Pegasus is commercial mobile spyware developed by the Israeli cyber-arms company NSO Group. It covertly and remotely compromises iOS and Android devices, enabling full access to communications, files, camera, microphone, location, and encrypted messaging apps. NSO Group markets Pegasus exclusively to governments for combating terrorism and crime, but it has been routinely abused to surveil journalists, lawyers, political dissidents, and human rights activists across dozens of countries.
Pegasus was first publicly identified in August 2016 when Citizen Lab and Lookout captured an attempted infection of Emirati human-rights defender Ahmed Mansoor.1 Since then, Amnesty International and Citizen Lab have analysed over 1,000 devices and found hundreds with traces of Pegasus, spanning infections from 2014 through at least 2023.2 The 2021 Pegasus Project investigation, led by Forbidden Stories and Amnesty International, centred on a leaked list of 50,000 phone numbers and drew global attention to the scale of abuse.3
NSO Group: corporate background
NSO Group was founded in 2010 by Shalev Hulio and Omri Lavie. The company is headquartered in Luxembourg and maintains core R&D operations in Israel. It employs approximately 700 people.2 The sale of Pegasus licenses to foreign governments must be approved by the Israeli Ministry of Defense.4
NSO’s ownership has passed through several hands:
| Period | Controlling owner | Reported value |
|---|---|---|
| 2010–2014 | Founders | — |
| 2014–2019 | Francisco Partners (70%) | Acquired for ~$130M |
| 2019–2022 | Management (50%) + Novalpina Capital (50%) | Valued at ~$1B |
| 2023–present | Omri Lavie (Dufresne Holdings) | Lenders foreclosed after NSO defaulted on ~$500M debt |
In 2023, after NSO defaulted on its financial obligations, a syndicate of lenders foreclosed and transferred all shares to Dufresne Holdings, a Luxembourg entity whose sole shareholder is founder Omri Lavie.5 The NOAL Fund, which had held majority equity, stated in court filings that it had been “consistently denied even basic corporate information” and described its investment as “valueless.”5
NSO’s complex multi-jurisdictional structure spans the British Virgin Islands, Bulgaria, the Cayman Islands, Cyprus, Israel, Luxembourg, the UK, and the US.6 Export licences have been granted in Israel, Bulgaria, and Cyprus.6 Several public pension funds have invested in NSO through private equity channels, including two UK funds (South Yorkshire Pensions Authority and East Riding Pension Fund) and two US funds (Oregon Public Employees Retirement System and Alaska Permanent Fund Corp).6
Technical capabilities
Infection vectors
Pegasus is a suite of exploits rather than a single vulnerability. NSO Group categorises infection vectors as:7
- Covert (zero-click): Requires no user interaction. Delivered via iMessage, WhatsApp, Apple Photos, Apple Music, or network injection.
- Triggered (one-click): Requires the target to click a link, typically delivered by SMS or social media.
- Tactical Network Element: Infection via a malicious Wi-Fi access point or ISP-level network injection equipment.
- Physical: Operator has physical access to the target device.
A Pegasus customer does not need technical expertise to select the appropriate vector. The system monitors a target’s phone number, determines device type and OS version, examines installed apps, and recommends the best available vector.7
Known zero-click exploit history
| Name | Year | Target | Vector | Platform |
|---|---|---|---|---|
| Trident | 2016 | CVE-2016-4655/4656/4657 | Safari WebKit (1-click) | iOS 9 |
| Heaven | 2018 | Zero-click | Android (broad) | |
| Eden | 2018–2019 | Zero-click | Android | |
| Erised | 2018–2019 | Zero-click | Samsung-only | |
| CVE-2019-3568 | 2019 | WhatsApp video calling | Zero-click | Android |
| KISMET | 2019–2020 | iMessage | Zero-click | iOS 13 |
| Diablo | 2018 | Voice-over-WiFi | Zero-click | iOS 11 |
| Dragonfly | 2019 | iMessage | Zero-click | iOS 12 |
| FORCEDENTRY (Megalodon) | 2021 | iMessage / CoreGraphics | Zero-click | iOS 14, macOS, watchOS |
FORCEDENTRY (CVE-2021-30860) is the best-documented exploit. It targeted Apple’s CoreGraphics image-rendering library via a malformed PDF disguised as a GIF in iMessage, achieving arbitrary code execution with no user interaction on fully patched iPhones through iOS 14.7.8 The exploit was in use from at least February 2021 until Apple patched it in September 2021.
