Pegasus on Android
Pegasus has been documented on Android since 2017. While iOS has received more public attention, Android variants of Pegasus are equally capable and often more persistent — surviving device reboots. Detection on Android requires different forensic techniques than iOS.
- 01Android Pegasus variants are typically persistent — they survive device reboots
- 02Android delivery vectors include WhatsApp call exploitation, SMS links, and malicious apps
- 03Android forensic analysis uses different techniques than iOS (ADB logs, app analysis)
- 04MVT supports Android analysis through ADB (Android Debug Bridge) log collection
- 05Fragmentation across Android versions and manufacturers complicates both exploitation and detection
History of Pegasus on Android
Pegasus on Android was first publicly documented in 2017 by Lookout and Citizen Lab. The Android variant has evolved alongside the iOS version, with delivery methods and capabilities adapted to the Android platform.
| Era | Vector | Interaction | Persistence | Notes |
|---|---|---|---|---|
| 2017–2019 | WhatsApp call, SMS link | Zero-click / one-click | Persistent (APK) | First documented Android variant |
| 2019–2021 | WhatsApp call exploit | Zero-click | Persistent | Similar to iOS KISMET era |
| 2021–2023 | Various | Zero-click / one-click | Persistent | Post-FORCEDENTRY era |
| 2023–2026 | Chromium-based, messaging | Zero-click | Persistent | Modern variants |
Delivery Vectors on Android
Pegasus on Android uses several delivery methods:
- WhatsApp call exploit (2019): A vulnerability in WhatsApp's call setup protocol allowed Pegasus to be delivered via a missed call — even if the call was not answered. This affected both Android and iOS.
- SMS with link: One-click delivery via a link in an SMS message that leads to a web exploit
- Malicious apps: In some cases, Pegasus has been delivered disguised as legitimate apps or through compromised app distribution channels
- Browser exploits: Chromium-based exploits delivered via malicious web pages (one-click)
- Zero-click messaging: Similar to iOS, exploiting automatic message processing in Android messaging apps
Persistence on Android
Unlike iOS, where Pegasus often operates in a non-persistent (memory-only) mode, Android variants of Pegasus are typically persistent. They install as system-level services or APKs that survive device reboots. This makes them easier to detect through filesystem analysis but harder to remove without a factory reset.
Android persistence methods include:
- System APK: Installed as a system-level package, sometimes disguised as a legitimate system service
- Daemon process: A background service that restarts automatically after reboot
- Boot receiver: A broadcast receiver that triggers on BOOT_COMPLETED to restart the spyware
- Device admin: Granted device administrator privileges to resist uninstallation
Android Fragmentation
Android's fragmentation — the wide variety of manufacturers, Android versions, and custom UI layers — affects both exploitation and detection:
- For attackers: Fragmentation means more potential vulnerabilities across different OEM implementations, but also requires more exploit variants to cover the ecosystem
- For defenders: Fragmentation means patch availability varies widely — some manufacturers delay security patches by months, leaving devices vulnerable longer
- For forensic analysts: Different Android versions and OEM customizations require different analysis techniques and tools
Detection on Android
Detecting Pegasus on Android requires different techniques than iOS:
- MVT (Android mode): Uses ADB (Android Debug Bridge) to collect system logs and analyze them for indicators of compromise
- App analysis: Examining installed apps for suspicious packages, permissions, or behaviors
- Log analysis: Examining system logs (logcat) for traces of exploit activity or C2 communication
- Network analysis: Monitoring network traffic for connections to known Pegasus C2 infrastructure
- Filesystem analysis: Looking for suspicious files, binaries, or configuration in system directories
See MVT for the primary open-source detection tool.
How to Check Your Android Phone
- Install the latest security patch — check Settings → System → System update
- Review installed apps for anything unfamiliar (Settings → Apps)
- Check for device admin apps (Settings → Security → Device admin apps) — remove anything unrecognized
- Use Google Play Protect (enabled by default) to scan for harmful apps
- Use MVT with ADB for forensic analysis (requires technical expertise)
- Look for indirect indicators: unexpected battery drain, data usage, device running warm
- If you suspect targeting, contact a professional forensic investigator
iOS vs Android: Key Differences
| Aspect | iOS | Android |
|---|---|---|
| Primary vector | iMessage | WhatsApp / SMS / browser |
| Persistence | Often non-persistent | Typically persistent |
| Detection difficulty | Harder (memory-only) | Easier (files on disk) |
| Patch speed | Fast (Apple controls all) | Varies by manufacturer |
| Fragmentation | Low (few models) | High (many OEMs) |
| Lockdown Mode equivalent | Yes (iOS 16+) | No equivalent |
| Threat notifications | Apple Threat Notifications | Google Play Protect (limited) |
