Pegasus is a commercial mercenary spyware platform developed by NSO Group for covert surveillance of mobile devices. It is primarily associated with high-end targeting of journalists, politicians, human rights defenders, civil society members, diplomats, and other sensitive individuals, and has been repeatedly documented in cases involving cross-border surveillance and alleged abuse by government customers. Pegasus is designed to compromise iOS and Android devices, often through zero-click exploitation that requires no user interaction, and to operate with a high degree of stealth while minimizing forensic traces.
Once deployed, Pegasus can provide extensive access to device contents and activity, including text messages, calls, application data, passwords, location information, photos, and other sensitive stored or processed data. Reported behavior also includes use of the device microphone for ambient audio collection and broader surveillance of communications and personal activity. On iPhones, documented Pegasus operations have used multiple exploit chains, including PWNYOURHOME, FINDMYPWN, and LATENTIMAGE, targeting components such as HomeKit, iMessage-related services, and Find My. These exploit chains were observed as zero-day or zero-click attacks against supported iOS versions before vendor mitigations were applied.
Pegasus has also shown strong defense-evasion characteristics. Later variants were observed removing or reducing forensic artifacts in device logs more aggressively than earlier versions, complicating incident response and retrospective detection. Researchers have linked some Pegasus operations through reuse of operator-specific targeting infrastructure patterns, suggesting that individual NSO Group customers may conduct campaigns across multiple jurisdictions where their licenses permit.
The spyware has figured prominently in major surveillance scandals and investigations in Europe and elsewhere. Documented cases include infections of members of civil society in Mexico and repeated compromise of former European Parliament member Stelios Kouloglou while he served on the PEGA committee investigating spyware abuses. Additional reporting has linked Pegasus targeting to exiled Russian- and Belarusian-speaking journalists and opposition figures in Europe. These cases have intensified scrutiny of the commercial spyware industry, the adequacy of export controls and oversight, and the use of intrusive surveillance tools against non-criminal targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-3568: heap overflow в VOIP-стеке. Buffer overflow в VoIP-стеке WhatsApp - одна из первых публично задокументированных zero-click цепочек NSO Group... По данным WhatsApp/Meta... уязвимость использовалась против примерно 1400 устройств за двухнедельный период. | Устройство было полностью скомпрометировано Pegasus от NSO Group.
CVE-2023-41064 - переполнение буфера (CWE-120, Buffer Copy without Checking Size of Input) в компоненте ImageIO. Обработка специально сформированного изображения приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
Эксплойт FORCEDENTRY (2021), обнаруженный Citizen Lab и детально разобранный Google Project Zero, атаковал iMessage через PDF с JBIG2-stream, замаскированный под GIF (CVE-2021-30860 в CoreGraphics). | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
BLASTPASS: цепочка CVE-2023-41061 + CVE-2023-41064. CVE-2023-41061 - ошибка валидации (CWE-20, Improper Input Validation) в компоненте Wallet. Специально сформированное вложение PassKit приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
Defendants’ products included “Pegasus,” a type of spyware known as a remote access trojan. According to Defendants, Pegasus and its variants (collectively, “Pegasus”) were designed to be remotely installed and enable the remote access and control of information—including calls, messages, and location—on mobile devices using the Android, iOS, and BlackBerry operating systems. | On information and belief, in order to enable Pegasus’ remote installation, Defendants exploited vulnerabilities in operating systems and applications (e.g., CVE-2016-4657) and used other malware delivery methods, like spearphishing messages containing links to malicious code.
Apple patched two zero-days tagged by Citizen Lab as being exploited in attacks as part of an exploit chain known as BLASTPASS to infect fully-patched iPhones with NSO Group's Pegasus mercenary spyware.
"This level of sophistication resembles other exploits developed by the commercial surveillance industry. These are private companies that also developed prominent spyware tools like Pegasus and Predator."
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Europe.
Amnesty International has uncovered targeted digital attacks against two prominent Moroccan Human Rights Defenders (HRDs) using NSO Group’s Pegasus spyware.
Griselda Triana, a journalist and the wife of slain journalist Javier Valdez, was targeted with NSO Group’s Pegasus spyware following his assassination.
New York Times journalist Ben Hubbard was targeted with NSO Group’s Pegasus spyware via a June 2018 SMS message promising details about “Ben Hubbard and the story of the Saudi Royal Family.”
If the targets had clicked the links, their phones would likely have been infected with NSO Group’s Pegasus spyware.
We identified nine Bahraini activists whose iPhones were successfully hacked with NSO Group’s Pegasus spyware between June 2020 and February 2021.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
No matter how much an attacker thinks they are varying the behavior of their infrastructure, it is likely that there will be some link between operations carried out with shared tooling in multiple contexts.
The logistics of Morocco’s surveillance relied on a middleman to maintain plausible deniability, according to Safir. The former intelligence officer said a private company acted as an intermediary between the DGST and NSO Group in the procurement and administrative management of the spyware.
PWNYOURHOME appeared to first involve the attacker sending a specially crafted NSKeyedArchive that landed in HomeKit, followed by malicious content that landed in MessagesBlastDoorService. No interaction required from Kouloglou.
The delivery mechanism for the first infection was PWNYOURHOME, a zero-click exploit targeting Apple’s HomeKit system.
In 2017, we reported that three members of the Mexican legal aid and human rights organization, Centro PRODH, were targeted with Pegasus spyware... Citizen Lab in 2017, which found evidence of Pegasus infection attempts via text message on his device that he had been sent in 2016.
Messaging apps are a royal road onto devices... this attack appears to leverage a flaw in a messaging app. Past NSO attacks have exploited flaws in iMessage attachment processing... as well as flaws in WhatsApp’s negotiation of end-to-end encryption for video calls.
Stealth - техники уровня Rootkit (T1014) для сокрытия артефактов ниже уровня ОС.
Скрытность T1036.008 Masquerade File Type / T1027 Obfuscated Files or Information (Defense Evasion) PSD/PDF маскируются под .gif
The open presence of Israel’s coupled systems of cyber, satellites, spies, wiretapping, tracking, and spyware (Pegasus) has resulted in the Middle East’s doctrinal fatigue.
It allowed the spyware to grab private data from Kouloglou’s phone without his knowledge, such as his text messages and other correspondence, location data, and photos.
The open presence of Israel’s coupled systems of cyber, satellites, spies, wiretapping, tracking, and spyware (Pegasus) has resulted in the Middle East’s doctrinal fatigue.
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
операторы спайвари могли активировать микрофон устройства и слушать разговоры политика с врачами и посетителями.
175 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware used to hack mobile devices and enable covert surveillance, including access to sensitive device data and communications.
Commercial spyware allegedly used in Morocco’s surveillance apparatus, with procurement and administration reportedly handled through intermediaries to provide plausible deniability.
Коммерческая шпионская платформа, разработанная NSO Group. Используется для скрытого наблюдения и может собирать текстовые сообщения, сведения о приложениях, прослушивать звонки, отслеживать местоположение и похищать пароли с устройств iOS и Android.
Intrusive commercial spyware described as a form of spyware that only governments can procure, used to infect iPhones and conduct covert surveillance of targets including politicians, activists, journalists, and other high-profile individuals.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.