Citizen Lab documented multiple Pegasus infections against civil society targets, including New York Times journalist Ben Hubbard and four Jordanian human rights defenders, lawyers, and journalists. Hubbard’s iPhone was reportedly infected twice through zero-click iMessage exploit chains tied to KISMET and FORCEDENTRY, after earlier SMS and WhatsApp lure attempts linked to a Saudi-associated operator. In Jordan, researchers found repeated Pegasus targeting between 2019 and 2021 and assessed that two operators, MANSAF and BLACKIRIS, were likely connected to Jordanian government agencies; one successful iPhone compromise occurred even after Apple sued NSO Group and began notifying victims.
Technical reporting and forensic guidance showed Pegasus was built for covert, persistent surveillance across mobile platforms. Google previously identified the Android variant Chrysaor on a small number of devices, describing capabilities including privilege escalation, persistence, keylogging, screenshot capture, data theft, and covert microphone use. Reverse-engineering of Pegasus for Android detailed command-and-control over HTTP with encrypted values, SMS-based command execution disguised as verification texts, exfiltration of messages, contacts, call logs, emails, and app data, plus live audio recording, screenshot capture, camera access, and self-deletion features; Amnesty International separately published forensic methodology to help investigators detect Pegasus infections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Cyber Geeks published the second part of its Pegasus for Android analysis, describing command-and-control communications, SMS command handling, live audio surveillance, outbound SMS telemetry, and keylogging. The article further documented how the Android implant authenticated SMS commands and exfiltrated data.
Cyber Geeks published the first part of its reverse-engineering analysis of Pegasus for Android, detailing initialization, configuration retrieval, targeted data sources, core C2 commands, and self-removal mechanisms. The analysis covered the Android sample with SHA-256 ade8bef0ac29fa363fc9afd958af0074478aef650adeb0318517b48bd996d5d5.
Suhair Jaradat's iPhone was successfully hacked on December 5, 2021. Citizen Lab highlighted this as evidence that Pegasus activity on Apple devices continued after Apple sued NSO Group and notified victims in November 2021.
The same anonymous Jordanian woman human rights defender and journalist was hacked again on or around October 5, 2021. The repeated compromises were part of Pegasus targeting of Jordanian civil society.
An anonymous Jordanian woman human rights defender and journalist had her phone hacked on or around October 3, 2021. The report says her device was compromised at least twice in October 2021.
Amnesty International published its forensic methodology report on how to detect NSO Group's Pegasus spyware. The report became a cited reference point for Pegasus forensic investigations.
Citizen Lab concluded with high confidence that Ben Hubbard's iPhone was infected again on June 13, 2021. The infection was linked to a zero-click iMessage exploit chain associated with FORCEDENTRY.
Ahmed Al-Neimat's phone was hacked on or around January 28, 2021 for approximately two days. Logs indicated a zero-click Pegasus exploit likely involving FORCEDENTRY.
Researchers assessed that the suspected Pegasus operator BLACKIRIS had been active since at least December 2020 and was focused on Jordanian targets. The operator is believed likely to be an agency of the Jordanian government.
Citizen Lab concluded with high confidence that Ben Hubbard's iPhone was infected with Pegasus on July 12, 2020. The infection likely used a zero-click iMessage exploit chain associated with KISMET.
Malik Abu Orabi received another Pegasus-linked SMS message on March 20, 2020. The messages formed part of a campaign in which his phone was hacked repeatedly between 2019 and 2021.
A second Pegasus-linked SMS message was sent to Malik Abu Orabi on September 29, 2019. Researchers later tied lure domains used in such messages to Pegasus infrastructure focused on Jordan.
Malik Abu Orabi's phone contained a Pegasus-linked SMS message sent on September 22, 2019. The message was part of a broader Pegasus targeting campaign against Jordanian civil society figures.
Researchers assessed that the suspected Pegasus operator MANSAF had been active since at least December 2018 and was primarily focused on Jordanian targets. The operator is believed likely to be an agency of the Jordanian government.
Citizen Lab found forensic artifacts linked to NSO Group on Ben Hubbard's iPhone as early as April 2018. The report says it could not confirm whether these artifacts reflected a genuine infection attempt or a feasibility test.
Google disclosed Chrysaor as a newly discovered Android spyware family used in highly targeted attacks and said it was believed to have been created by NSO Group and related to Pegasus. Google found fewer than three dozen infected devices, notified affected users, disabled the apps, and updated Verify Apps protections.
The report states that FinFisher spyware was detected in Jordan, cited as evidence that the Jordanian government appears to have used spyware for years. It also notes that no civil society targets of FinFisher in Jordan had previously been publicly identified.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourcecitizenlab.ca
Open sourcecybergeeks.tech
Open sourcecybergeeks.tech
Open sourceamnesty.org
Open sourcesecurity.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.