Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

Pegasus & Spyware Glossary

A growing reference of 50+ terms covering Pegasus, NSO Group, zero-click concepts, exploit chains, forensic terminology, and the legal/policy landscape.

A

Amnesty International Security Lab

entity

Amnesty International's technical research unit, co-founder of the Pegasus Project and developer of MVT.

Citizen LabMVTPegasus Project

Apple Threat Notification

technical

Apple's alert to users who may have been targeted by mercenary spyware. Apple has reported notifying users in more than 150 countries since 2021.

Lockdown ModeThreat notification

Attack surface reduction

concept

A defensive approach that limits the features and channels an attacker can target, exemplified by Apple's Lockdown Mode and BlastDoor.

Lockdown ModeBlastDoor

Attribution

concept

The process of identifying the actor responsible for an attack. Attribution may be made with varying levels of confidence.

Forensic artifactCommand and Control

B

BLASTPASS

exploit

A 2023 zero-click, zero-day Pegasus exploit targeting PassKit/iMessage on iOS 16.6, patched in iOS 16.6.1.

PassKitiMessageFORCEDENTRY

BlastDoor

technical

Apple's security architecture for iMessage that processes untrusted data in a hardened, isolated environment, introduced in response to iMessage zero-click research.

iMessageKISMETFORCEDENTRY

C

C2

technical

See Command and Control.

Command and Control

CVE

technical

Common Vulnerabilities and Exposures: a standardized identifier for publicly disclosed software vulnerabilities.

Zero-dayExploit

Citizen Lab

entity

An interdisciplinary research laboratory at the University of Toronto's Munk School that has produced foundational Pegasus research.

Amnesty International Security LabPegasus

Command and Control

technical

Infrastructure used by operators to issue commands to compromised devices and receive exfiltrated data. Abbreviated C2.

C2ExfiltrationAttribution

Commercial surveillance vendor

entity

A company that develops and sells surveillance capabilities, typically to government customers. Also called a mercenary spyware company.

Mercenary spywareNSO Group

Consensual digital forensics

concept

Forensic examination of a device conducted with the informed consent of its owner, the standard approach for investigating suspected spyware infections.

MVTForensic artifact

E

Endpoint

concept

A device such as a smartphone that is the target of surveillance. Endpoint compromise can expose data even when communications are encrypted in transit.

ExfiltrationZero-click

Entity List

legal

A US Commerce Department trade restriction list. NSO Group and Candiru were added on November 3, 2021, restricting access to US-origin items.

NSO GroupUS Department of Commerce

Exfiltration

technical

The unauthorized transfer of data from a compromised device to an attacker-controlled destination.

Command and ControlEndpoint

Exploit

technical

Code or a technique that takes advantage of a vulnerability to cause unintended behavior in software, often enabling unauthorized access or code execution.

VulnerabilityExploit chainPayload

Exploit chain

technical

A sequence of exploits combined to achieve a goal such as remote code execution and privilege escalation, often chaining multiple vulnerabilities.

ExploitPrivilege escalationSandbox escape

F

FINDMYPWN

exploit

A 2022-era Pegasus zero-click chain documented in Citizen Lab's Triple Threat research.

iMessagePWNYOURHOME

FORCEDENTRY

exploit

A 2021 zero-click, zero-day iMessage Pegasus exploit (CVE-2021-30860) captured by Citizen Lab and patched by Apple.

iMessageMegalodonKISMET

Forbidden Stories

entity

A non-profit journalism organization that coordinated the Pegasus Project collaboration.

Pegasus ProjectAmnesty International Security Lab

Forensic artifact

technical

A trace left on a device or in logs by an exploit or spyware, used by investigators to assess whether compromise occurred.

IOCAttribution

H

HOMAGE

exploit

A zero-click capability identified during the CatalanGate research affecting older iOS versions.

CatalanGateiMessage

I

IOC

technical

Indicator of Compromise: an observable artifact (a file path, domain, configuration value) that suggests a system may have been compromised.

Indicator of CompromiseForensic artifact

Indicator of Compromise

technical

See IOC. Forensic evidence used to identify potential compromise.

IOCForensic artifact

iMessage

technical

Apple's messaging service, a documented attack surface for zero-click Pegasus exploits including KISMET, FORCEDENTRY, and BLASTPASS.

