Pegasus is a commercial mercenary spyware platform developed by NSO Group and sold to government clients for covert surveillance of mobile devices. It is primarily associated with targeted intrusions against iPhones and Android devices and has been repeatedly documented in operations affecting journalists, opposition figures, human rights defenders, politicians, and other civil society targets across multiple countries.
Pegasus supports deep device compromise and post-compromise surveillance. Documented capabilities include exfiltration of messages, emails, photos, files, credentials, cloud-linked data, application information, call records, and location data, as well as active collection through microphone and camera activation and geolocation retrieval. The platform is designed for stealth and forensic resistance, including efforts to reduce visible traces on compromised devices.
Pegasus has used multiple infection vectors over time, including zero-click and one-click delivery. Reported vectors include WhatsApp-based Android chains, iMessage-based iOS chains, Voice-over-WiFi exploitation, Apple Photos-related exploitation, HomeKit-linked exploitation, adversary-in-the-middle network injection, and methods requiring physical access or short-range radio proximity. Named exploit chains and vectors associated with Pegasus include Heaven, Eden, Erised, Diablo, Dragonfly, KISMET, Megalodon/FORCEDENTRY, FINDMYPWN, LATENTIMAGE, and PWNYOURHOME. Several of these were used as zero-days against supported iOS versions before vendor patches were applied.
NSO Group operates Pegasus through segregated customer infrastructure and anonymized support services. Reporting has described a dedicated transmission network, per-client infrastructure separation, operator dashboards for managing target cases, and device fingerprinting features that help operators tailor exploitation to a target’s environment. Researchers have also noted that reuse of certain operator-linked artifacts can enable clustering of victims to a single Pegasus customer, even when the responsible government cannot be conclusively identified.
Pegasus has figured prominently in major spyware abuse investigations in Europe and elsewhere. Confirmed cases include targeting of exiled Russian- and Belarusian-speaking journalists and activists in Europe, human rights defenders in Mexico, and former European Parliament member Stelios Kouloglou while he served on the PEGA committee investigating spyware abuses. These cases have intensified scrutiny of the commercial spyware industry and of state use of intrusive surveillance tools against non-criminal targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-3568: heap overflow в VOIP-стеке. Buffer overflow в VoIP-стеке WhatsApp - одна из первых публично задокументированных zero-click цепочек NSO Group... По данным WhatsApp/Meta... уязвимость использовалась против примерно 1400 устройств за двухнедельный период. | Устройство было полностью скомпрометировано Pegasus от NSO Group.
CVE-2023-41064 - переполнение буфера (CWE-120, Buffer Copy without Checking Size of Input) в компоненте ImageIO. Обработка специально сформированного изображения приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
Эксплойт FORCEDENTRY (2021), обнаруженный Citizen Lab и детально разобранный Google Project Zero, атаковал iMessage через PDF с JBIG2-stream, замаскированный под GIF (CVE-2021-30860 в CoreGraphics). | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
BLASTPASS: цепочка CVE-2023-41061 + CVE-2023-41064. CVE-2023-41061 - ошибка валидации (CWE-20, Improper Input Validation) в компоненте Wallet. Специально сформированное вложение PassKit приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
Defendants’ products included “Pegasus,” a type of spyware known as a remote access trojan. According to Defendants, Pegasus and its variants (collectively, “Pegasus”) were designed to be remotely installed and enable the remote access and control of information—including calls, messages, and location—on mobile devices using the Android, iOS, and BlackBerry operating systems. | On information and belief, in order to enable Pegasus’ remote installation, Defendants exploited vulnerabilities in operating systems and applications (e.g., CVE-2016-4657) and used other malware delivery methods, like spearphishing messages containing links to malicious code.
Apple patched two zero-days tagged by Citizen Lab as being exploited in attacks as part of an exploit chain known as BLASTPASS to infect fully-patched iPhones with NSO Group's Pegasus mercenary spyware.
"This level of sophistication resembles other exploits developed by the commercial surveillance industry. These are private companies that also developed prominent spyware tools like Pegasus and Predator."
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le 16 juillet 2026, le Security Lab d’Amnesty International publie une analyse technique approfondie du spyware Pegasus développé par NSO Group.
Amnesty International has uncovered targeted digital attacks against two prominent Moroccan Human Rights Defenders (HRDs) using NSO Group’s Pegasus spyware.
Griselda Triana, a journalist and the wife of slain journalist Javier Valdez, was targeted with NSO Group’s Pegasus spyware following his assassination.
New York Times journalist Ben Hubbard was targeted with NSO Group’s Pegasus spyware via a June 2018 SMS message promising details about “Ben Hubbard and the story of the Saudi Royal Family.”
If the targets had clicked the links, their phones would likely have been infected with NSO Group’s Pegasus spyware.
We identified nine Bahraini activists whose iPhones were successfully hacked with NSO Group’s Pegasus spyware between June 2020 and February 2021.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Effectuer un fingerprinting du dispositif cible (OS, réseau, applications installées, statut de roaming)
Effectuer un fingerprinting du dispositif cible (OS, réseau, applications installées, statut de roaming)
« White Services » , responsable de l’enregistrement anonyme de domaines, comptes email, serveurs et comptes WhatsApp/iCloud pour chaque client
The logistics of Morocco’s surveillance relied on a middleman to maintain plausible deniability, according to Safir. The former intelligence officer said a private company acted as an intermediary between the DGST and NSO Group in the procurement and administrative management of the spyware.
« White Services » , responsable de l’enregistrement anonyme de domaines, comptes email, serveurs et comptes WhatsApp/iCloud pour chaque client
PWNYOURHOME appeared to first involve the attacker sending a specially crafted NSKeyedArchive that landed in HomeKit, followed by malicious content that landed in MessagesBlastDoorService. No interaction required from Kouloglou.
The open presence of Israel’s coupled systems of cyber, satellites, spies, wiretapping, tracking, and spyware (Pegasus) has resulted in the Middle East’s doctrinal fatigue.
Pegasus ... способен собирать с устройств ... похищать пароли
It allowed the spyware to grab private data from Kouloglou’s phone without his knowledge, such as his text messages and other correspondence, location data, and photos.
The open presence of Israel’s coupled systems of cyber, satellites, spies, wiretapping, tracking, and spyware (Pegasus) has resulted in the Middle East’s doctrinal fatigue.
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
Envoyer des commandes actives (activation micro, caméra, géolocalisation)
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
175 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spyware used to target journalists and opposition activists.
Spyware vendu aux gouvernements comme une solution de surveillance « end-to-end ». Il permet le fingerprinting des appareils cibles, des attaques zero-click et 1-click, l’exfiltration d’appels, messages, emails, photos, fichiers, identifiants et données cloud, ainsi que des commandes actives comme l’activation du micro, de la caméra et la géolocalisation.
Commercial spyware used to hack targeted devices and enable access to sensitive data and communications.
Commercial spyware used to hack mobile devices and enable covert surveillance, including access to sensitive device data and communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.