As of September 2023, Pegasus operators were able to remotely compromise iOS devices through version 16.6 using a zero-click exploit.4
Surveillance capabilities
Once installed, Pegasus provides:1 9
- Communications: Read and exfiltrate SMS, iMessages, emails, call logs, and the cleartext of encrypted messaging apps (WhatsApp, Signal, Telegram, Facebook Messenger, Viber, Skype, WeChat, Line, KakaoTalk) by hooking into app processes before encryption.
- Sensors: Activate microphone and cameras for live surveillance.
- Location: Track GPS and cell-tower location.
- Credentials: Harvest Wi-Fi passwords and stored account credentials.
- Files: Browse and exfiltrate photos, videos, documents, and app data.
- Keystrokes: Log keyboard input on Android devices.
- Persistence: Survive device reboots by re-exploiting the kernel on boot on jailbroken iOS devices.
- Self-destruct: Delete itself if unable to reach C&C servers for more than 60 days, if on the wrong device, or on command.
The Android variant (internally called Chrysaor) achieves root access where possible. If root fails, it requests user permissions to harvest at least partial data.9
Infrastructure
NSO Group manages a custom anonymising relay network called the Pegasus Anonymizing Transmission Network (PATN), which routes attacks and surveillance data through “whitened” infrastructure to prevent attribution to the customer.7 A dedicated “White Services” team acquires this infrastructure using cryptocurrency payments.7 Customer-specific data and the Pegasus user dashboard are installed locally at the customer’s site.
Documented abuse
Scale and geography
Amnesty International and Citizen Lab have documented Pegasus infections in at least the following countries through forensic analysis of victim devices:2 4
Mexico, El Salvador, Spain, Poland, Hungary, Morocco, UAE, Saudi Arabia, Bahrain, Jordan, India, Israel and Palestine, Kazakhstan, Thailand, Azerbaijan, Togo, Rwanda, and others.
Notable cases
Ahmed Mansoor (2016). The first public discovery. An Emirati human-rights defender received an SMS with a link promising “secrets” about UAE prison torture. He forwarded it to Citizen Lab instead of clicking, leading to the discovery of the Trident exploit chain and Apple’s iOS 9.3.5 emergency patch.1
Jamal Khashoggi (2018). Saudi dissident Omar Abdulaziz, a close associate of the murdered Washington Post journalist, filed suit against NSO Group in Israel, alleging the firm provided the Saudi government with Pegasus to spy on him and his friends, including Khashoggi.4
El Faro / El Salvador (2020–2021). Citizen Lab confirmed 35 Pegasus infections and 37 infected devices among Salvadoran journalists and civil-society figures, including at least 23 devices connected to the investigative newsroom El Faro.10 The newsroom had to reconfigure its reporting practices. El Faro employees sued NSO Group in California in November 2022, and the Ninth Circuit revived the case in July 2025.10
Morocco and France (2019–2021). Amnesty International documented network-injection attacks in Morocco that delivered Pegasus by redirecting target traffic through malicious infrastructure at the ISP level.11 Targets included French journalists and a human-rights lawyer. French President Emmanuel Macron’s phone number appeared on the leaked target list.4
Poland and Hungary (2019–2021). Pegasus was used against opposition politicians, lawyers, and journalists in both EU member states. The European Parliament established a committee to investigate spyware abuses, and a former MEP serving on that committee was himself found to have been hacked with Pegasus in 2026.4
The Pegasus Project (2021)
In July 2021, a consortium of 17 media organisations led by Forbidden Stories published the Pegasus Project investigation.3 It centred on a leaked list of approximately 50,000 phone numbers selected by Pegasus customers for potential targeting. The list included numbers belonging to:
- at least 180 journalists across the consortium’s member outlets;
- 600 government officials and politicians;
- 85 human-rights activists;
- heads of state and foreign ministers;
- business executives and diplomats.
