Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

Pegasus on Android

Pegasus has been documented on Android since 2017. While iOS has received more public attention, Android variants of Pegasus are equally capable and often more persistent — surviving device reboots. Detection on Android requires different forensic techniques than iOS.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01Android Pegasus variants are typically persistent — they survive device reboots
  • 02Android delivery vectors include WhatsApp call exploitation, SMS links, and malicious apps
  • 03Android forensic analysis uses different techniques than iOS (ADB logs, app analysis)
  • 04MVT supports Android analysis through ADB (Android Debug Bridge) log collection
  • 05Fragmentation across Android versions and manufacturers complicates both exploitation and detection

History of Pegasus on Android

Pegasus on Android was first publicly documented in 2017 by Lookout and Citizen Lab. The Android variant has evolved alongside the iOS version, with delivery methods and capabilities adapted to the Android platform.

EraVectorInteractionPersistenceNotes
2017–2019WhatsApp call, SMS linkZero-click / one-clickPersistent (APK)First documented Android variant
2019–2021WhatsApp call exploitZero-clickPersistentSimilar to iOS KISMET era
2021–2023VariousZero-click / one-clickPersistentPost-FORCEDENTRY era
2023–2026Chromium-based, messagingZero-clickPersistentModern variants

Delivery Vectors on Android

Pegasus on Android uses several delivery methods:

  • WhatsApp call exploit (2019): A vulnerability in WhatsApp's call setup protocol allowed Pegasus to be delivered via a missed call — even if the call was not answered. This affected both Android and iOS.
  • SMS with link: One-click delivery via a link in an SMS message that leads to a web exploit
  • Malicious apps: In some cases, Pegasus has been delivered disguised as legitimate apps or through compromised app distribution channels
  • Browser exploits: Chromium-based exploits delivered via malicious web pages (one-click)
  • Zero-click messaging: Similar to iOS, exploiting automatic message processing in Android messaging apps

Persistence on Android

Android Persistence

Unlike iOS, where Pegasus often operates in a non-persistent (memory-only) mode, Android variants of Pegasus are typically persistent. They install as system-level services or APKs that survive device reboots. This makes them easier to detect through filesystem analysis but harder to remove without a factory reset.

Android persistence methods include:

  • System APK: Installed as a system-level package, sometimes disguised as a legitimate system service
  • Daemon process: A background service that restarts automatically after reboot
  • Boot receiver: A broadcast receiver that triggers on BOOT_COMPLETED to restart the spyware
  • Device admin: Granted device administrator privileges to resist uninstallation

Android Fragmentation

Android's fragmentation — the wide variety of manufacturers, Android versions, and custom UI layers — affects both exploitation and detection:

  • For attackers: Fragmentation means more potential vulnerabilities across different OEM implementations, but also requires more exploit variants to cover the ecosystem
  • For defenders: Fragmentation means patch availability varies widely — some manufacturers delay security patches by months, leaving devices vulnerable longer
  • For forensic analysts: Different Android versions and OEM customizations require different analysis techniques and tools

Detection on Android

Detecting Pegasus on Android requires different techniques than iOS:

  • MVT (Android mode): Uses ADB (Android Debug Bridge) to collect system logs and analyze them for indicators of compromise
  • App analysis: Examining installed apps for suspicious packages, permissions, or behaviors
  • Log analysis: Examining system logs (logcat) for traces of exploit activity or C2 communication
  • Network analysis: Monitoring network traffic for connections to known Pegasus C2 infrastructure
  • Filesystem analysis: Looking for suspicious files, binaries, or configuration in system directories

See MVT for the primary open-source detection tool.

How to Check Your Android Phone

  1. Install the latest security patch — check Settings → System → System update
  2. Review installed apps for anything unfamiliar (Settings → Apps)
  3. Check for device admin apps (Settings → Security → Device admin apps) — remove anything unrecognized
  4. Use Google Play Protect (enabled by default) to scan for harmful apps
  5. Use MVT with ADB for forensic analysis (requires technical expertise)
  6. Look for indirect indicators: unexpected battery drain, data usage, device running warm
  7. If you suspect targeting, contact a professional forensic investigator

iOS vs Android: Key Differences

AspectiOSAndroid
Primary vectoriMessageWhatsApp / SMS / browser
PersistenceOften non-persistentTypically persistent
Detection difficultyHarder (memory-only)Easier (files on disk)
Patch speedFast (Apple controls all)Varies by manufacturer
FragmentationLow (few models)High (many OEMs)
Lockdown Mode equivalentYes (iOS 16+)No equivalent
Threat notificationsApple Threat NotificationsGoogle Play Protect (limited)
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more