Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

Pegasus Zero-Click Spyware

Pegasus is a commercial spyware product developed by NSO Group that can compromise iOS and Android devices without any action by the target. Zero-click exploits — delivered via iMessage, WhatsApp, or other message channels — require no tap, no click, and no interaction, making them among the most powerful surveillance tools ever deployed against civilians.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01Pegasus is developed by NSO Group, an Israeli cyber-intelligence company founded in 2010
  • 02Zero-click delivery means the target's phone is compromised without any user interaction
  • 03FORCEDENTRY (2021) and BLASTPASS (2023) are the most documented zero-click Pegasus exploits
  • 04Forensic detection requires tools like MVT (Mobile Verification Toolkit) or Apple's Lockdown Mode
  • 05Pegasus has been confirmed on devices of journalists, activists, politicians, and lawyers in 45+ countries
  • 06NSO Group states its products are sold only to vetted government agencies for law-enforcement purposes

What Is Pegasus?

Pegasus is a proprietary spyware suite developed by NSO Group, an Israeli cyber-intelligence company founded in 2010. It is classified as "mercenary spyware" — commercial surveillance software sold to government clients. Once installed on a target's smartphone, Pegasus can extract messages, photos, contacts, location data, microphone audio, and other sensitive information. It can also activate cameras and microphones remotely.

What makes Pegasus particularly dangerous is its zero-click delivery capability. Unlike traditional malware that requires a user to click a link or download a file, zero-click exploits compromise a device through incoming messages or network traffic without any action by the target. The victim receives a message; the exploit runs automatically; the spyware installs itself; the message is deleted — all silently.

How Zero-Click Exploits Work

Zero-click exploits target parsing vulnerabilities in messaging and media-handling software. When a device receives a message — an iMessage, a WhatsApp message, an SMS with an attachment — the operating system automatically processes and renders the content. If the parsing code contains a vulnerability, a specially crafted message can trigger arbitrary code execution during this automatic processing, before the user ever sees or interacts with the message.

The Zero-Click Chain
  1. Attacker sends a specially crafted message (iMessage, WhatsApp, etc.) to the target's phone number
  2. The target's phone receives the message and automatically begins parsing/rendering its content
  3. The exploit triggers a memory corruption or logic bug in the parsing code
  4. Arbitrary code executes with the privileges of the messaging app
  5. The exploit escalates privileges to gain full system access (kernel-level)
  6. Pegasus payload is installed and the original message is silently deleted
  7. The target never sees anything. The phone is now compromised.

Documented Zero-Click Exploits

ExploitYearVectorPlatformInteractionStatus
Trident2016SMS/LinkiOSOne-clickPatched
KISMET2019iMessageiOSZero-clickPatched
FORCEDENTRY2021iMessage (PDF/GIF)iOSZero-clickPatched
BLASTPASS2023iMessage (PassKit)iOSZero-clickPatched
LOCKDOWN-LESS2024iMessage (variant)iOSZero-clickPatched
Chromium-based2025VariousAndroidZero-clickPatched

What Pegasus Can Do

Once installed, Pegasus grants the operator near-total access to the target device. Documented capabilities include:

  • Communication interception: Reading encrypted messages from WhatsApp, Signal, Telegram, iMessage, and others (by reading them before/after encryption, from the device itself)
  • File exfiltration: Downloading photos, videos, documents, contacts, calendars, and call logs
  • Location tracking: Real-time GPS location and historical movement data
  • Audio/visual surveillance: Activating the microphone and camera remotely to record conversations and surroundings
  • Credential theft: Stealing passwords, 2FA codes, and session tokens from keychain and other storage
  • Persistence: Surviving device reboots and operating system updates in some configurations
  • Self-destruction: Removing itself on command or after a set period to avoid detection

Scale of the Problem

45+

Countries with documented Pegasus activity

Source
50,000+

Phone numbers on leaked Pegasus target list

Source
11

Zero-click exploit variants documented

Source

It is critical to distinguish between these numbers. A phone number appearing on a target selection list indicates the operator selected that number for potential surveillance. It does notmean the device was successfully infected. Forensic confirmation requires laboratory analysis of the device itself. Of the 50,000+ numbers on the leaked 2021 list, a subset has been forensically confirmed as infected by Citizen Lab and Amnesty International.