Amnesty International’s Security Lab performed forensic analysis on 67 devices and confirmed 37 successful Pegasus infections.11 The investigation established that Pegasus had been used to target journalists and civil society far beyond any credible counter-terrorism rationale.
Legal and regulatory consequences
US sanctions
In November 2021, the US Commerce Department added NSO Group to its Entity List, prohibiting US companies from exporting technology to NSO without a licence.4 This significantly constrained NSO’s access to US-origin components and cloud services.
WhatsApp v. NSO Group
In October 2019, WhatsApp (Meta) sued NSO Group in US federal court, alleging that NSO exploited a WhatsApp vulnerability (CVE-2019-3568) to target approximately 1,400 phones in a two-week period.2 In December 2024, a US district court ruled that NSO Group was liable for hacking WhatsApp users, finding violations of the Computer Fraud and Abuse Act, the California Comprehensive Computer Data Access and Fraud Act, and WhatsApp’s terms of service.4
In February 2024, the court ordered NSO Group to hand over Pegasus source code to WhatsApp as part of discovery.4
Apple v. NSO Group
Apple sued NSO Group in 2021 but dropped its appeal in September 2024, citing concerns that its own disclosures could aid NSO and similar companies while NSO’s most critical files might never be disclosed.4
Israeli export controls
Israel’s Ministry of Defense must approve all Pegasus export licences. In practice, the approval process has not prevented sales to governments subsequently found to have abused the technology.4 An Israeli Supreme Court petition challenging export approvals was dismissed in 2022, with the court accepting the state’s argument that export oversight was adequate.4
Defences and detection
Pegasus is a top-tier remote-access threat. Ordinary security measures such as end-to-end encryption, app updates, and antivirus software do not protect against zero-click exploitation of the operating system or messaging infrastructure.
Detection
Mobile Verification Toolkit (MVT). Amnesty International’s open-source forensic tool scans iOS and Android backups or filesystem dumps for Indicators of Compromise (IOCs) associated with known Pegasus campaigns.12 MVT is a command-line tool designed for technologists and investigators, not for end-user self-assessment. Public IOCs alone are insufficient to declare a device “clean”; definitive assessment requires non-public indicators and expert forensic analysis.12
iMazing Spyware Analyzer. A free GUI tool for iOS that reimplements MVT’s methodology for non-technical users. It scans for Pegasus, Predator, KingsPawn, and several other spyware families.13
Amnesty International’s Security Lab offers free forensic analysis for civil-society members at risk, though capacity is limited.14
Prevention and hardening
No consumer-grade defence reliably prevents zero-click Pegasus infection if a target is selected by a state-level adversary. The following measures reduce the attack surface:
- iOS Lockdown Mode. Introduced by Apple in 2022, Lockdown Mode disables most message attachment types, blocks just-in-time JavaScript compilation, prevents wired data connections when locked, and blocks new MDM enrolment. It significantly constrains the remote attack surface that Pegasus vectors exploit. Apple has paid bounties for Lockdown Mode bypasses and described the feature as “extreme protection” for users facing targeted threats.
- Reboot regularly. On iOS 18.1+, the inactivity reboot returns the device to the BFU state, purging resident malware from memory. A daily reboot makes persistent infection harder to maintain.
- Keep updated. Pegasus operators have exploited fully patched devices using zero-day vulnerabilities, but each Apple or Google security update closes the known exploited vulnerabilities and forces NSO Group to develop new exploits.
