NSO Group is an Israeli commercial spyware and surveillance technology company best known for Pegasus, a highly sophisticated mobile spyware platform sold to government customers. It is widely tracked as a private sector offensive actor rather than a traditional nation-state intrusion set; Microsoft has mapped it to Night Tsunami. The company is also associated with the name Q Cyber Technologies, and Pegasus is sometimes incorrectly used as an alias for the actor because it is the firm’s flagship capability. NSO Group develops and licenses intrusion and surveillance tooling designed to compromise iOS and Android devices and provide operators with extensive post-compromise access. Documented Pegasus capabilities include collection of messages, emails, photos, files, credentials, cloud-linked data, contacts, call records, and location information, as well as active tasking such as microphone activation, camera activation, and geolocation tracking. Court disclosures and technical investigations indicate that NSO has offered multiple infection vectors over time, including zero-click and one-click delivery through messaging applications, voice and calling features, iMessage, WhatsApp, browser and operating-system attack surfaces, network injection, and other covert delivery methods. NSO Group has been repeatedly linked to advanced mobile exploitation chains, including WhatsApp-based zero-click attacks in 2019 and iMessage-based Pegasus delivery using the FORCEDENTRY exploit chain against Apple devices. Additional Pegasus vectors publicly associated with NSO include exploit families and codenames such as Heaven, Eden, Erised, Hummingbird, KISMET, Diablo, Dragonfly, Megalodon, FINDMYPWN, and PWNYOURHOME. Reporting and litigation records indicate that NSO continued exploit development after public exposure and legal action, and that its tooling architecture supported per-customer operational segregation. Technical reporting on Pegasus infrastructure describes a mature access-as-a-service model with anonymized and segregated infrastructure for each customer, dedicated support functions, and centralized operational monitoring. Publicly disclosed internal materials describe a dedicated White Services function used to provision anonymized infrastructure and accounts for customers, as well as a Pegasus Anonymizing Transmission Network intended to obscure operational ownership. Researchers have assessed that this customer-by-customer segregation can still permit attribution when the same operator artifacts recur across victims. NSO Group states that it sells only to government clients for lawful purposes such as counterterrorism and serious crime investigations. However, the company has been repeatedly and credibly linked to abusive surveillance of civil society, including journalists, human rights defenders, lawyers, dissidents, diplomats, political opposition figures, humanitarian personnel, and government officials. Multiple independent investigations, platform security teams, and court proceedings have tied Pegasus operations to transnational repression and politically motivated surveillance in numerous countries. The company has faced sustained legal and regulatory pressure. WhatsApp sued NSO Group over the 2019 exploitation of its platform to target roughly 1,400 users, and U.S. court proceedings found NSO liable under hacking-related claims, awarded substantial damages, and imposed a permanent injunction barring NSO from targeting WhatsApp and its users. Meta later alleged that NSO violated that injunction through renewed WhatsApp-linked social-engineering and spear-phishing activity. Apple also sued NSO Group over Pegasus attacks against Apple users. The U.S. government placed NSO Group on the Entity List in 2021, citing activity contrary to U.S. foreign policy and national security interests. NSO Group is one of the most prominent examples of the mercenary spyware industry: a commercial vendor that develops high-end offensive cyber capabilities and sells them to state customers. Its operations are characterized by sophisticated mobile exploitation, stealthy surveillance tooling, customer-specific infrastructure, and repeated association with human-rights abuses and unlawful or unethical targeting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Эксплойт FORCEDENTRY (2021), обнаруженный Citizen Lab и детально разобранный Google Project Zero, атаковал iMessage через PDF с JBIG2-stream, замаскированный под GIF (CVE-2021-30860 в CoreGraphics).
CVE-2019-3568: heap overflow в VOIP-стеке. Buffer overflow в VoIP-стеке WhatsApp - одна из первых публично задокументированных zero-click цепочек NSO Group... По данным WhatsApp/Meta... уязвимость использовалась против примерно 1400 устройств за двухнедельный период.
On information and belief, in order to enable Pegasus’ remote installation, Defendants exploited vulnerabilities in operating systems and applications (e.g., CVE-2016-4657) and used other malware delivery methods, like spearphishing messages containing links to malicious code.
Apple ... released emergency security updates ... to address two zero-day flaws that have been exploited in the wild to deliver NSO Group's Pegasus ... CVE-2023-41061 - A validation issue in Wallet that could result in arbitrary code execution when handling a maliciously crafted attachment.
CVE-2023-41064 - A buffer overflow issue in the Image I/O component that could result in arbitrary code execution when processing a maliciously crafted image.
1 more CVE tied to this actor tracked in Mallory.
153 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mercenary spyware vendor operating Pegasus as an end-to-end surveillance platform for government clients, including anonymized delivery infrastructure, client-segregated operations, zero-click and one-click infection capabilities, device fingerprinting, and broad data exfiltration and active surveillance functions.
Mentioned only in a related-content link about a spyware firm; not part of the main article about WhatsApp usernames and privacy.
Accused of phishing WhatsApp users despite a court order; associated in the content with spyware-enabled intrusion activity targeting WhatsApp users.
Mercenary spyware firm accused of conducting spear-phishing via WhatsApp against users in Jordan and Lebanon despite a US court injunction; known for developing and deploying Pegasus spyware to infiltrate phones and harvest messages, photos, calls, and other data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.