Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

MVT — Mobile Verification Toolkit

MVT is an open-source forensic tool developed by Amnesty International's Security Lab for detecting Pegasus and other spyware on iOS and Android devices. It analyzes device backups, system logs, and network traces for indicators of compromise (IOCs).

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01MVT was developed by Amnesty International's Security Lab and released in 2021
  • 02It analyzes iOS backups and Android ADB logs for Pegasus indicators of compromise
  • 03MVT requires technical comfort with command-line tools (Python, terminal)
  • 04It uses IOC files from Citizen Lab and Amnesty to match against device artifacts
  • 05MVT can produce false positives — results should be interpreted with expert guidance

What Is MVT?

The Mobile Verification Toolkit (MVT) is a collection of utilities designed to facilitate the forensic analysis of mobile devices for signs of infection by Pegasus and other mercenary spyware. It was developed by Amnesty International's Security Lab and first released in July 2021 alongside the Pegasus Project investigation.

MVT is open-source (licensed under the MIT license) and available on GitHub. It is designed for forensic investigators, security researchers, and technically capable at-risk users — not for general consumers.

How MVT Works

MVT works by analyzing data from the target device and comparing it against known indicators of compromise (IOCs) — signatures of Pegasus activity identified by Citizen Lab, Amnesty International, and other researchers.

MVT Analysis Process
  1. Collect data from the device (iOS backup or Android ADB logs)
  2. Parse the data to extract relevant artifacts (logs, files, network traces)
  3. Compare artifacts against IOC databases (known Pegasus C2 domains, file hashes, process names)
  4. Flag matches and suspicious patterns
  5. Generate a report of potential indicators of compromise

iOS Analysis with MVT

For iOS, MVT analyzes an encrypted iTunes/Finder backup of the device:

  • Backup creation: Connect the iPhone to a computer and create an encrypted backup via Finder (macOS) or iTunes/Finder (Windows)
  • Backup decryption: MVT decrypts the backup using the backup password
  • Artifact extraction: MVT extracts SMS/iMessage databases, call logs, browsing history, app data, and system files
  • IOC matching: Extracted artifacts are compared against Pegasus IOC databases
  • Log analysis: MVT also analyzes sysdiagnose logs (if available) for traces of exploit activity

Android Analysis with MVT

For Android, MVT uses ADB (Android Debug Bridge) to collect data:

  • ADB connection: Connect the Android device to a computer with ADB enabled
  • Log collection: MVT collects system logs (logcat), app information, and network traces
  • App analysis: MVT examines installed apps for suspicious packages or permissions
  • IOC matching: Collected data is compared against Pegasus IOC databases

Limitations of MVT

Important Limitations
  • False positives: MVT can flag benign activity as suspicious. Results require expert interpretation.
  • False negatives: Non-persistent infections (memory-only) may leave no traces for MVT to find.
  • IOC currency: MVT only detects known IOCs. New Pegasus variants with unknown signatures will not be detected.
  • Technical barrier: MVT requires command-line expertise and understanding of forensic concepts.
  • Not a guarantee: A clean MVT scan does not guarantee the device is not or was not infected.
  • Evidence destruction: Running MVT itself may modify the device. For legal-grade forensics, use a write-blocker and professional tools.

Getting MVT

MVT is available on GitHub at github.com/mvt-project/mvt. Installation requires Python 3.8+ and some command-line setup. Amnesty International provides documentation and IOC files alongside the tool.

For At-Risk Individuals

If you are a journalist, activist, or human rights defender who suspects you may have been targeted by Pegasus, consider contacting Citizen Lab or Amnesty International's Security Lab directly rather than running MVT yourself. These organizations offer professional forensic analysis and can help interpret results.

A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more