Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Privacy

Codename Morgan: inside Morocco’s Pegasus machine

Ransomnews Research TeamBy Ransomnews Research TeamJuly 22, 2026No Comments11 Mins Read147 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Codename Morgan: how Morocco ran Pegasus, a Forbidden Stories investigation, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Morocco is the NSO Group customer that the company internally codenames “Morgan”. A July 2026 Forbidden Stories investigation, with Amnesty International’s Security Lab as technical partner, retraces how Morocco’s domestic intelligence service acquired Pegasus through an Emirati intermediary in 2017, selected roughly 12,000 phone numbers, and left forensic traces on the devices of journalists and foreign officials, including seven French ministers. Morocco has always denied using the spyware.

This piece is a companion to our technical breakdown of how the Pegasus system works, drawn from NSO’s own unsealed court files. Where that analysis explained the machine, this one follows a single customer: what “Morgan” bought, who ran it, and how the trail was reconstructed. The reporting is the work of Forbidden Stories journalists José Bautista, Eloïse Layan, Hicham Mansouri and Guillaume Vénétitay, with forensic analysis by Amnesty’s Security Lab. Ransomnews summarises and analyses their findings here.

Who is “Morgan”?

“Morgan” is the internal alias NSO used for Morocco’s General Directorate for Territorial Surveillance, the DGST. Multiple sources across the cyber-surveillance industry confirmed the codename to Forbidden Stories, and it also appears in an NSO document made public through the US litigation. The name fits a pattern the consortium describes: NSO’s client aliases tend to borrow a country’s opening letters and lean on car brands, and Morgan is a British marque. It is a small detail, but it matters, because a codename in NSO’s paperwork is one more thread tying the company to a customer it has never publicly named.

The villa in Rabat: how Morocco got Pegasus

Morocco’s first close look at Pegasus came in late 2017, at a discreet Rabat property that DGST agents nicknamed “Villa FSSYS”. For ten days, according to a former DGST agent Forbidden Stories calls Safir, NSO staff demonstrated the spyware on sample phones, remotely switching on cameras and microphones and extracting messages. In 2017, Safir recalls, the target still had to click a link. By 2019 an anonymous call was enough, and the phone was infected “within five seconds”. He describes Pegasus as “the monster’s weapon”.

The deal did not run directly between Rabat and NSO’s headquarters in Herzliya. It ran through an Emirati intermediary. The villa took its nickname from FSSYS Maroc, the Moroccan branch of Al Fahad, an Abu Dhabi company that now sits inside Etimad and, in turn, under Edge, the Emirati government’s large defence and aerospace group. Forbidden Stories reports that a Moroccan point of contact managed updates and reported infiltration figures for invoicing, and served as the channel to the office of Fouad el Himma, a powerful adviser to King Mohammed VI, on high-value targets. This was not a new arrangement: leaked 2015 emails from the Italian firm Hacking Team already show the DGST buying that company’s RCS spyware through the same intermediary, listed as the “end user in Morocco”.

Who ultimately paid is the part the consortium could not confirm. One theory circulating inside the DGST, relayed by Safir, is that the Emiratis footed the bill and shared access, likened to friends splitting a streaming subscription. Two other sources leaned the same way, but a former NSO employee said they knew of no such UAE payment to Morocco. Pegasus is not cheap. To illustrate NSO’s pricing, Forbidden Stories published a 2012 letter to Panama’s government, signed by NSO co-founder Shalev Hulio, recording an 8 million dollar installation for 300 simultaneous targets. Against that yardstick, a client with roughly 12,000 selected numbers is operating at a very different scale.

Morocco’s Pegasus era, on a timeline ransomnews.com 2015Hacking TeamRCS (via broker) 2017Rabat demo“Villa FSSYS” 2019Zero-click“5 seconds” Jul 2021PegasusProject Nov 2021last traces Jul 2026disclosed

How many were targeted, and who?

