Pegasus is commercial mobile spyware developed by the Israeli company NSO Group Technologies for surveillance of Android and iOS devices. It is marketed to government law-enforcement and intelligence agencies for investigating terrorism and serious crime, but has been deployed against journalists, human-rights defenders, activists, political opponents, and other civil-society figures internationally. Documented victims include Bahraini activists and staff of the Salvadoran investigative news outlet El Faro.
Pegasus infections provide covert remote access to targeted phones, enabling collection and exfiltration of messages, emails, contacts, photographs, documents, passwords, browsing history, and call records. Its surveillance capabilities include location tracking, call monitoring, and covert camera and microphone activation. Access to the compromised endpoint enables collection of messaging content despite end-to-end encryption. Pegasus uses elevated privileges and concealment techniques, including encrypted communications and manipulation or deletion of logs.
Delivery methods include personalized spearphishing links and zero-click exploit chains that abuse automatic processing of messaging content without user interaction. Documented iOS infection chains include Kismet, ForcedEntry, and BLASTPASS. ForcedEntry bypassed Apple's BlastDoor protections and exploited CVE-2021-30860 in CoreGraphics. BLASTPASS used malicious PassKit attachments delivered through iMessage and exploited CVE-2023-41061 and CVE-2023-41064, allowing compromise of fully updated iPhones when the campaign was uncovered in 2023. Exploit chains and forensic traces vary across versions, complicating detection and retrospective investigation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-41061 and CVE-2023-41064 (Apple iOS) — NSO Group (Pegasus).
2023 Pegasus BLASTPASS Exploit lists CVE-2023-41061 and CVE-2023-41064. The presentation references Apple's security content for iOS 16.6.1 and iPadOS 16.6.1.
CVE-2023-7024 (Google Chrome) — NSO Group (Pegasus).
The vulnerability is inside the function JBIG2Stream::readTextRegionSeg of CoreGraphics.framework. Apple patched the function in iOS 14.8. | The activists were reportedly hacked with the NSO Group’s Pegasus spyware using two zero-click iMessage exploits: Kismet, which was identified in 2020; and ForcedEntry, a new vulnerability that was identified in 2021.
On October 3, 2019, we disclosed issue 1942 (CVE-2019-2215), which is a use-after-free in Binder in the Android kernel. The bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device. | Google’s Threat Analysis Group (TAG), Android Security, and Project Zero team received information suggesting that NSO had a 0-day exploit for Android that was part of an attack chain that installed Pegasus spyware on target devices.
The most notable patch is for CVE-2026-65346, a defect in the ImageIO framework Apple uses to parse image files. Discovered and reported by Nik Tsytsarkin of Meta's Red Team X, CVE-2026-65346 is an integer-overflow bug that could allow arbitrary code execution when an affected device processes an image.
CVE-2019-3568: heap overflow в VOIP-стеке. Buffer overflow в VoIP-стеке WhatsApp - одна из первых публично задокументированных zero-click цепочек NSO Group... По данным WhatsApp/Meta... уязвимость использовалась против примерно 1400 устройств за двухнедельный период. | Устройство было полностью скомпрометировано Pegasus от NSO Group.
Defendants’ products included “Pegasus,” a type of spyware known as a remote access trojan. According to Defendants, Pegasus and its variants (collectively, “Pegasus”) were designed to be remotely installed and enable the remote access and control of information—including calls, messages, and location—on mobile devices using the Android, iOS, and BlackBerry operating systems. | On information and belief, in order to enable Pegasus’ remote installation, Defendants exploited vulnerabilities in operating systems and applications (e.g., CVE-2016-4657) and used other malware delivery methods, like spearphishing messages containing links to malicious code.
Apple patched two zero-days tagged by Citizen Lab as being exploited in attacks as part of an exploit chain known as BLASTPASS to infect fully-patched iPhones with NSO Group's Pegasus mercenary spyware.
"This level of sophistication resembles other exploits developed by the commercial surveillance industry. These are private companies that also developed prominent spyware tools like Pegasus and Predator."
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The activists were reportedly hacked with the NSO Group’s Pegasus spyware using two zero-click iMessage exploits: Kismet, which was identified in 2020; and ForcedEntry, a new vulnerability that was identified in 2021.
Amnesty documented that Moroccan authorities deployed NSO Group's Pegasus spyware against civil-society figures from 2017 to 2021, using one-click phishing and zero-click compromise vectors.
Pegasus (NSO Group) : Infection confirmée sur l’iPhone d’un militant étudiant ; indicateurs d’infection à haute confiance entre décembre 2025 et janvier 2026, via un exploit zero-click iMessage.
Pegasus is discussed as spyware allegedly used by Saudi Arabia, Bahrain, the United Arab Emirates, and Rwanda to target dissidents, journalists, and opposition figures in the United Kingdom.
Pegasus is discussed as spyware allegedly used by Saudi Arabia, Bahrain, the United Arab Emirates, and Rwanda to target dissidents, journalists, and opposition figures in the United Kingdom.
Pegasus is discussed as spyware allegedly used by Saudi Arabia, Bahrain, the United Arab Emirates, and Rwanda to target dissidents, journalists, and opposition figures in the United Kingdom.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
If chained with a browser renderer exploit, this bug could fully compromise a device through a malicious website.
„Нашата анализа потврди дека е искористена zero-click експлоатација преку iMessage за да се инфицира уредот со шпионскиот софтвер Pegasus на NSO Group“
Level 10 involves a government partnering with or coercing a service provider to provide information; examples include providers assisting state-run data collection from mobile-phone networks.
The government deployed ... Pegasus spyware to target civil society figures both domestically and abroad in what Amnesty described as “unlawful surveillance attacks.”
“Spyware is noted for its ability to access everything on a device, record screens or take over its microphone.”
Pegasus "has the ability to covertly enable the phone’s microphone and camera."
The agent constructs the following URL that contains the C2 server, which can be extracted from the initial configuration or a command sent via SMS... The malware adds “SessionId1” and “SessionId2” to the HTTP headers... The HTTP response should be an XML file containing at least the following fields: “response”, “code”, and “message”. | 1. HTTP Communication... The agent constructs the following URL that contains the C2 server... The malware creates an XmlSerializer object that will be encrypted using the AES algorithm and then sent to a C2 server via HTTP.
314 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware from NSO Group cited as being used to surveil journalists and dissidents. The reference discusses it as an example of commercial surveillance technology abused against civil society.
Sophisticated zero-click spyware discussed in connection with alleged Mexican military surveillance of journalists and human rights defenders. Investigators searched leaked military emails for evidence of its acquisition, approval, and deployment.
Mobile surveillance spyware developed by NSO Group and sold to government agencies. The article describes infection through zero-click exploits, malicious links, and network injection. Once installed, it can extract messages, credentials, files, and other device data; access encrypted messaging content on the compromised endpoint; activate cameras and microphones; and track location. It conceals activity and can delete traces or itself. Reported targets include politicians, diplomats, journalists, lawyers, and human-rights activists.
Phone-surveillance spyware developed by NSO Group. The article describes its use against El Faro journalists and staff, with surveillance peaking around politically significant events and investigative reporting. The journalists' lawsuit seeks disclosure and deletion of collected information, prevention of further deployments against them, and identification of the government client responsible. The client remains unidentified, and El Salvador's government denies involvement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.