Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

Latest Pegasus News

Each article carries a publication date, last updated date, author, editor, primary sources, evidence status, and related entities. This archive does not fabricate citations or invent developments. For comprehensive background, see the Pegasus zero-click spyware pillar page.

2026-10-02MoroccoAmnesty International Security LabFORENSICALLY CONFIRMED

Morocco Pegasus Investigation: What Amnesty's 2026 Findings Say

Amnesty International Security Lab's October 2026 investigation reported surveillance practices in Morocco and the country's reported use of Pegasus, covering a 2017-2021 period and possibly later activity.

Read full article

On October 1, 2026, Amnesty International published a major investigation concerning surveillance practices in Morocco and the country's reported use of Pegasus. The investigation covered a 2017-2021 period and possibly later activity, documenting one-click attacks, zero-click attacks, and network injection allegations involving telecommunications infrastructure, with targets inside and outside Morocco. Government and agency denials or responses should be sought from official sources where available.

2026-09-25GlobalAmnesty International Security LabCONFIRMED

MVT and Modern Mobile Spyware Investigations

MVT (Mobile Verification Toolkit), developed by Amnesty International Security Lab, assists with mobile forensic analysis by comparing device backups and logs against known indicators of compromise.

Read full article

MVT (Mobile Verification Toolkit) is a collection of utilities developed by Amnesty International Security Lab to assist with mobile forensic analysis. It helps compare iOS forensic backups and Android diagnostic data against known indicators of compromise. MVT can help identify potential compromise but cannot definitively rule out infection in every case. It is intended for consensual digital forensics by qualified practitioners.

2026-09-20GlobalAmnesty International Security LabRESEARCHER ASSESSMENT

Pegasus Detection: What Forensics Can and Cannot Prove

There is no simple consumer Pegasus scanner. Detection requires specialist forensic analysis, and the absence of known indicators is not proof a device was never targeted or compromised.

Read full article

There is no simple consumer Pegasus scanner capable of definitively ruling out infection in every case. Sophisticated spyware tries to minimize evidence, forensic traces vary by exploit and version, and the absence of known indicators is not proof a device was never targeted or compromised. Detection typically requires specialist forensic analysis using tools such as MVT, correlation with known indicators of compromise, and expert interpretation.

2026-09-15GreeceCitizen LabFORENSICALLY CONFIRMED

Former MEP Files Criminal Complaint Over Pegasus Infection

Stelios Kouloglou filed a criminal complaint in Greece in September 2026 concerning Pegasus surveillance documented by Citizen Lab.

Read full article

In September 2026, former MEP and journalist Stelios Kouloglou filed a criminal complaint in Greece concerning Pegasus surveillance documented by Citizen Lab around October 2022 and March 2023. The complaint follows Citizen Lab's July 2026 disclosure. Citizen Lab did not publicly identify the responsible operator.

2026-09-10GlobalApple Inc.CONFIRMED

Apple Threat Notifications Explained in 2026

Apple has reported notifying targeted users in more than 150 countries since 2021. Recipients should verify notifications through their Apple account and not click links in unsolicited messages.

Read full article

Apple Threat Notifications alert users who Apple believes may have been targeted by mercenary spyware. Apple has reported notifying targeted users in more than 150 countries since 2021. Apple states that legitimate threat notifications do not ask users to click unknown links, install applications, or provide passwords. Recipients should verify a notification through their Apple account directly and seek expert help.

2026-09-03SerbiaCitizen LabFORENSICALLY CONFIRMED

Citizen Lab Confirms New iMessage Zero-Click Pegasus Infection

Citizen Lab's September 2026 confirmation marks the most recent documented iMessage zero-click Pegasus infection, continuing the documented progression of zero-click capability into 2026.

Read full article

The September 2026 Citizen Lab confirmation of an iMessage zero-click Pegasus infection against a Serbian student activist continues the documented progression of zero-click capability. The case illustrates that iMessage remains an attack surface despite Apple's BlastDoor mitigations, and that zero-click attacks against then-current iOS remain possible before vendor patches.

2026-09-02SerbiaCitizen LabFORENSICALLY CONFIRMED

Pegasus Zero-Click Spyware Infects Serbian Student Activist

Citizen Lab confirmed a Pegasus infection of a Serbian student activist with high-confidence evidence across December 2025 to January 2026, assessing an iMessage zero-click vector was used. The vulnerability was patched as of iOS 18.4.1.

Read full article

On September 2, 2026, Citizen Lab confirmed a Pegasus infection of a Serbian pro-democracy student activist. Forensic evidence was assessed with high confidence across December 2025 to January 2026. Citizen Lab assessed that an iMessage zero-click vector was used. The relevant vulnerability was subsequently patched as of iOS 18.4.1. SHARE Foundation and Citizen Lab reported that at least 14 civil-society, student, and opposition figures received Apple Threat Notifications. Citizen Lab did not publicly identify the responsible government operator.

2026-08-30GlobalPegasus Research ArchiveRESEARCHER ASSESSMENT

What Is the Difference Between Pegasus, Predator and Graphite?

Pegasus (NSO Group), Predator (Intellexa), and Graphite (Paragon) are distinct mercenary spyware families from different companies, each with its own documented capabilities and operators.

Read full article

Pegasus (NSO Group), Predator (Intellexa), and Graphite (Paragon) are distinct mercenary spyware families developed by different companies. Pegasus is the most extensively documented. Predator has been documented by researchers including Citizen Lab. Graphite has been reported in connection with various governments. Each has its own capabilities, operators, and evidentiary record, and they should not be conflated.

