KINGDOM is a Pegasus spyware operator linked with high confidence to Saudi Arabia and associated with transnational surveillance of Saudi dissidents, journalists, and civil society figures. The cluster has been tied to use of NSO Group’s Pegasus against targets inside and outside Saudi Arabia, including Saudi activists living abroad, a journalist at The New York Times, and an Amnesty International staff member. Known aliases include kingdom and kingdom_hacker_crew. Activity attributed to KINGDOM in 2018 included targeting Ben Hubbard, Omar Abdulaziz, Ghanem Al-Masarir, Yahya Assiri, and an Amnesty International researcher. Reporting also associated the operator with broader monitoring of persons of interest across multiple countries in the Middle East, Europe, and North America. A UK court later accepted expert evidence that Ghanem Al-Masarir’s devices were infected with Pegasus and held Saudi Arabia responsible for damages arising from the spyware targeting. KINGDOM’s operations relied on Pegasus delivery infrastructure and malicious lure messages designed to induce victims to click exploit links. Once successful, Pegasus would provide the operator with extensive post-compromise access to mobile devices, including communications, files, microphones, and cameras. The actor’s observed tradecraft therefore supports capabilities including initial access, credential and communications theft through device compromise, surveillance-oriented post-exploitation, exfiltration, and defense evasion typical of mercenary spyware operations. The targeting pattern is consistent with espionage and repression of dissidents, journalists, and human rights-related actors rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Saudi-linked operator/activity cluster reported by Citizen Lab as conducting targeted surveillance against dissidents abroad using NSO Group’s Pegasus spyware, via malicious links/messages leading to iPhone infection.
Saudi Arabia-linked Pegasus operator conducting cross-border surveillance of dissidents, activists, and researchers using NSO Group’s Pegasus spyware, including the targeting and likely infection of Omar Abdulaziz in Canada.
Pegasus operator linked to Saudi Arabia that targeted journalist Ben Hubbard, Saudi dissidents, and an Amnesty International staff member using SMS messages with malicious links and Pegasus infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.