The scale comes from the leaked dataset at the heart of the 2021 Pegasus Project, a list of numbers selected as potential targets that Forbidden Stories and Amnesty obtained five years ago. Just over 12,000 of those numbers are attributed to the Moroccan client. That figure needs a careful caveat, and the consortium supplies it: selection is not the same as infection. Some numbers may have been entered as tests, and others cycled in and out of active surveillance over months. Selection does, however, show intent, and where devices have been examined forensically, Amnesty has confirmed real infections. Domestically, the documented targets include Moroccan journalists and activists. The email accounts used against them become important in a moment, because one of them reaches far beyond Morocco’s borders.

The France thread: spying on a partner it wanted to court

The most striking new revelation concerns France. Forbidden Stories reports that seven French ministers’ phones show “signs of compromise” by Pegasus in 2019 and 2020, all linked to Morocco: Jean-Michel Blanquer, Jacqueline Gourault, Julien Denormandie, Emmanuelle Wargon, François de Rugy, Florence Parly and Sébastien Lecornu, who is now France’s prime minister and was targeted in July 2019. The timing is the sting. At the very moment Morocco was allegedly inside French ministers’ phones, France was seriously weighing whether to buy Pegasus itself. NSO’s exclusive French reseller, the Angoulême firm Syans, quoted a price of “60 to 80 million euros”, and the interior, military and justice arms of the state were interested. The Élysée vetoed the purchase in late 2020, citing sovereignty and reputational risk, as Le Monde first reported. France, it turned out, had been a victim while it shopped.

France’s own foreign intelligence service, the DGSE, put its position on the record. In documents filed in the French criminal investigation and reviewed by the consortium, and reported by Mediapart, the DGSE confirmed that “the United Arab Emirates and Morocco have been using NSO products since at least 2017”, and assessed that certain intrusions could be tied to espionage by Pegasus client states. The 2021 Pegasus Project had already found the numbers of President Emmanuel Macron and 15 members of his government on Morocco’s selection list. Morocco denied everything then, and denies it now.

The email that ties it all together

Here is where the forensic story and the political story meet, and it is the same mechanism we described in the parent piece. NSO’s “White Services” team builds a separate, anonymised set of attack accounts and domains for each customer. Because those accounts are never shared between customers, a single account recurring across different victims is a customer fingerprint. On Lecornu’s iPhone XS, France’s cybersecurity agency found markers for the attacker addresses [email protected] and [email protected]. Parly’s iPhone 12 carried bergers.o79 as well. And that same account, according to Amnesty’s Security Lab, had earlier been used to compromise the phone of the Moroccan journalist Omar Radi. One account, three victims, one operator. This is precisely the indicator-based attribution that lets investigators cluster attacks, and it is why the compromise of two French ministers points back to the same hand that targeted a Moroccan reporter.

One attack account, three victims, one customer ransomnews.com [email protected] NSO “White Services” account Omar Radi (journalist) S. Lecornu (FR minister) F. Parly (FR minister) Because NSO never shares an attack account between customers, a shared account = a shared operator.

The Spain thread, and an agent who forgot to log out

Morocco’s foreign targeting did not stop at France. In a related strand of the investigation, Forbidden Stories reports that Morocco used Pegasus against a senior officer of Spain’s Guardia Civil, at a time when Spanish officers were helping to train Morocco’s own service. The detail captures the cynicism of the trade: a partner teaching a service that was, in the same window, turning the tools back on the teacher.

The human operators left traces too. Amnesty’s Security Lab tied an ordinary Gmail address to a DGST IT specialist because it had been used to register a TLS certificate for an internal DGST domain. The same person’s public Google Maps reviews placed him near NSO’s Herzliya headquarters, where, Safir says, agents were told to describe their training trips as visits to Cape Verde rather than Israel. It is a textbook example of the kind of selector-based OSINT pivoting that turns a reused identifier into a named individual, applied here to the watchers rather than the watched.

Denials, seizures, and a judge told “no”

Everyone with something to lose has closed ranks. Morocco has consistently denied buying or using Pegasus and has pursued defamation actions against the journalists and organisations behind the Pegasus Project. NSO stays silent behind Israeli law: appearing before a French investigating judge in January 2026, Hulio reportedly declined to answer eleven times, citing his country’s legal restrictions, though on Morocco he allowed himself one line, that he knew Morocco “has denied purchasing it”. Israel, for its part, moved in 2020 to seize documents from NSO’s offices ahead of the WhatsApp case, claiming they might contain state secrets, a detail that surfaced through a later data leak shared with Forbidden Stories.

