VOX POPULI
Subscribe
  • Home
  • In the News
    • Security
    • Enterprise
    • Perspective
    • Health
    • Ever Green Series
  • Politics
  • Investigations
    • Surveillance
  • Ukweli Check
  • Podcasts
  • videos
No Result
View All Result
VOX POPULI
  • Home
  • In the News
    • Security
    • Enterprise
    • Perspective
    • Health
    • Ever Green Series
  • Politics
  • Investigations
    • Surveillance
  • Ukweli Check
  • Podcasts
  • videos
No Result
View All Result
VOX POPULI
No Result
View All Result
Home Investigations

The making of evil twins: When torture, intrusive software become bedfellows

byEACIR Reporter
September 4, 2026
in Investigations, Surveillance
0
Share on FacebookShare on Twitter

The cache of classified documents spans 55 pages, and in its transparency makes numerous inadvertent revelations about how the cellphone of an Ugandan dissident was breached using mobile forensic products from the Israeli firm Cellebrite. Tucked inside the cache is an examination report from the Uganda Police Force’s Directorate of Forensic Services, a cog in the Department of Cyber Crime.

Meticulous in reviewing even the smallest details, the report—seen by Vox Populi—shows how social media posts put out by Kakwenza Rukirabashaija using a Tecno Spark 5 smartphone were reduced to their constituent parts. UFED Touch 2 and Physical Analyzer proved to be handy tools. It had been five days since Ugandans rang in 2022 when a law enforcement officer ran one of the software products at the Uganda Police Force’s headquarters in the leafy Kampala suburb of Naguru.

“A forensic advanced logical extraction of the exhibit was performed using UFED touch 2 versions 7.50.0.137 and bit-by-bit copy of the exhibits’ flash memory was obtained. UFED Physical Analyzer version 7.51.0.30 was used to examine and analyse the extracted forensic images,” the analysis report reads in part.

“Twitter account cloud acquisition of the submitted twitter handle KAKWENZA RUKIRA @KakwenzaRukira was also successfully acquired using Magnet Axiom Process 3.11.0.19007 forensic cloud acquisition tool. Using Magnet Axiom Examine 3.11.0.19007, the acquired forensic copy of the submitted exhibit A was parsed and processed for further examination and analysis,” it adds.

Chilling swiftness

The extraction process was remarkably swift. Documents show that it started at 3.44 p.m.. By 3.58 p.m. the source extraction process had run its course. Kakwenza had for days been held incommunicado in a torture cell after he used a communication style government functionaries deemed unsavoury while calling out Uganda’s first family.

“The soldiers supplied the violence, the telephone company supplied my private life, but the instruments that turned my seized phone into a searchable exhibit were built, sold and licensed by two private corporations, an ocean away, in countries that call themselves democracies,” Kakwenza discloses in an essay he wrote for Vox Populi.

“The extraction was performed with Cellebrite UFED Touch 2 and Physical Analyzer, products of an Israeli firm. The cloud acquisition used Magnet AXIOM, a product of a Canadian firm. Their logos, in effect, are stamped on the machinery of my persecution. What is their responsibility for what was done with their tools in a Ugandan dungeon’s aftermath?” he adds.

Kakwenza’s lived experiences illuminate the almost tangible correlation between the deployment of hacking software, on the one hand, and, on the other hand, torture—be it physical and/or psychological. Whereas Cellebrite has always contended that there is a distinction to be drawn between its main software suites like UFED and spyware like Pegasus, the former’s forensic extraction is just as insidious. Suites like UFED are meticulously tailored to bypass passcodes, unlock operating systems, and download existing data as Kakwenza reveals with granularity in his essay for Vox Populi. He particularly disputed Cellebrite’s stance in which the firm vigorously defends its solutions as being “forensic tools used in legally sanctioned investigations.” The winner of the English PEN 2021 Pinter International Writer of Courage Award ascribes the position to the art of doublespeak.

“Vicarious and contributory responsibility exist precisely to reach the party who profits from harm while keeping his hands clean. In the political economy of modern repression, the torturer and the toolmaker are partners, and the law is slowly learning to name them both,” Kakwenza writes in the essay for Vox Populi.

“The chain of hands that reached into my life is longer than any charge sheet admits. A soldier held the pliers, a telecom clerk released my registration data, a foreign engineer wrote the extraction software, a magistrate signed the order—not one of them appears as an accused, yet the investigation could not have functioned without every link. That is the defining feature of contemporary repression. It is a supply chain, its cruelty distributed so widely that each participant persuades himself his portion was too small to matter,” he adds.