- Disable iMessage and FaceTime on high-risk devices. Many zero-click Pegasus vectors have used iMessage as the delivery path.
- Use a separate device for sensitive work. A phone used exclusively for encrypted messaging and never opened to web links, attachments, or public-facing messaging accounts presents a smaller attack surface.
A victim of a confirmed Pegasus infection should assume all data on the device was exfiltrated and that any accounts accessed from it are compromised. The response is forensic triage, not merely reinstalling applications.
Relationship to other spyware and forensic tools
Pegasus differs from tools such as Cellebrite’s UFED in that it provides remote, often zero-click access rather than requiring physical possession. Both are Israeli in origin and subject to the Ministry of Defense’s export approval, and both have been documented in authoritarian misuse.
NSO Group operates in a broader mercenary spyware ecosystem that includes: Intellexa (Predator), QuaDream (KingsPawn), FinFisher, and Candiru (DevilsTongue). These vendors share the same business model: sell exclusively to governments, claim human-rights safeguards, and disclaim responsibility when customers use the tools against journalists and dissidents.
Apple’s introduction of Lockdown Mode, the BlastDoor iMessage sandbox, and automatic inactivity reboot are direct engineering responses to the techniques disclosed by Pegasus forensic investigations. In September 2025, Apple went further with Memory Integrity Enforcement (MIE) on iPhone 17 and iPhone Air: always-on synchronous memory tagging covering the kernel and over 70 userland processes, which Apple reports could not be worked around when it rebuilt recent real mercenary-spyware chains against it. Exploit developers quoted publicly expected a window in which some vendors would have no working iPhone 17 chain at all.15 Each successive iOS version has raised the cost of maintaining effective zero-click vectors, though NSO Group has consistently found new exploits within months of major releases.2
Related notes
-
Technical Analysis of Pegasus Spyware, Lookout, August 2016. ↩↩↩
-
Donncha O’Cearbhaill and Bill Marczak, “Exploit archaeology: a forensic history of in-the-wild NSO Group exploits,” Virus Bulletin, September 2022. ↩↩↩↩↩↩
-
The Pegasus Project, Forbidden Stories, July 2021. ↩↩
-
Pegasus (spyware), Wikipedia. Accessed 2026-07-23. ↩↩↩↩↩↩↩↩↩↩↩↩
-
NSO co-founders tighten grip on company amid legal battle, Ctech (Calcalist), March 2023. ↩↩
-
Operating from the Shadows, Amnesty International, Privacy International, and SOMO, May 2021. ↩↩↩
-
Inside Pegasus: The evolution of the world’s most notorious spyware system, Amnesty International Security Lab, July 2026. ↩↩↩↩↩
-
FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild, Citizen Lab, September 2021. ↩↩
-
Pegasus for Android, Lookout and Google, 2017. ↩↩
-
Project Torogoz: Extensive Hacking of Media and Civil Society in El Salvador with Pegasus Spyware, Citizen Lab, January 2022. ↩↩
-
Forensic Methodology Report: How to catch NSO Group’s Pegasus, Amnesty International, July 2021. ↩↩
-
Mobile Verification Toolkit, Amnesty International Security Lab, 2021–present. ↩↩
-
iPhone Spyware Analyzer, iMazing, 2021–present. ↩
-
Get Help — Digital Forensic Support, Amnesty International Security Lab. ↩
-
Apple’s latest iPhone security feature just made life more difficult for spyware makers, TechCrunch, September 2025. ↩
Built on 9 sources (9 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (535 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "DeepSeek V4 Pro", "label": "DeepSeek V4 Pro (93%)", "lines": 499, "share": 0.9327102803738317}, {"model": "Kimi K3", "label": "Kimi K3 (4%)", "lines": 19, "share": 0.03551401869158879}, {"model": "GPT-5", "label": "GPT-5 (2%)", "lines": 10, "share": 0.018691588785046728}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (1%)", "lines": 7, "share": 0.013084112149532711}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}