NSO Group and Pegasus Spyware

What matters

  • Pegasus compromises the phone itself. Encryption cannot protect data that spyware reads on an unlocked endpoint.
  • Documented Pegasus attacks have used both malicious links and zero-click exploit chains.
  • Fast updates and Lockdown Mode reduce risk. Neither can prove that a phone is clean.
Product
Pegasus
Warning
Citizen Lab
Attack class
Targeted
Caution
Apple
U.S. restriction
Entity List
Caution
BIS
WhatsApp judgment
$4.45m
Warning
U.S. court

Pegasus is surveillance software made by the Israeli company NSO Group. It is built to enter a target's phone, install an agent without the user's knowledge, and return data to an operator. Evidence filed in the WhatsApp litigation described access to user data, calls, location, messages, and, on some agents, the microphone and camera.

NSO says it licenses its products to government intelligence and law-enforcement agencies for investigations into serious crime and terrorism. That stated purpose does not settle how customers use the tool. The U.S. Commerce Department added NSO Group to the Entity List in 2021 after finding that foreign governments used its spyware to target officials, journalists, businesspeople, activists, academics, and embassy workers.

Why encrypted apps do not solve endpoint compromise

Signal, WhatsApp, and iMessage can protect messages in transit. They cannot keep a message secret from spyware that controls the sending or receiving phone. Once an implant can read local storage, capture the screen, or monitor input, the encryption layer has already finished its job.

This distinction matters. A Pegasus infection does not mean the underlying encryption protocol was broken. It means the attacker reached one endpoint and collected data there. Changing messaging apps on the same compromised phone does not restore control.

How Pegasus reaches a phone

Public investigations have documented one-click attacks delivered through malicious links and zero-click attacks delivered through phone services. A zero-click chain does not require the target to open anything. The vulnerable service processes attacker-controlled data and triggers the exploit.

Citizen Lab documented FORCEDENTRY in 2021, PWNYOURHOME and FINDMYPWN in 2022, and BLASTPASS in 2023. Those chains used different parts of Apple's software, including iMessage, HomeKit, Find My, and PassKit. Apple patched the vulnerabilities after researchers disclosed them. The names describe specific historical exploit chains, not a permanent list of every route Pegasus can use.

Updates matter because they close known routes. They do not rule out a private zero-day that has not yet been found. High-risk users should install operating-system and browser updates as soon as practical instead of waiting for a routine maintenance window.

Who has been documented as a target

Citizen Lab and Amnesty International have published forensic findings involving journalists, human-rights defenders, lawyers, political figures, and civil-society workers in multiple countries. These reports identify particular infections or targeting attempts from device evidence. They do not prove that every number found in a leaked targeting list was infected.

Risk is selective. Most people will face account theft, commodity malware, or phishing before they face Pegasus. Risk rises for people whose private communications carry political, legal, diplomatic, military, or commercial value. Family members and close colleagues can also become routes into a target's network.

What changed in the WhatsApp case

WhatsApp sued NSO Group in 2019. In December 2024, a U.S. district court granted summary judgment to WhatsApp and Meta on liability under federal and California computer-access laws and for breach of contract. A jury later awarded damages. The court reduced the punitive award and entered final judgment in November 2025 for $4,447,190.

The court also issued a permanent injunction. It bars NSO and covered parties from interacting with or emulating the WhatsApp platform without written permission, collecting data from it, reverse engineering it, or creating WhatsApp accounts. The injunction is limited to the WhatsApp platform and excludes NSO's foreign sovereign customers from the defined prohibited parties. NSO appealed. The order does not ban every Pegasus deployment or end the spyware market.

Lockdown Mode reduces attack surface

Apple built Lockdown Mode for the small group of users who may face targeted mercenary spyware. It limits message attachments, some web technologies, unsolicited service invitations, device connections, configuration profiles, and other features that have created attack surface.

Citizen Lab reported that Lockdown Mode blocked or exposed attempts involving specific Pegasus chains. That is useful evidence, not a permanent guarantee. Enable it on every supported Apple device tied to the same accounts. Leaving an iPad or Mac outside the hardened setup keeps another route open.

High-risk mobile rules
Update
Install current operating-system and app security updates on every linked device.
Harden
Enable Lockdown Mode on supported Apple devices when your work or identity creates targeted risk.
Separate
Keep sensitive work and personal activity on different devices and accounts.
Preserve
After a credible warning, stop changing the device and contact a qualified forensic team.

Detection has limits

Amnesty International's Mobile Verification Toolkit can examine backups and system records for known indicators. It is an expert tool, not a consumer antivirus scan. A positive result may support an investigation. A clean result does not prove that no spyware was present.

Evidence can disappear as logs rotate, the implant removes traces, or a phone is reset. Public indicators may also lag behind current attacks. Amnesty advises people in civil society with credible concerns to seek help from reputable forensic specialists who can use current private indicators and interpret ambiguous artifacts.

If Apple sends a threat notification, verify it by signing in directly to your Apple Account rather than following links in an email or message. Preserve the device, record when the warning appeared, and contact a digital-security helpline or forensic team. Do not wipe the phone before getting advice if evidence matters.

Sources

Frequently Asked Questions

What is Pegasus spyware?

Pegasus is phone spyware made by NSO Group. Once installed, it can collect files, messages, location data, calls, and other information from the device. Some versions can activate the microphone or camera.

Can Pegasus infect a phone without a click?

Yes. Citizen Lab has documented several zero-click exploit chains attributed to NSO Group. A zero-click attack does not require the target to open a link or attachment.

Does encryption stop Pegasus?

No. End-to-end encryption protects messages while they travel between devices. Spyware on an endpoint can read data after the receiving device decrypts it or before the sending device encrypts it.

Can Mobile Verification Toolkit prove a phone is clean?

No. MVT can find known forensic indicators, but Amnesty International warns that public tools may not detect the latest spyware without specialist knowledge and private indicators.

Does Lockdown Mode stop Pegasus?

Lockdown Mode reduces attack surface and has blocked documented exploit chains, but it is not a guarantee. High-risk Apple users should update every device, enable Lockdown Mode, and seek expert help after a threat notification or credible warning.