli company to governments — deployed against a grassroots democratic movement in Southeast Asia; the targeting was of student protest leaders, human rights lawyers, and NGO workers pressing for constitutional reform, and the campaign's evidence base is the cleanest technical proof available that commercial surveillance companies' end-use claims about their customers' deployment practices are not self-enforcing without external civil society scrutiny. Third, the campaign's legal track — the November 2022 class action, the July 2023 individual lawsuit, the failed mediation, and the November 2024 dismissal — is the corpus's first recorded instance of an NSO Group legal accountability case pursued by a civil society plaintiff inside an Asian national court system, structurally distinct from the Apple v. NSO case in US federal court and directly relevant to the broader make-AI-good field's emerging question of how transnational AI-enabled harm can be adjudicated when the harm, the company, the state purchaser, and the victims are each in different legal jurisdictions.

04 · Sources

Where this came from.

6 sources listed from the pinned corpus. Links are shown only when the source URL is a valid HTTP(S) address.

  1. citizenlab.ca

    Checked 2026-06-08

    Citizen Lab GeckoSpy report (17 July 2022) — primary source for the forensic methodology, 30 forensically confirmed infections (October 2020–November 2021), the two zero-click exploits (KISMET and FORCEDENTRY), named infection counts for Panusaya Sithijirawattanakul (6 infections June–September 2021), Arnon Nampa (5 infections 2020–2021), Jatupat Boonpattararaksa (3 infections June–July 2021), Jutatip Sirikhan (6 infections from October 2020), circumstantial attribution to Thai government operators, report authors (John Scott-Railton, Bill Marczak, Irene Poetranto, Bahr Abdul Razzak, Sutawan Chanprasert, Ron Deibert), and Amnesty International Security Lab's independent verification of five cases

  2. ilaw.or.th

    Checked 2026-06-08

    iLaw's published landing page for the Parasite That Smiles companion report (July 2022) — primary source for iLaw and DigitalReach Asia as co-authors, the Thailand-specific policy and legal-reform recommendations, and iLaw's role in the March–June 2022 civil society field survey

  3. amnesty.org

    Checked 2026-06-08

    Amnesty International (18 July 2022) — independent secondary source confirming Amnesty Security Lab's forensic verification of five cases; primary source for Amnesty's demand for a global moratorium on spyware sales and its call on Thai authorities to launch an independent investigation and amend the Computer Crimes Act, Cybersecurity Act, and National Intelligence Act; names Arnon Nampa, Benja Apan, and Panusaya Sithijirawattanakul as confirmed targets

  4. aljazeera.com

    Checked 2026-06-08

    Al Jazeera (18 July 2022) — mainstream news secondary source for the joint investigation's public release; names iLaw, DigitalReach, and Citizen Lab as the co-investigating organisations; names Emilie Pradichit of the Manushya Foundation as a Bangkok human rights commentator; records Thai government spokesman Thanakorn Wangboonkongchana's denial that the reports were "untrue" and Digital Economy Minister's statement he could "guarantee there are no attacks"

  5. manushyafoundation.org

    Checked 2026-06-08

    Manushya Foundation account of Jatupat Boonpattararaksa's legal battle — primary source for the November 2022 class-action filing by eight victims, the June 2023 separate lawsuit by Arnon Nampa and Yingcheep Atchanont against nine Thai government agencies, the June 2024 mediation and NSO's partial-settlement offer with non-disclosure clause, and the September 3–5 and 10 2024 witness hearings at Ratchada Civil Court in Bangkok

  6. amnesty.org

    Checked 2026-06-08

    Amnesty International (21 November 2024) — primary source for the Bangkok Civil Court's dismissal of Jatupat's individual case, the court's ruling that he had not adequately presented forensic evidence, Amnesty's "critical and alarming setback" characterisation, and the statement that the dismissal "won't deter the fight against unlawful use of spyware"

Source: entities/campaigns/camp-ilaw-pegasus-civil-society-thailand-2022.md — movement-graph pin 5d136ad.