FORENSICALLY CONFIRMED

“Pegasus has been used to spy on journalists, activists, and political dissidents.”

Multiple independent forensic investigations by Citizen Lab, Amnesty International's Security Lab, and the Pegasus Project consortium have confirmed Pegasus infections on devices belonging to journalists, human rights activists, lawyers, and political figures across multiple countries.

CL-2026-09-02

Who Is Affected?

Documented Pegasus targets span a wide range of civil society categories:

  • Journalists: Reporters investigating corruption, human rights abuses, and organized crime — the most documented victim category
  • Activists: Human rights defenders, pro-democracy campaigners, and civil society organizers
  • Politicians: Opposition leaders, government officials, and political operatives — including heads of state
  • Lawyers: Defense attorneys and legal advocates representing dissidents or opposition figures
  • Diplomats: Foreign embassy staff and international organization representatives
  • Researchers: Academics and NGO workers studying surveillance technology
  • Family members: Spouses, children, and associates of primary targets — so-called "collateral" surveillance

How to Detect Pegasus

Detecting Pegasus is extraordinarily difficult because it is designed to operate stealthily and self-destruct to avoid forensic traces. However, several tools and methods have been developed:

  • MVT (Mobile Verification Toolkit): Open-source forensic tool developed by Amnesty International that analyzes iOS/Android backups and device logs for indicators of compromise
  • Apple Threat Notifications: Apple's own warning system that alerts users when state-sponsored attack attempts are detected against their Apple ID
  • Lockdown Mode: Apple's optional extreme security setting that disables high-risk features (message attachment rendering, link previews, etc.) to block zero-click vectors
  • Device check (MDM): Enterprise-level device inspection for managed fleets

For a full guide, see the Detection Hub.

What NSO Group Says — and What Internal Documents Show

NSO Group's Official Position

NSO Group maintains that its technology is licensed exclusively to vetted government intelligence and law-enforcement agencies for legitimate national security and law-enforcement purposes, including counter-terrorism and combating serious crime. The company states it does not operate the technology itself and has no access to data collected by its clients. NSO has also stated it has terminated contracts with clients found to be misusing its products.

What Internal Documents Show (Amnesty International, July 2026)

In July 2026, Amnesty International's Security Lab published "Inside Pegasus" — its most complete analysis to date, based on internal NSO Group documents disclosed during the WhatsApp v. NSO Group litigation. The documents show that:

  • Pegasus is not operated autonomously by government customers — NSO Group plays an active, ongoing role
  • A dedicated "White Services" team acquires anonymized infrastructure for each customer, often paid with cryptocurrencies
  • The "Pegasus Anonymizing Transmission Network" (PATN) hides the customer's location and actions
  • NSO maintains a 24/7 Network Operation Center (NOC) monitoring customer systems
  • NSO builds separate, independent infrastructure for each customer to avoid cross-contamination

Source: Amnesty International Security Lab, "Inside Pegasus," July 31, 2026 (AI-2026-07-31)

Legal and Regulatory Action

Pegasus has been the subject of significant legal and regulatory action worldwide:

  • WhatsApp v. NSO Group (2019): Meta/WhatsApp sued NSO Group in US federal court for exploiting a vulnerability in WhatsApp's call feature to deliver Pegasus to ~1,400 targets. The case proceeded to discovery after the Ninth Circuit ruled NSO could not claim sovereign immunity.
  • Apple v. NSO Group (2021): Apple sued NSO Group in US federal court for targeting Apple users with FORCEDENTRY, seeking an injunction and damages.
  • US Entity List (2021): The US Commerce Department added NSO Group to the Entity List, restricting the company's access to US technology.
  • EU PEGA Committee (2022): The European Parliament established a committee to investigate the use of Pegasus and equivalent surveillance spyware in EU member states.
  • Israel export controls (2022): Israel's Defense Ministry tightened export oversight of NSO Group, requiring additional government approval for sales.

Frequently Asked Questions

See the full FAQ database for 80+ answered questions about Pegasus.

A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more