2026-08-20GlobalAmnesty International Security LabCONFIRMED

Pegasus on Android: What the Public Evidence Shows

Pegasus is not exclusively an iPhone threat. Public documents and research describe Android capability, including the historical WhatsApp zero-click attack in 2019.

Read full article

Pegasus is not exclusively an iPhone threat. Public documents and research, including Amnesty's 2026 analysis, describe Android capability. The 2019 WhatsApp zero-click attack affected both iOS and Android. Android forensic research has historically appeared less frequently in datasets, partly because shorter-lived forensic logs can make post-event investigation more difficult. Modern Android security developments include Advanced Protection, Intrusion Logging, and consensual digital forensics tools such as Android Quick Forensics.

2026-08-05GlobalCitizen LabRESEARCHER ASSESSMENT

How Zero-Click Spyware Has Evolved

From the 2016 one-click Trident chain to the 2025-2026 iMessage zero-click infection in Serbia, documented Pegasus capability has evolved toward zero-click delivery against then-current operating systems.

Read full article

Documented Pegasus capability has evolved from the 2016 one-click Trident chain (Ahmed Mansoor) through the 2019 WhatsApp zero-click attack, the 2020 KISMET iMessage zero-click, the 2021 FORCEDENTRY zero-click zero-day, the 2022 HOMAGE/FINDMYPWN/PWNYOURHOME chains, the 2023 BLASTPASS zero-click zero-day, to the 2025-2026 iMessage zero-click infection of a Serbian student activist. The progression shows a sustained shift toward zero-click delivery against then-current, fully patched devices before vendor fixes.

2026-07-17GlobalAmnesty International Security LabRESEARCHER ASSESSMENT

Amnesty Publishes Major New Pegasus Architecture Analysis

Amnesty's July 2026 analysis used internal NSO materials disclosed during WhatsApp litigation to describe the Pegasus architecture, including customer-side and vendor-managed components and anonymized infrastructure.

Read full article

Amnesty International Security Lab's July 16, 2026 analysis described the Pegasus architecture using internal NSO documentation disclosed through the WhatsApp litigation. The analysis distinguishes customer-hosted components (dashboard, collection/storage) from vendor-managed delivery and anonymization infrastructure, describes 'whitened' infrastructure designed to minimize attribution, and a NOC monitoring technical/security alerts. NSO Group maintains that customers conduct surveillance operations and that NSO licenses technology to vetted governmental agencies.

2026-07-16GlobalAmnesty International Security LabRESEARCHER ASSESSMENT

Inside Pegasus: What Newly Disclosed NSO Documents Reveal

Amnesty International Security Lab published its most extensive analysis to date of the Pegasus architecture using internal NSO materials disclosed during WhatsApp litigation, describing customer-side and vendor-managed components, anonymized infrastructure, and a NOC.

Read full article

On July 16, 2026, Amnesty International Security Lab published 'Inside Pegasus', an analysis of internal NSO documentation disclosed through the WhatsApp litigation. According to Amnesty's interpretation, customer-side systems include the Pegasus dashboard and collection/storage infrastructure; parts of delivery and anonymization infrastructure have historically been managed outside the customer environment; NSO documentation refers to anonymized or 'whitened' infrastructure; a Network Operation Center (NOC) is described as monitoring technical/security alerts; and infrastructure was designed to minimize attribution. NSO Group maintains that customers conduct surveillance operations and that NSO licenses technology to vetted governmental agencies for legitimate purposes.

2026-07-02GreeceCitizen LabFORENSICALLY CONFIRMED

Pegasus and the European Parliament: The Kouloglou Case

Citizen Lab revealed Pegasus infections of former MEP and journalist Stelios Kouloglou around October 2022 and March 2023, raising questions about surveillance of a member of the PEGA committee.

Read full article

In July 2026, Citizen Lab revealed that former MEP and journalist Stelios Kouloglou was infected with Pegasus. Forensic infection dates were assessed around 21 October 2022, 6 March 2023, and 7 March 2023. Kouloglou served on the European Parliament's PEGA committee, which investigated spyware use across member states. Citizen Lab did not publicly identify the responsible Pegasus operator. In September 2026, Kouloglou filed a criminal complaint in Greece concerning the surveillance.

2026-06-03United StatesUS federal courtCOURT FINDING

What the 2025 WhatsApp Injunction Means for Pegasus

The 2025 permanent injunction against NSO Group followed a 2024 liability ruling and damages proceedings in which an initial punitive damages award of approximately $167 million was later reduced to $4 million.

Read full article

In 2025, a US federal court issued a permanent injunction against NSO Group in the WhatsApp litigation, following a 2024 liability ruling. The 2025 jury damages proceedings produced an initial punitive damages award of approximately $167 million, subsequently reduced to $4 million. The injunction restrains NSO from certain conduct related to WhatsApp. In 2026, Meta sought to hold NSO in contempt for alleged violations.

2026-06-02United StatesMeta / WhatsAppCOURT FINDING

WhatsApp Seeks Contempt Order Against NSO Group

In June 2026, Meta announced it was asking a federal court to hold NSO Group in contempt for alleged violation of the permanent injunction, and disclosed NSO-linked spear-phishing attempts.

Read full article

In June 2026, Meta announced it was asking a federal court to hold NSO Group in contempt for alleged violation of the permanent injunction issued in 2025. Meta also said WhatsApp disrupted NSO-linked spear-phishing and social-engineering attempts. The 2026 Meta-reported campaign involved one-click social engineering, not zero-click. This distinction is important: the social-engineering attempts should not be labeled zero-click.

A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more