NSO Group is an Israeli spyware company and private sector offensive actor known for developing and selling Pegasus spyware; it is also referred to as NSO, nso_group, Pegasus, and Q Cyber Technologies. Microsoft maps NSO Group to Night Tsunami (formerly DEV-0336) in its private sector offensive actor taxonomy. The company is repeatedly described as the maker of Pegasus, a surveillance platform and remote access trojan used to target mobile devices, including iOS, Android, and BlackBerry, and capable of extracting messages, calls, photos, location data, contacts, browser history, and other device data, as well as activating cameras and microphones. The content states that NSO sells packaged hacking solutions or access-as-a-service capabilities to government customers. The content directly links NSO Group to multiple Pegasus delivery vectors and campaigns. WhatsApp publicly attributed the 2019 exploitation of CVE-2019-3568 to NSO Group, in which specially crafted WhatsApp calls enabled zero-click installation of Pegasus against approximately 1,400 users. Court filings and testimony described NSO using WhatsApp infrastructure, malicious signaling traffic, and follow-on servers to deliver Pegasus, and indicated continued development of WhatsApp-related vectors after the lawsuit, including Eden, Heaven, and Erised, collectively referred to as Hummingbird. The content also attributes iMessage-based Pegasus activity to NSO Group with high confidence, including the FORCEDENTRY exploit chain exploiting CVE-2021-30860 to deliver Pegasus via zero-click messages. Additional reporting in the content describes an NSO-associated “MMS Fingerprint” technique that used MMS notification behavior to fingerprint target devices without user interaction. The actor is associated in the content with phishing and social engineering as well as zero-click exploitation. Multiple reports state that Meta and WhatsApp detected and disrupted new NSO-linked spear-phishing or one-click phishing campaigns targeting WhatsApp users despite a permanent injunction barring NSO from targeting WhatsApp and its users. Reported activity included malicious links redirecting users to external websites, creation of WhatsApp test accounts and groups, and targeting of a small number of users, including users in Jordan and Lebanon. WhatsApp and Meta published related domains including ikhwancast[.]com, ghazacast[.]com, and fr24cast[.]com. Earlier Pegasus operations in the content also used SMS phishing and other deception-based lures. Targets directly mentioned in the content include journalists, human rights defenders, activists, lawyers, political dissidents, diplomats, senior foreign government officials, humanitarian workers, military personnel, and other civil society members. Citizen Lab reporting cited in the content identified more than 100 cases of abusive targeting of human rights defenders and journalists in at least 20 countries linked to the 2019 WhatsApp incident. The content also references documented targeting in countries including Bahrain, Saudi Arabia, Mexico, Morocco, Canada, Jordan, Lebanon, and others. The content states that NSO Group has faced significant legal and policy action. WhatsApp and Facebook sued NSO Group and Q Cyber Technologies in 2019 over the WhatsApp attacks; a court found NSO violated U.S. hacking laws, a jury awarded roughly $167.25 million in punitive damages plus compensatory damages, and a permanent injunction barred NSO from targeting WhatsApp and its users. Apple also sued NSO Group, alleging Pegasus was used to attack a small number of Apple users worldwide. The U.S. government placed NSO Group on the Entity List in 2021, and the content says the blacklist was tied to activity contrary to U.S. national security and foreign policy interests and to widespread Pegasus abuse. The content also notes that Amazon shut down accounts linked to NSO Group after Amnesty International disclosed Pegasus-related domains.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Эксплойт FORCEDENTRY (2021), обнаруженный Citizen Lab и детально разобранный Google Project Zero, атаковал iMessage через PDF с JBIG2-stream, замаскированный под GIF (CVE-2021-30860 в CoreGraphics).
CVE-2019-3568: heap overflow в VOIP-стеке. Buffer overflow в VoIP-стеке WhatsApp - одна из первых публично задокументированных zero-click цепочек NSO Group... По данным WhatsApp/Meta... уязвимость использовалась против примерно 1400 устройств за двухнедельный период.
On information and belief, in order to enable Pegasus’ remote installation, Defendants exploited vulnerabilities in operating systems and applications (e.g., CVE-2016-4657) and used other malware delivery methods, like spearphishing messages containing links to malicious code.
Apple ... released emergency security updates ... to address two zero-day flaws that have been exploited in the wild to deliver NSO Group's Pegasus ... CVE-2023-41061 - A validation issue in Wallet that could result in arbitrary code execution when handling a maliciously crafted attachment.
CVE-2023-41064 - A buffer overflow issue in the Image I/O component that could result in arbitrary code execution when processing a maliciously crafted image.
1 more CVE tied to this actor tracked in Mallory.
153 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in a related-content link about a spyware firm; not part of the main article about WhatsApp usernames and privacy.
Accused of phishing WhatsApp users despite a court order; associated in the content with spyware-enabled intrusion activity targeting WhatsApp users.
Mercenary spyware firm accused of conducting spear-phishing via WhatsApp against users in Jordan and Lebanon despite a US court injunction; known for developing and deploying Pegasus spyware to infiltrate phones and harvest messages, photos, calls, and other data.
Conducting spyware-enabled targeting of WhatsApp users through social engineering and phishing campaigns, while developing access vectors beyond WhatsApp against browsers, operating systems, and other applications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.