Pegasus is a commercial mercenary spyware platform developed by NSO Group and used in highly targeted surveillance operations, principally against journalists, activists, dissidents, politicians, diplomats, and other civil-society figures. It has been associated with government customers and alleged targeting of opposition and civil-society actors in multiple countries. Pegasus compromises mobile devices through sophisticated exploit chains, including zero-click attacks against messaging services such as iMessage and WhatsApp, requiring no victim interaction in some cases. Following compromise, operators can access sensitive device data, including messages, notes, photographs, and other private content, and can covertly activate device microphones and cameras. Confirmed forensic investigations have documented Pegasus infections of iPhones belonging to Serbian student-movement members via an iMessage zero-click exploit. Pegasus-related Android exploit chains have also been linked to exploitation of CVE-2019-2215 for privileged device compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On October 3, 2019, we disclosed issue 1942 (CVE-2019-2215), which is a use-after-free in Binder in the Android kernel. The bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device. | Google’s Threat Analysis Group (TAG), Android Security, and Project Zero team received information suggesting that NSO had a 0-day exploit for Android that was part of an attack chain that installed Pegasus spyware on target devices.
So did FORCEDENTRY, an exploit used to deliver NSO Group's Pegasus spyware through Apple's image-processing software.
The most notable patch is for CVE-2026-65346, a defect in the ImageIO framework Apple uses to parse image files. Discovered and reported by Nik Tsytsarkin of Meta's Red Team X, CVE-2026-65346 is an integer-overflow bug that could allow arbitrary code execution when an affected device processes an image.
CVE-2019-3568: heap overflow в VOIP-стеке. Buffer overflow в VoIP-стеке WhatsApp - одна из первых публично задокументированных zero-click цепочек NSO Group... По данным WhatsApp/Meta... уязвимость использовалась против примерно 1400 устройств за двухнедельный период. | Устройство было полностью скомпрометировано Pegasus от NSO Group.
CVE-2023-41064 - переполнение буфера (CWE-120, Buffer Copy without Checking Size of Input) в компоненте ImageIO. Обработка специально сформированного изображения приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
BLASTPASS: цепочка CVE-2023-41061 + CVE-2023-41064. CVE-2023-41061 - ошибка валидации (CWE-20, Improper Input Validation) в компоненте Wallet. Специально сформированное вложение PassKit приводит к выполнению произвольного кода. | Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Pegasus spyware от NSO Group - эталон по адаптивности.
Defendants’ products included “Pegasus,” a type of spyware known as a remote access trojan. According to Defendants, Pegasus and its variants (collectively, “Pegasus”) were designed to be remotely installed and enable the remote access and control of information—including calls, messages, and location—on mobile devices using the Android, iOS, and BlackBerry operating systems. | On information and belief, in order to enable Pegasus’ remote installation, Defendants exploited vulnerabilities in operating systems and applications (e.g., CVE-2016-4657) and used other malware delivery methods, like spearphishing messages containing links to malicious code.
Apple patched two zero-days tagged by Citizen Lab as being exploited in attacks as part of an exploit chain known as BLASTPASS to infect fully-patched iPhones with NSO Group's Pegasus mercenary spyware.
"This level of sophistication resembles other exploits developed by the commercial surveillance industry. These are private companies that also developed prominent spyware tools like Pegasus and Predator."
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Citizen Lab confirmed that a zero-click iMessage exploit was used to infect a Serbian student-movement member's iPhone with NSO Group's Pegasus spyware, with high-confidence infection indicators from December 2025 through January 2026.
Pegasus is discussed as spyware allegedly used by Saudi Arabia, Bahrain, the United Arab Emirates, and Rwanda to target dissidents, journalists, and opposition figures in the United Kingdom.
Pegasus is discussed as spyware allegedly used by Saudi Arabia, Bahrain, the United Arab Emirates, and Rwanda to target dissidents, journalists, and opposition figures in the United Kingdom.
Pegasus is discussed as spyware allegedly used by Saudi Arabia, Bahrain, the United Arab Emirates, and Rwanda to target dissidents, journalists, and opposition figures in the United Kingdom.
Pegasus is discussed as spyware allegedly used by Saudi Arabia, Bahrain, the United Arab Emirates, and Rwanda to target dissidents, journalists, and opposition figures in the United Kingdom.
The latest Pegasus spyware campaign targeted at least nine Bahraini activists, a French lawyer, and an Indian journalist via a new iOS exploit, dubbed FORCEDENTRY.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
If chained with a browser renderer exploit, this bug could fully compromise a device through a malicious website.
„Нашата анализа потврди дека е искористена zero-click експлоатација преку iMessage за да се инфицира уредот со шпионскиот софтвер Pegasus на NSO Group“
At the centre of this investigation is NSO Group’s Pegasus spyware which, when surreptitiously installed on victims’ phones, allows an attacker complete access to the device’s messages, emails, media, microphone, camera, calls and contacts.
“Pegasus allows an attacker to do anything that a user can do, ranging from accessing private data like notes, pictures and even encrypted messages.”
At the centre of this investigation is NSO Group’s Pegasus spyware which, when surreptitiously installed on victims’ phones, allows an attacker complete access to the device’s messages, emails, media, microphone, camera, calls and contacts.
“Spyware is noted for its ability to access everything on a device, record screens or take over its microphone.”
NSO Group has not taken adequate action to stop the use of its tools for unlawful targeted surveillance of activists and journalists, despite the fact that it either knew, or arguably ought to have known, that this was taking place.
“Pegasus also has the ability to covertly enable the phone’s microphone and camera.”
The agent constructs the following URL that contains the C2 server, which can be extracted from the initial configuration or a command sent via SMS... The malware adds “SessionId1” and “SessionId2” to the HTTP headers... The HTTP response should be an XML file containing at least the following fields: “response”, “code”, and “message”. | 1. HTTP Communication... The agent constructs the following URL that contains the C2 server... The malware creates an XmlSerializer object that will be encrypted using the AES algorithm and then sent to a C2 server via HTTP.
314 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial mobile spyware deployed through a zero-click iMessage exploit against an iPhone belonging to a member of Serbia's student protest movement.
Mercenary spyware used to infect the iPhone of a Serbian student protest movement member through an iMessage zero-click exploit.
Pegasus is mercenary spyware that provides its operator effectively total access to an infected iPhone, including private data, notes, photographs, and encrypted messages, and can covertly activate the microphone and camera.
Commercial spyware developed by NSO Group that can compromise devices through zero-click exploits, enabling extensive device surveillance. In this case it targeted a Serbian student activist without requiring victim interaction.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.