MVT — Mobile Verification Toolkit
MVT is an open-source forensic tool developed by Amnesty International's Security Lab for detecting Pegasus and other spyware on iOS and Android devices. It analyzes device backups, system logs, and network traces for indicators of compromise (IOCs).
- 01MVT was developed by Amnesty International's Security Lab and released in 2021
- 02It analyzes iOS backups and Android ADB logs for Pegasus indicators of compromise
- 03MVT requires technical comfort with command-line tools (Python, terminal)
- 04It uses IOC files from Citizen Lab and Amnesty to match against device artifacts
- 05MVT can produce false positives — results should be interpreted with expert guidance
What Is MVT?
The Mobile Verification Toolkit (MVT) is a collection of utilities designed to facilitate the forensic analysis of mobile devices for signs of infection by Pegasus and other mercenary spyware. It was developed by Amnesty International's Security Lab and first released in July 2021 alongside the Pegasus Project investigation.
MVT is open-source (licensed under the MIT license) and available on GitHub. It is designed for forensic investigators, security researchers, and technically capable at-risk users — not for general consumers.
How MVT Works
MVT works by analyzing data from the target device and comparing it against known indicators of compromise (IOCs) — signatures of Pegasus activity identified by Citizen Lab, Amnesty International, and other researchers.
- Collect data from the device (iOS backup or Android ADB logs)
- Parse the data to extract relevant artifacts (logs, files, network traces)
- Compare artifacts against IOC databases (known Pegasus C2 domains, file hashes, process names)
- Flag matches and suspicious patterns
- Generate a report of potential indicators of compromise
iOS Analysis with MVT
For iOS, MVT analyzes an encrypted iTunes/Finder backup of the device:
- Backup creation: Connect the iPhone to a computer and create an encrypted backup via Finder (macOS) or iTunes/Finder (Windows)
- Backup decryption: MVT decrypts the backup using the backup password
- Artifact extraction: MVT extracts SMS/iMessage databases, call logs, browsing history, app data, and system files
- IOC matching: Extracted artifacts are compared against Pegasus IOC databases
- Log analysis: MVT also analyzes sysdiagnose logs (if available) for traces of exploit activity
Android Analysis with MVT
For Android, MVT uses ADB (Android Debug Bridge) to collect data:
- ADB connection: Connect the Android device to a computer with ADB enabled
- Log collection: MVT collects system logs (logcat), app information, and network traces
- App analysis: MVT examines installed apps for suspicious packages or permissions
- IOC matching: Collected data is compared against Pegasus IOC databases
Limitations of MVT
- False positives: MVT can flag benign activity as suspicious. Results require expert interpretation.
- False negatives: Non-persistent infections (memory-only) may leave no traces for MVT to find.
- IOC currency: MVT only detects known IOCs. New Pegasus variants with unknown signatures will not be detected.
- Technical barrier: MVT requires command-line expertise and understanding of forensic concepts.
- Not a guarantee: A clean MVT scan does not guarantee the device is not or was not infected.
- Evidence destruction: Running MVT itself may modify the device. For legal-grade forensics, use a write-blocker and professional tools.
Getting MVT
MVT is available on GitHub at github.com/mvt-project/mvt. Installation requires Python 3.8+ and some command-line setup. Amnesty International provides documentation and IOC files alongside the tool.
If you are a journalist, activist, or human rights defender who suspects you may have been targeted by Pegasus, consider contacting Citizen Lab or Amnesty International's Security Lab directly rather than running MVT yourself. These organizations offer professional forensic analysis and can help interpret results.
