Pegasus is a mercenary mobile spyware platform developed by NSO Group and sold to government customers for targeted surveillance. It is designed to compromise iOS and Android devices and provide covert access to highly sensitive data and device functions. Documented Pegasus capabilities include collection of messages, calls, emails, photos, files, location data, application data, credentials, and certain cloud-linked data, as well as active surveillance functions such as microphone activation, camera activation, and geolocation retrieval.
Pegasus has been delivered through multiple infection vectors over time, including zero-click and one-click chains. Publicly documented vectors include WhatsApp-based delivery, iMessage exploit chains such as FORCEDENTRY, HomeKit-linked exploitation associated with PWNYOURHOME, Voice-over-WiFi exploitation, Apple Photos-related exploitation, adversary-in-the-middle network injection, and infections requiring physical access or short-range wireless proximity. NSO Group documentation and forensic investigations indicate that Pegasus operations are supported by segregated per-customer infrastructure and anonymization layers intended to obscure operator identity while enabling targeted deployment.
Pegasus is strongly associated with surveillance of journalists, opposition figures, human rights defenders, civil society members, lawyers, politicians, and other high-value individuals across multiple regions. Confirmed and reported cases include targeting in Europe and Mexico, including infections of exiled Russian- and Belarusian-speaking journalists and activists, human rights defenders connected to sensitive military-abuse investigations, and former European Parliament member Stelios Kouloglou while he served on the PEGA committee investigating spyware abuses. Multiple investigations have linked Pegasus activity to transnational repression and politically sensitive monitoring rather than narrowly scoped criminal investigations.
The platform is notable for sophisticated defense-evasion measures and evolving exploit chains. Researchers have reported that newer Pegasus variants reduced forensic traces on compromised iPhones compared with earlier versions, complicating post-incident analysis. Pegasus has become one of the most prominent examples of the commercial spyware industry and is widely cited in debates over lawful interception, export controls, human rights, and oversight of state use of intrusive surveillance technology.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-3568: heap overflow в VOIP-стеке. Buffer overflow в VoIP-стеке WhatsApp - одна из первых публично задокументированных zero-click цепочек NSO Group... По данным WhatsApp/Meta... уязвимость использовалась против примерно 1400 устройств за двухнедельный период. | Устройство было полностью скомпрометировано Pegasus от NSO Group.
CVE-2023-41064 - переполнение буфера (CWE-120, Buffer Copy without Checking Size of Input) в компоненте ImageIO. Обработка специально сформированного изображения приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
Эксплойт FORCEDENTRY (2021), обнаруженный Citizen Lab и детально разобранный Google Project Zero, атаковал iMessage через PDF с JBIG2-stream, замаскированный под GIF (CVE-2021-30860 в CoreGraphics). | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
BLASTPASS: цепочка CVE-2023-41061 + CVE-2023-41064. CVE-2023-41061 - ошибка валидации (CWE-20, Improper Input Validation) в компоненте Wallet. Специально сформированное вложение PassKit приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
Defendants’ products included “Pegasus,” a type of spyware known as a remote access trojan. According to Defendants, Pegasus and its variants (collectively, “Pegasus”) were designed to be remotely installed and enable the remote access and control of information—including calls, messages, and location—on mobile devices using the Android, iOS, and BlackBerry operating systems. | On information and belief, in order to enable Pegasus’ remote installation, Defendants exploited vulnerabilities in operating systems and applications (e.g., CVE-2016-4657) and used other malware delivery methods, like spearphishing messages containing links to malicious code.
Apple patched two zero-days tagged by Citizen Lab as being exploited in attacks as part of an exploit chain known as BLASTPASS to infect fully-patched iPhones with NSO Group's Pegasus mercenary spyware.
"This level of sophistication resembles other exploits developed by the commercial surveillance industry. These are private companies that also developed prominent spyware tools like Pegasus and Predator."
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A recent investigation by OCCRP found that the co-founder of NSO Group, which develops Pegasus spyware, travelled to Panama in 2013 on an Israeli diplomatic passport.
Amnesty International has uncovered targeted digital attacks against two prominent Moroccan Human Rights Defenders (HRDs) using NSO Group’s Pegasus spyware.
Griselda Triana, a journalist and the wife of slain journalist Javier Valdez, was targeted with NSO Group’s Pegasus spyware following his assassination.
New York Times journalist Ben Hubbard was targeted with NSO Group’s Pegasus spyware via a June 2018 SMS message promising details about “Ben Hubbard and the story of the Saudi Royal Family.”
If the targets had clicked the links, their phones would likely have been infected with NSO Group’s Pegasus spyware.
We identified nine Bahraini activists whose iPhones were successfully hacked with NSO Group’s Pegasus spyware between June 2020 and February 2021.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Effectuer un fingerprinting du dispositif cible (OS, réseau, applications installées, statut de roaming)
Effectuer un fingerprinting du dispositif cible (OS, réseau, applications installées, statut de roaming)
« White Services » , responsable de l’enregistrement anonyme de domaines, comptes email, serveurs et comptes WhatsApp/iCloud pour chaque client
The logistics of Morocco’s surveillance relied on a middleman to maintain plausible deniability, according to Safir. The former intelligence officer said a private company acted as an intermediary between the DGST and NSO Group in the procurement and administrative management of the spyware.
« White Services » , responsable de l’enregistrement anonyme de domaines, comptes email, serveurs et comptes WhatsApp/iCloud pour chaque client
Like Natalie’s research we target WebRTC to achieve 0-click exploitation on a modern mobile target... Signal introduced this patch specifically to detect situations where something “is broken or someone is doing an attack.” This is a logical fix that drastically reduces 0-click surface by refusing to parse any RTP/RTCP data packets prior to both parties accepting a call.
Like Natalie’s research we target WebRTC to achieve 0-click exploitation on a modern mobile target... This first post investigates Signal’s WebRTC library, sets up a local research environment, injects vulnerabilities and demonstrates their reachability.
The open presence of Israel’s coupled systems of cyber, satellites, spies, wiretapping, tracking, and spyware (Pegasus) has resulted in the Middle East’s doctrinal fatigue.
Pegasus ... способен собирать с устройств ... похищать пароли
It allowed the spyware to grab private data from Kouloglou’s phone without his knowledge, such as his text messages and other correspondence, location data, and photos.
The open presence of Israel’s coupled systems of cyber, satellites, spies, wiretapping, tracking, and spyware (Pegasus) has resulted in the Middle East’s doctrinal fatigue.
Envoyer des commandes actives (activation micro, caméra, géolocalisation)
175 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware / cyberweapon referenced as an example of remote exploitation threats that hardware memory tagging can help complicate.
Commercial spyware developed by NSO Group and used for targeted surveillance of mobile devices.
Spyware used to target journalists and opposition activists.
Spyware vendu aux gouvernements comme une solution de surveillance « end-to-end ». Il permet le fingerprinting des appareils cibles, des attaques zero-click et 1-click, l’exfiltration d’appels, messages, emails, photos, fichiers, identifiants et données cloud, ainsi que des commandes actives comme l’activation du micro, de la caméra et la géolocalisation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.