NSO Group is an Israeli private-sector offensive actor and commercial spyware vendor known principally for Pegasus, a mobile surveillance platform sold to government clients. Pegasus operations have targeted selected journalists, human rights defenders, activists, lawyers, diplomats, politicians, dissidents, and other civil-society figures. Public forensic investigations have documented Pegasus targeting in, among other locations, Bahrain, India, and Mexico. NSO Group is associated with Android spyware also tracked as Chrysaor, which is related to Pegasus, and Phantom, a related surveillance tool. Pegasus has used both zero-click and one-click delivery methods. Documented zero-click exploit chains have targeted messaging, device-discovery, smart-home, voice-over-Wi-Fi, and image-processing functionality on iOS, while Android operations have used exploit chains for privilege escalation. The platform supports collection and exfiltration of messages, calls, email, files, photos, location data, credentials, and cloud data; microphone and camera activation; screenshots; keylogging; and application-specific data collection. Android variants have established persistence through privileged installation, disabled security controls and updates, removed forensic traces, and supported operator-directed or condition-based self-removal. NSO Group has maintained segregated, anonymized infrastructure for individual customers and provides operational dashboards that permit clients to manage target cases, profile devices, and launch covert or triggered infections. Available evidence indicates that government customers generally select targets and operate the deployed tools. NSO Group has been subject to significant legal and regulatory action, including placement on the United States Entity List and litigation relating to Pegasus attacks against WhatsApp users.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
The latest Pegasus spyware campaign targeted at least nine Bahraini activists, a French lawyer, and an Indian journalist via a new iOS exploit, dubbed FORCEDENTRY. This was a highly sophisticated zero-click, 0day vulnerability in iMessage, meaning it could be triggered without the intended victim either viewing the message sent by the threat actors or clicking the link contained in the message.
CVE-2019-3568: heap overflow в VOIP-стеке. Buffer overflow в VoIP-стеке WhatsApp - одна из первых публично задокументированных zero-click цепочек NSO Group... По данным WhatsApp/Meta... уязвимость использовалась против примерно 1400 устройств за двухнедельный период.
On October 3, 2019, we disclosed issue 1942 (CVE-2019-2215), which is a use-after-free in Binder in the Android kernel. The bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device.
This vulnerability was initially tracked under the CVE identifier CVE-2023-4863. Google provided effective security patches from the Chrome browser at the time. The new advisory was released to reflect that a wider number of products were impacted than initially believed.
On information and belief, in order to enable Pegasus’ remote installation, Defendants exploited vulnerabilities in operating systems and applications (e.g., CVE-2016-4657) and used other malware delivery methods, like spearphishing messages containing links to malicious code.
3 more CVEs tied to this actor tracked in Mallory.
290 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in the automatically extracted actor list; no direct role in the EncroChat operation is described in the provided content.
Mentioned as the company whose Pegasus spyware previously used the same Android exploit chain that helped expose the Bad Binder vulnerability later leveraged in the EncroChat operation.
Referenced as a known mercenary spyware vendor associated with Pegasus and prior iPhone zero-click exploitation, but not attributed to the August 2026 notification wave.
Commercial spyware vendor accused of enabling targeted mercenary spyware attacks against high-profile individuals through Pegasus spyware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.