In East Africa’s embrace

Governments in East Africa have at their behest seen use of Cellebrite’s software spread so rapidly and damagingly. It is rarely possible to apply this software that can bypass passwords and security protocols on smartphones and computers with either clinical sensitivity or regard for fundamental rights. As a matter of fact, it is as if a willingness to be reckless becomes the qualifying threshold after taking out a product with Cellebrite.

Amidst growing acts of civil disobedience by East Africa’s vastly youthful population, government functionaries in countries like Uganda and Kenya have taken the threats seriously by preparing for the worst. That was precisely the case when Boniface Mwangi, a Kenyan activist, was arrested after mass protests in his native country in July of 2025. When he was released on bail after a criminal charge was preferred against him, an analysis by the Citizen Lab turned up evidence that Cellebrite’s data extraction technology had been used to unlock his smartphone. The Citizen Lab is an interdisciplinary unit at the University of Toronto that investigates digital threats to human rights and democracy. The telltale signs that it discovered after an investigation were vestiges of the software’s UFED Reader Client which appeared under the package name com.client.appA.

Cellebrite’s data extraction tools, in their grandeur and efficiency, allowed law enforcement agencies in Kenya to gain access to all of Mwangi’s communications and pictures. Little wonder, he found the Israeli manufacturer frustratingly silent about why it enters deals with so-called “rogue states.” Empirical evidence shows that it is not just in East Africa where Cellebrite’s advanced mobile forensic products have been used to illegally extract data from mobile devices of change agents.

In 2024, an Amnesty International report revealed that authorities in Serbia were using “surveillance technology and digital repression tactics as instruments of wider state control and repression directed against civil society.” Cellebrite’s products were used to enable NoviSpy—a less technically advanced spyware than Pegasus—surreptitiously penetrate the defences of smartphones of journalists and rights activists in the European country.

Joined at the hip with torture

When Amnesty International went to Cellebrite with its findings, the Israeli company made clear that its products were “licensed strictly for lawful use, [and] require a warrant or consent to help law enforcement agencies with legally sanctioned investigations after a crime has taken place.” It is a position that flies in the face of the lived experiences of Mwangi and Kakwenza. The latter’s case painstakingly shows just how Cellebrite’s data extraction tools are used in abusive detentions. UFED hardware was used to bypass passwords or encryption in a bid to pull data while the Ugandan dissident was physically detained. Thereafter, Cellebrite Physical Analyzer was used to comb through the extracted files.

RelatedPosts

How spyware operates outside  confines of the law in Uganda

How elections in East Africa and intrusive malware ended up being joined at the hip

Firms whose extraction tools were used to breach my phone have blood on their hands

The surveillance iron curtain descends on East Africa

“The forensic examiner performed an advanced logical extraction of my phone and, more sweepingly, a cloud acquisition of my entire Twitter, WhatsApp, email and Facebook accounts,” Kakwenza describes the parsing in the Vox Populi essay.

“The report tallies the yield. Fifty thousand two hundred and thirty-eight results from the account. One thousand six hundred and sixty-nine call logs. Eighteen hundred contacts. Four thousand six hundred images. My messages, my documents, my browsing, my location history, the whole sediment of a modern life, dredged and parsed by two of the most powerful forensic engines on earth,” he further adds.

Perhaps, most importantly, is the direct correlation between the deployment of the software and torture. Kakwenza has scars to show for it.

“My tortured body surrendered the key that opened every door the examiner then walked through. In law, the poison travels with the fruit. A search made possible only by torture does not become lawful because it was done tidily, any more than a house burgled with a stolen key becomes lawfully entered because the burglar wiped his feet,” he writes in the Vox Populi essay that is punctuated with excerpts from the third of four books and counting he has authored—The Savage Avenger.

Digital forensic research has also shown that Cellebrite’s software has previously been used against change agents that populate Jordan’s civic space. In a report published on 22 January 2026 after a multi-year investigation, the Citizen Lab found that “Cellebrite’s products have been used by the Jordanian authorities to extract data from the phones of activists and civil society members without their consent.” Court records it gained access to also indicated “use of Cellebrite products in criminal prosecutions against activists and members of Jordanian civil society in a manner that does not comply with human rights treaties that Jordan has ratified (‘abuse’).” It’s a concern that Kakwenza, a trained lawyer, also raised in his Vox Populi essay, arguing that “a court that feeds on the fruit of torture ceases to be a court and becomes a continuation of the torture chamber by other means.”

Tags: bedfellowsintrusive softwaretorture
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Call us: +256

© 2025 Vox Populi. All Rights Reserved.

No Result
View All Result
  • Home
  • In the News
    • Security
    • Enterprise
    • Perspective
    • Health
    • Ever Green Series
  • Politics
  • Investigations
    • Surveillance
  • Ukweli Check
  • Podcasts
  • videos

© 2025 Vox Populi. All Rights Reserved.