Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

Pegasus Capabilities

Pegasus can intercept encrypted communications, exfiltrate files, track location, activate microphones and cameras, steal credentials, and persist across reboots. Its full capability set makes it one of the most powerful commercial spyware products ever documented.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01Pegasus can read messages from encrypted apps by accessing them on-device after decryption
  • 02It can activate microphones and cameras remotely for real-time surveillance
  • 03It steals credentials from the device keychain (passwords, 2FA tokens, session cookies)
  • 04It can track real-time GPS location and historical movement patterns
  • 05Persistence varies — some iOS infections are memory-only; Android variants can survive reboots

Communication Interception

Pegasus can read messages from end-to-end encrypted apps — not by breaking the encryption, but by accessing the messages on the device itself after they have been decrypted for display. This includes:

  • WhatsApp: All messages, calls, voice notes, and shared media
  • Signal: Messages and voice messages (accessed from device storage)
  • iMessage: All messages, attachments, and iCloud-synced conversations
  • Telegram: Messages, media, and secret chats
  • SMS/MMS: All text and multimedia messages
  • Email: Content from Mail, Gmail, Outlook, and other email apps
  • Voice calls: Call audio, metadata, and recordings
Why End-to-End Encryption Doesn't Help

End-to-end encryption protects messages in transit — between the sender's and recipient's devices. But once a message arrives on the target's phone, it is decrypted for display. Pegasus reads the decrypted message directly from the device's memory or storage, bypassing the encryption entirely. No encryption standard can protect against this — the vulnerability is physical access to the device.

File & Data Exfiltration

Pegasus can download any file from the target device:

  • Photos and videos (including deleted items in some cases, from the photo trash)
  • Documents (PDFs, Word, Excel, etc.)
  • Contacts and calendar entries
  • Call logs (incoming, outgoing, missed, duration)
  • Browsing history and bookmarks
  • App data from third-party applications
  • Clipboard contents

Location Tracking

Pegasus provides both real-time and historical location data:

  • Real-time GPS: Current latitude/longitude from the device's GPS chip
  • Wi-Fi positioning: Location derived from nearby Wi-Fi networks
  • Cell tower data: Approximate location from cellular network connections
  • Historical movement: Past location data stored on the device (Significant Locations, Google Timeline)

Audio & Visual Surveillance

Pegasus can remotely activate the device's microphone and camera(s) to record conversations and surroundings:

  • Microphone activation: Record ambient audio and phone conversations without the user's knowledge
  • Camera activation: Capture photos and video from front and rear cameras
  • On-demand recording: The operator can trigger recording at specific times or continuously
  • Stealth operation: Camera and microphone indicators are suppressed — no red dot, no notification

Credential Theft

Pegasus can extract stored credentials from the device:

  • iOS Keychain: Passwords, tokens, and certificates stored in Apple's encrypted keychain
  • 2FA/MFA codes: Two-factor authentication codes from authenticator apps and SMS
  • Session cookies: Browser and app session tokens that allow account takeover without re-login
  • Saved passwords: Passwords stored in browsers, password managers, and apps
  • Biometric bypass: While biometrics (Face ID/Touch ID) cannot be directly extracted, stolen session tokens allow account access without biometric authentication

Capability Comparison: iOS vs Android

CapabilityiOSAndroid
Encrypted message accessYesYes
File exfiltrationYesYes
Location trackingYesYes
Microphone activationYesYes
Camera activationYesYes
Credential theft (keychain)Yes (Keychain)Yes (Keystore)
Persistence (survives reboot)SometimesYes (typically)
Self-destructYesYes
Kernel-level accessYes (via exploit)Yes (via exploit)
App sandbox escapeYesYes

What Pegasus Cannot Do

Limitations
  • Cannot break encryption in transit: It reads messages on-device, not by intercepting encrypted traffic
  • Cannot infect a fully patched, locked-down device indefinitely: Apple and Google release patches for discovered vulnerabilities
  • Cannot operate without a network connection: C2 communication requires internet access
  • Cannot infect via physical proximity alone: It requires a delivery vector (message, link, or network)
  • Cannot bypass hardware security modules (SEP/TrustZone) directly: It targets the OS, not the secure enclave
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more