Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Для Android NSO создали Chrysaor - аналогичный по возможностям, но с другим вектором.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The biggest distinction between the iOS and Android versions of Pegasus is the Android version does not use zero-day vulnerabilities to root the device... Instead, the threat uses an otherwise well-known rooting technique called Framaroot. | The Android version of one of the most sophisticated and targeted mobile attacks we’ve seen in the wild: Pegasus... developed the Pegasus malware, which jailbreaks or roots target devices to surveil specific targets.
It self-destructs if the software feels its position is at risk. Pegasus for Android will remove itself from the phone if: The SIM MCC ID is invalid An “antidote” file exists It has not been able to check in with the servers after 60 days It receives a command from the server to remove itself
The Android version performs similar spying functionality as Pegasus for iOS, including: Keylogging
The Android version performs similar spying functionality as Pegasus for iOS, including: Keylogging Screenshot capture Live audio capture
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware from NSO with capabilities similar to Pegasus. It used known rooting-style techniques rather than zero-day exploits, and if rooting failed it requested user permissions to collect partial data.
Referenced as an example of malware using MQTT for C2 communications; no additional technical details provided in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.