Detecting Pegasus Spyware: Forensic Methods and Tools in 2026
Pegasus is designed to be undetectable. It runs with kernel-level privileges, can hide its files and processes, and self-destructs when it detects forensic analysis. Detecting it is a matter of looking for the traces the spyware cannot fully erase. This article covers the primary detection methods available to researchers as of 2026.

The Detection Problem
Pegasus is designed to be undetectable. It runs with kernel-level privileges, can hide its files and processes, and in many cases self-destructs when it detects forensic analysis. Detecting it is therefore not a matter of looking for a known file or process. It is a matter of looking for the traces that the spyware cannot fully erase: artifacts left in backup files, in network logs, and in the device's own forensic record.
This article covers the primary detection methods available to researchers and high-risk users as of 2026. It is written for incident responders and forensic analysts who may need to assess whether a device has been compromised.
MVT: Mobile Verification Toolkit
The most widely used open-source tool for Pegasus detection is MVT (Mobile Verification Toolkit), developed by Amnesty International's Security Lab and released in 2021 in response to the Pegasus Project. MVT operates on two types of input: a forensic backup of an iOS device (obtained via iTunes or libimobiledevice) and a full file-system extraction (obtained via a checkm8-vulnerable bootrom exploit on older devices).
MVT works by comparing artifacts on the device against a set of known indicators of compromise. These indicators include suspicious domain names used by Pegasus command-and-control servers, suspicious file paths, and suspicious process names. When MVT finds a match, it flags the artifact for analyst review.
The limitation of MVT is that it is only as good as its indicators. NSO Group has historically rotated its command-and-control infrastructure and updated its implant to avoid known signatures. A negative MVT scan does not prove a device was not compromised. It proves that no known indicator was found. This is an important distinction that is often lost in media reporting.
iOS Backup Analysis
For iOS, the most accessible detection method is analyzing an iTunes backup. A backup contains a snapshot of the device's file system, including application databases, system logs, and configuration files. Pegasus artifacts that have been identified in backups include:
- Suspicious entries in the SMS and iMessage databases that correspond to known exploit delivery messages.
- Files in the temporary or application support directories that do not correspond to any installed application.
- Entries in the device's network configuration that reference known Pegasus command-and-control domains.
The limitation is that a standard backup does not include the full file system. Files that Pegasus hides in protected system directories may not appear. For a full forensic picture, a file-system extraction is necessary, which on modern devices requires either a known bootrom vulnerability (checkm8, affecting A5 through A11 chips) or a vendor-supported forensic extraction.
Apple Threat Notifications
Since late 2021, Apple has operated a threat notification program that alerts users when the company detects state-sponsored attack activity against their Apple ID. These notifications are sent via email and as a banner in the user's Apple ID settings page. Apple has stated that it uses threat intelligence, including its own analysis of exploit activity, to identify targets.
Apple threat notifications are a valuable signal but have known limitations. They are retrospective, meaning they alert after activity has been detected, not in real time. They also produce false negatives, particularly against the most current exploit variants. A researcher who receives a threat notification should treat it as a strong indicator of compromise and conduct a full forensic analysis. A researcher who does not receive one should not treat that as proof of safety.
Network-Based Detection
A complementary approach is network-based detection. Pegasus communicates with its command-and-control servers over the internet. These servers have been observed to use domain fronting and fast-flux DNS to disguise their location. A network operator or a user with access to their own DNS logs can look for connections to domains matching known Pegasus infrastructure patterns.
Citizen Lab and other researchers maintain lists of suspected Pegasus command-and-control domains. These lists are necessarily incomplete and aging, as NSO Group rotates infrastructure. But in combination with device-based forensics, network analysis can corroborate a finding.
The Reality of Detection in 2026
No single tool provides a definitive answer. The state of the art is a combination of methods: a full file-system extraction analyzed with MVT, cross-referenced against current indicator lists, combined with any available network logs and vendor threat notifications. Even with all of these, a sophisticated and recent Pegasus infection may leave no detectable trace. The honest position is that detection is possible in many cases but not guaranteed in all cases. This is why prevention, including Lockdown Mode for high-risk users, remains essential alongside detection.
References
- Amnesty International Security Lab, MVT Documentation, 2021 through 2026.
- Citizen Lab, Pegasus command-and-control domain publications.
- Apple, Apple Threat Notifications, support documentation.
