Pegasus for Android is an Android spyware implant associated with the Pegasus surveillance platform. It is designed for covert collection from compromised mobile devices and supports multiple surveillance functions, including access to contacts, call logs, installed application lists, device audio capture, and use of the device camera to take pictures. It also profiles device connectivity state, including whether the device is using Wi‑Fi or cellular service and whether it is roaming.
On Android, Pegasus for Android has been observed using broadcast receivers to maintain persistence and trigger execution at system startup by listening for device boot events. This allows the implant to reactivate after reboot and continue surveillance activity with limited user visibility. Its documented behavior aligns with targeted mobile espionage operations focused on persistent monitoring and data collection from infected handsets.
The malware targets Android devices and exhibits capabilities typical of advanced mobile spyware, emphasizing stealthy collection of personal, communications, and device-environment data rather than disruptive effects. Its known functionality supports intelligence gathering against individual victims through ongoing access to sensitive mobile-device content and sensors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Monokle checks if the device is connected via Wi-Fi or mobile data; Pegasus for Android checks if the device is on Wi-Fi, a cellular network, and is roaming; TianySpy can check to see if Wi‑Fi is enabled; TERRACOTTA can check if the active network connection is metered; TrickMo can collect device network configuration information such as IMSI, IMEI, and Wi‑Fi connection state.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware capable of taking pictures using the device camera.
Android spyware/implant that accesses installed application lists.
Android spyware that maintains persistence by activating at device boot via BOOT_COMPLETED.
Android variant of Pegasus spyware with device audio recording capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.