BlastDoorFORCEDENTRYKISMETBLASTPASS

K

KISMET

exploit

A 2020 iMessage zero-click Pegasus exploit chain active in the iOS 13 era, documented by Citizen Lab.

iMessageBlastDoorFORCEDENTRY

Kernel exploit

technical

An exploit targeting the operating system kernel to gain privileged control over a device.

ExploitPrivilege escalationSandbox escape

L

Lockdown Mode

technical

An optional Apple security setting that reduces attack surface by disabling or limiting high-risk features. It is not a guarantee of immunity.

Apple Threat NotificationAttack surface reduction

M

MVT

technical

Mobile Verification Toolkit: a collection of utilities to assist with mobile forensic analysis, developed by Amnesty International Security Lab.

Amnesty International Security LabIOCForensic artifact

Man-in-the-middle

technical

An attack where an adversary intercepts or alters communications between parties, distinct from endpoint compromise.

Network injection

Megalodon

exploit

Terminology used by Amnesty researchers in relation to FORCEDENTRY-era analysis.

FORCEDENTRY

Mercenary spyware

concept

Commercial surveillance software sold to government customers, often used in targeted operations. Pegasus is the most extensively documented example.

PegasusCommercial spywareCommercial surveillance vendor

N

NSO Group

entity

Israel-based company that develops and licenses Pegasus spyware to vetted governmental agencies. NSO states its technology is used for legitimate law-enforcement and national-security purposes.

Pegasus

Network injection

technical

An attack technique where malicious content is injected into network traffic to deliver an exploit, sometimes associated with telecommunications infrastructure.

Man-in-the-middleOne-click

O

One-click

concept

An attack that requires the target to perform a single interaction, such as clicking a malicious link, to begin exploitation.

Zero-clickTrident

P

PEGA Committee

entity

The European Parliament's committee of inquiry investigating the use of Pegasus and equivalent spyware, which issued 2023 recommendations.

European Parliament

PWNYOURHOME

exploit

A 2022 two-stage Pegasus attack involving HomeKit and iMessage according to Citizen Lab.

FINDMYPWNiMessage

PassKit

technical

Apple's framework for Wallet/pass content; exploited by the BLASTPASS zero-click chain via malicious pass attachments delivered through iMessage.

BLASTPASSiMessage

Payload

technical

The component delivered by an exploit that performs the intended malicious action, such as installing spyware.

ExploitSpyware

Pegasus

entity

Sophisticated mobile surveillance software developed by NSO Group and licensed to government intelligence and law-enforcement customers, capable of compromising smartphones and collecting sensitive information.

NSO GroupZero-clickSpyware

Pegasus Project

entity

A 2021 collaborative investigation by Forbidden Stories, Amnesty International, and more than 80 journalists across 17 media organizations analyzing a leaked dataset of approximately 50,000 numbers selected as potential surveillance targets.

Forbidden StoriesAmnesty International Security Lab

Privilege escalation

technical

Gaining higher permissions on a device than intended, often a step in an exploit chain.

Exploit chainKernel exploit

R

Remote code execution

technical

The ability of an attacker to run arbitrary code on a target device, often achieved through an exploit.

ExploitKernel exploitSandbox escape

S

Sandbox escape

technical

An exploit that breaks out of a restricted execution environment (sandbox) to access broader system resources.

Exploit chainKernel exploit

Spyware

concept

Software designed to covertly monitor and collect information from a device.

PegasusMercenary spyware

T

Threat notification

concept

A security alert from a vendor (e.g., Apple) informing a user they may have been targeted by mercenary spyware.

Apple Threat NotificationLockdown Mode

Trident

exploit

A 2016 one-click Pegasus exploit chain (CVE-2016-4657/4655/4656) targeting iOS via a malicious link, documented in the Ahmed Mansoor case.

PegasusWebKitKernel exploit

W

WebKit

technical

The web browser engine used by iOS, historically a target for exploit chains including Trident.

TridentExploit

Z

Zero-click

concept

An attack that begins without requiring the target to click a link, download an attachment, install an application, or knowingly interact with the attacker.

One-clickZero-dayExploit chain

Zero-day

technical

A vulnerability that is unknown to the vendor or for which no patch is yet available. Zero-day is distinct from zero-click: one concerns patch status, the other user interaction.

Zero-clickCVEExploit
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more