Pegasus for iOS is an iPhone-targeting spyware implant associated with the Pegasus surveillance platform. It is designed for covert collection from compromised iOS devices and supports surveillance-oriented data theft including capture of SMS messages, collection of call logs, harvesting of contacts from the victim’s address book, and audio recording. The malware also performs device monitoring and includes behavior intended to disable competing jailbreak-related access on the phone, indicating post-compromise control and defense-evasion functionality. Access to some protected iOS data sources, such as call logs, implies elevated privileges beyond normal application access. Pegasus is widely associated with high-end targeted surveillance and espionage operations against mobile devices rather than commodity cybercrime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
iOS spyware that captures sent and received SMS messages.
iOS variant of Pegasus spyware that captures call log data.
iOS variant of Pegasus spyware with audio recording capability.
iOS spyware that monitors victim status and interferes with other jailbreaking software access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.