Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.
Pegasus & Spyware Glossary
A growing reference of 50+ terms covering Pegasus, NSO Group, zero-click concepts, exploit chains, forensic terminology, and the legal/policy landscape.
A
Amnesty International Security Lab
entityAmnesty International's technical research unit, co-founder of the Pegasus Project and developer of MVT.
Apple Threat Notification
technicalApple's alert to users who may have been targeted by mercenary spyware. Apple has reported notifying users in more than 150 countries since 2021.
Attack surface reduction
conceptA defensive approach that limits the features and channels an attacker can target, exemplified by Apple's Lockdown Mode and BlastDoor.
Attribution
conceptThe process of identifying the actor responsible for an attack. Attribution may be made with varying levels of confidence.
B
BLASTPASS
exploitA 2023 zero-click, zero-day Pegasus exploit targeting PassKit/iMessage on iOS 16.6, patched in iOS 16.6.1.
BlastDoor
technicalApple's security architecture for iMessage that processes untrusted data in a hardened, isolated environment, introduced in response to iMessage zero-click research.
C
C2
technicalSee Command and Control.
CVE
technicalCommon Vulnerabilities and Exposures: a standardized identifier for publicly disclosed software vulnerabilities.
Citizen Lab
entityAn interdisciplinary research laboratory at the University of Toronto's Munk School that has produced foundational Pegasus research.
Command and Control
technicalInfrastructure used by operators to issue commands to compromised devices and receive exfiltrated data. Abbreviated C2.
Commercial surveillance vendor
entityA company that develops and sells surveillance capabilities, typically to government customers. Also called a mercenary spyware company.
Consensual digital forensics
conceptForensic examination of a device conducted with the informed consent of its owner, the standard approach for investigating suspected spyware infections.
E
Endpoint
conceptA device such as a smartphone that is the target of surveillance. Endpoint compromise can expose data even when communications are encrypted in transit.
Entity List
legalA US Commerce Department trade restriction list. NSO Group and Candiru were added on November 3, 2021, restricting access to US-origin items.
Exfiltration
technicalThe unauthorized transfer of data from a compromised device to an attacker-controlled destination.
Exploit
technicalCode or a technique that takes advantage of a vulnerability to cause unintended behavior in software, often enabling unauthorized access or code execution.
Exploit chain
technicalA sequence of exploits combined to achieve a goal such as remote code execution and privilege escalation, often chaining multiple vulnerabilities.
F
FINDMYPWN
exploitA 2022-era Pegasus zero-click chain documented in Citizen Lab's Triple Threat research.
FORCEDENTRY
exploitA 2021 zero-click, zero-day iMessage Pegasus exploit (CVE-2021-30860) captured by Citizen Lab and patched by Apple.
Forbidden Stories
entityA non-profit journalism organization that coordinated the Pegasus Project collaboration.
Forensic artifact
technicalA trace left on a device or in logs by an exploit or spyware, used by investigators to assess whether compromise occurred.
H
HOMAGE
exploitA zero-click capability identified during the CatalanGate research affecting older iOS versions.
I
IOC
technicalIndicator of Compromise: an observable artifact (a file path, domain, configuration value) that suggests a system may have been compromised.
Indicator of Compromise
technicalSee IOC. Forensic evidence used to identify potential compromise.
iMessage
technicalApple's messaging service, a documented attack surface for zero-click Pegasus exploits including KISMET, FORCEDENTRY, and BLASTPASS.
K
KISMET
exploitA 2020 iMessage zero-click Pegasus exploit chain active in the iOS 13 era, documented by Citizen Lab.
Kernel exploit
technicalAn exploit targeting the operating system kernel to gain privileged control over a device.
L
Lockdown Mode
technicalAn optional Apple security setting that reduces attack surface by disabling or limiting high-risk features. It is not a guarantee of immunity.
M
MVT
technicalMobile Verification Toolkit: a collection of utilities to assist with mobile forensic analysis, developed by Amnesty International Security Lab.
Man-in-the-middle
technicalAn attack where an adversary intercepts or alters communications between parties, distinct from endpoint compromise.
Megalodon
exploitTerminology used by Amnesty researchers in relation to FORCEDENTRY-era analysis.
Mercenary spyware
conceptCommercial surveillance software sold to government customers, often used in targeted operations. Pegasus is the most extensively documented example.
N
NSO Group
entityIsrael-based company that develops and licenses Pegasus spyware to vetted governmental agencies. NSO states its technology is used for legitimate law-enforcement and national-security purposes.
Network injection
technicalAn attack technique where malicious content is injected into network traffic to deliver an exploit, sometimes associated with telecommunications infrastructure.
O
One-click
conceptAn attack that requires the target to perform a single interaction, such as clicking a malicious link, to begin exploitation.
P
PEGA Committee
entityThe European Parliament's committee of inquiry investigating the use of Pegasus and equivalent spyware, which issued 2023 recommendations.
PWNYOURHOME
exploitA 2022 two-stage Pegasus attack involving HomeKit and iMessage according to Citizen Lab.
PassKit
technicalApple's framework for Wallet/pass content; exploited by the BLASTPASS zero-click chain via malicious pass attachments delivered through iMessage.
Payload
technicalThe component delivered by an exploit that performs the intended malicious action, such as installing spyware.
Pegasus
entitySophisticated mobile surveillance software developed by NSO Group and licensed to government intelligence and law-enforcement customers, capable of compromising smartphones and collecting sensitive information.
Pegasus Project
entityA 2021 collaborative investigation by Forbidden Stories, Amnesty International, and more than 80 journalists across 17 media organizations analyzing a leaked dataset of approximately 50,000 numbers selected as potential surveillance targets.
Privilege escalation
technicalGaining higher permissions on a device than intended, often a step in an exploit chain.
R
Remote code execution
technicalThe ability of an attacker to run arbitrary code on a target device, often achieved through an exploit.
S
Sandbox escape
technicalAn exploit that breaks out of a restricted execution environment (sandbox) to access broader system resources.
Spyware
conceptSoftware designed to covertly monitor and collect information from a device.
T
Threat notification
conceptA security alert from a vendor (e.g., Apple) informing a user they may have been targeted by mercenary spyware.
Trident
exploitA 2016 one-click Pegasus exploit chain (CVE-2016-4657/4655/4656) targeting iOS via a malicious link, documented in the Ahmed Mansoor case.
W
WebKit
technicalThe web browser engine used by iOS, historically a target for exploit chains including Trident.
Z
Zero-click
conceptAn attack that begins without requiring the target to click a link, download an attachment, install an application, or knowingly interact with the attacker.
Zero-day
technicalA vulnerability that is unknown to the vendor or for which no patch is yet available. Zero-day is distinct from zero-click: one concerns patch status, the other user interaction.
