Pegasus is a mercenary mobile spyware platform developed by NSO Group and sold to government customers as a lawful interception capability. It is designed to covertly compromise smartphones, particularly iPhones and Android devices, and provide deep surveillance access to victim data and device functions. Public reporting and forensic investigations have repeatedly linked Pegasus to surveillance of journalists, human rights defenders, political opposition figures, lawyers, diplomats, and elected officials across multiple regions.
Pegasus supports highly intrusive post-compromise collection, including access to messages, calls, application data, passwords, location information, photos, and other sensitive content stored or processed on the device. It has also been associated with covert monitoring through device sensors such as the microphone, enabling operators to capture ambient conversations. The platform is engineered for stealth and has shown strong defense-evasion characteristics, including efforts to reduce forensic traces on infected devices.
A defining feature of Pegasus is its use of sophisticated mobile exploit chains, including zero-click attacks that require no user interaction. Documented iOS exploit chains associated with Pegasus include FORCEDENTRY, FINDMYPWN, PWNYOURHOME, LATENTIMAGE, and BLASTPASS. These chains have targeted components such as iMessage, HomeKit, Find My, Wallet, and ImageIO, enabling remote compromise of Apple devices. Pegasus infections have also been observed through earlier one-click or link-based delivery in some campaigns. Lockdown Mode on Apple devices has been reported to block certain Pegasus exploit attempts in some cases.
Pegasus has been repeatedly implicated in politically sensitive surveillance operations. Confirmed cases include infections of civil society members in Mexico and a former Member of the European Parliament, Stelios Kouloglou, while he served on the PEGA committee investigating spyware abuses in Europe. Technical overlaps have also linked Pegasus activity to campaigns targeting Russian- and Belarusian-speaking journalists and opposition figures in exile in Europe. Although specific operators are often not publicly attributed, investigations have consistently assessed that Pegasus deployments are conducted by NSO Group customers operating under government authority or claiming such authority.
The platform is widely regarded as one of the most capable commercial spyware systems publicly documented. Its repeated use against non-criminal targets and democratic institutions has made it central to international debates over spyware regulation, export controls, human rights, and state abuse of surveillance technology.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-3568: heap overflow в VOIP-стеке. Buffer overflow в VoIP-стеке WhatsApp - одна из первых публично задокументированных zero-click цепочек NSO Group... По данным WhatsApp/Meta... уязвимость использовалась против примерно 1400 устройств за двухнедельный период. | Устройство было полностью скомпрометировано Pegasus от NSO Group.
CVE-2023-41064 - переполнение буфера (CWE-120, Buffer Copy without Checking Size of Input) в компоненте ImageIO. Обработка специально сформированного изображения приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
Эксплойт FORCEDENTRY (2021), обнаруженный Citizen Lab и детально разобранный Google Project Zero, атаковал iMessage через PDF с JBIG2-stream, замаскированный под GIF (CVE-2021-30860 в CoreGraphics). | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
BLASTPASS: цепочка CVE-2023-41061 + CVE-2023-41064. CVE-2023-41061 - ошибка валидации (CWE-20, Improper Input Validation) в компоненте Wallet. Специально сформированное вложение PassKit приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
Defendants’ products included “Pegasus,” a type of spyware known as a remote access trojan. According to Defendants, Pegasus and its variants (collectively, “Pegasus”) were designed to be remotely installed and enable the remote access and control of information—including calls, messages, and location—on mobile devices using the Android, iOS, and BlackBerry operating systems. | On information and belief, in order to enable Pegasus’ remote installation, Defendants exploited vulnerabilities in operating systems and applications (e.g., CVE-2016-4657) and used other malware delivery methods, like spearphishing messages containing links to malicious code.
Apple patched two zero-days tagged by Citizen Lab as being exploited in attacks as part of an exploit chain known as BLASTPASS to infect fully-patched iPhones with NSO Group's Pegasus mercenary spyware.
"This level of sophistication resembles other exploits developed by the commercial surveillance industry. These are private companies that also developed prominent spyware tools like Pegasus and Predator."
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Safir alleged the Emirati venture, of which he said FSSYS Maroc was the Moroccan representative, was involved in administering Morocco’s access to Pegasus.
Amnesty International has uncovered targeted digital attacks against two prominent Moroccan Human Rights Defenders (HRDs) using NSO Group’s Pegasus spyware.
Griselda Triana, a journalist and the wife of slain journalist Javier Valdez, was targeted with NSO Group’s Pegasus spyware following his assassination.
New York Times journalist Ben Hubbard was targeted with NSO Group’s Pegasus spyware via a June 2018 SMS message promising details about “Ben Hubbard and the story of the Saudi Royal Family.”
If the targets had clicked the links, their phones would likely have been infected with NSO Group’s Pegasus spyware.
We identified nine Bahraini activists whose iPhones were successfully hacked with NSO Group’s Pegasus spyware between June 2020 and February 2021.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
No matter how much an attacker thinks they are varying the behavior of their infrastructure, it is likely that there will be some link between operations carried out with shared tooling in multiple contexts.
The logistics of Morocco’s surveillance relied on a middleman to maintain plausible deniability, according to Safir. The former intelligence officer said a private company acted as an intermediary between the DGST and NSO Group in the procurement and administrative management of the spyware.
PWNYOURHOME appeared to first involve the attacker sending a specially crafted NSKeyedArchive that landed in HomeKit, followed by malicious content that landed in MessagesBlastDoorService. No interaction required from Kouloglou.
The delivery mechanism for the first infection was PWNYOURHOME, a zero-click exploit targeting Apple’s HomeKit system.
In 2017, we reported that three members of the Mexican legal aid and human rights organization, Centro PRODH, were targeted with Pegasus spyware... Citizen Lab in 2017, which found evidence of Pegasus infection attempts via text message on his device that he had been sent in 2016.
Messaging apps are a royal road onto devices... this attack appears to leverage a flaw in a messaging app. Past NSO attacks have exploited flaws in iMessage attachment processing... as well as flaws in WhatsApp’s negotiation of end-to-end encryption for video calls.
Stealth - техники уровня Rootkit (T1014) для сокрытия артефактов ниже уровня ОС.
Скрытность T1036.008 Masquerade File Type / T1027 Obfuscated Files or Information (Defense Evasion) PSD/PDF маскируются под .gif
The open presence of Israel’s coupled systems of cyber, satellites, spies, wiretapping, tracking, and spyware (Pegasus) has resulted in the Middle East’s doctrinal fatigue.
It allowed the spyware to grab private data from Kouloglou’s phone without his knowledge, such as his text messages and other correspondence, location data, and photos.
The open presence of Israel’s coupled systems of cyber, satellites, spies, wiretapping, tracking, and spyware (Pegasus) has resulted in the Middle East’s doctrinal fatigue.
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
операторы спайвари могли активировать микрофон устройства и слушать разговоры политика с врачами и посетителями.
175 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware allegedly used in Morocco’s surveillance apparatus, with procurement and administration reportedly handled through intermediaries to provide plausible deniability.
Коммерческая шпионская платформа, разработанная NSO Group. Используется для скрытого наблюдения и может собирать текстовые сообщения, сведения о приложениях, прослушивать звонки, отслеживать местоположение и похищать пароли с устройств iOS и Android.
Intrusive commercial spyware described as a form of spyware that only governments can procure, used to infect iPhones and conduct covert surveillance of targets including politicians, activists, journalists, and other high-profile individuals.
Mercenary spyware attributed to NSO Group that infected the device of a former MEP, potentially giving attackers access to confidential documents, committee deliberations, and sensitive communications through zero-click compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.