The activity itself appears to have wound down rather than been forced to stop. Amnesty’s Security Lab dates the most recent Moroccan Pegasus traces to November 2021, after the Pegasus Project made the operation radioactive and Israel tightened its spyware export rules. That is not the same as accountability. As Forbidden Stories notes, the same intermediaries have since introduced Moroccan intelligence to new vendors, at least one founded by former NSO staff. New rules, familiar players.

What Codename Morgan actually shows

The Moroccan case is the clearest illustration of the argument running through the wider Pegasus disclosures. A government did not simply buy a tool and use it in secret. It bought into a managed service, brokered by a second state, invoiced by the infiltration, maintained by the vendor, and traceable precisely because the vendor built isolated infrastructure for each customer. The domestic targeting of journalists and the foreign targeting of French and Spanish officials came out of the same dashboard and, in at least one case, the same attack account. For anyone weighing their own exposure, the practical advice is unchanged from the parent piece: patch relentlessly, enable iPhone Lockdown Mode, and treat your contacts’ security as part of your own. Our 2026 privacy stack guide covers the baseline. The larger lesson is that “Morgan” was never anonymous to the people who built the system. It only looked that way from outside.

Frequently asked questions

What is “Codename Morgan” in the Pegasus story?

“Morgan” is the internal alias NSO Group used for its Moroccan customer, the DGST intelligence service, according to a July 2026 Forbidden Stories investigation. The codename also appears in an NSO document unsealed in US litigation.

How did Morocco get Pegasus?

Forbidden Stories reports that NSO demonstrated Pegasus to Morocco’s DGST at a Rabat villa in late 2017, with access brokered through an Emirati intermediary, FSSYS Maroc, a branch of the Abu Dhabi group Al Fahad. The DGST had used the same broker earlier to buy Hacking Team’s RCS spyware.

How many people did Morocco target with Pegasus?

Just over 12,000 phone numbers in the leaked Pegasus Project dataset are attributed to the Moroccan client. Selection indicates intent to target, but not every number was necessarily infected, as some may have been tests or rotated in and out of active surveillance.

Did Morocco spy on French officials?

According to Forbidden Stories, seven French ministers’ phones showed signs of Pegasus compromise in 2019 and 2020 linked to Morocco, including Sébastien Lecornu, now prime minister. The 2021 Pegasus Project had earlier found President Macron and 15 government members on Morocco’s selection list. Morocco denies using Pegasus.

How were the attacks linked back to Morocco?

NSO builds a separate, anonymised set of attack accounts for each customer, so a shared account acts as a fingerprint. The Gmail-registered iCloud attacker address bergers.o79 appeared on the phones of two French ministers and, earlier, on the phone of Moroccan journalist Omar Radi, tying them to the same operator.

Is Morocco still using Pegasus in 2026?

Amnesty International’s Security Lab dates the most recent Moroccan Pegasus traces to November 2021. Activity appears to have wound down after the Pegasus Project and tighter Israeli export rules, though Forbidden Stories reports the same intermediaries have since introduced Moroccan intelligence to newer spyware vendors.

Sources and further reading

  • Forbidden Stories — Codename “Morgan”: how Morocco accessed Pegasus (primary investigation)
  • Forbidden Stories — While France weighed buying Pegasus, Morocco was spying on its ministers
  • Amnesty International Security Lab — Inside Pegasus (forensic analysis)
  • Ransomnews — Inside Pegasus: NSO’s own files reveal the machine (companion technical piece)
  • Ransomnews — Attributing attacks by their indicators
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleInside Pegasus: NSO’s own files reveal the machine
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Inside Pegasus: NSO’s own files reveal the machine

July 22, 2026

Stealer logs bypassing MFA in 2026 [Field Guide]

May 16, 2026

SEC 4-day cyber rule: 2.5 years in, what CISOs learned

May 11, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.