Pegasus is a mobile spyware product sold by NSO Group, an Israeli surveillance technology company, to government clients worldwide. Once installed on an iPhone or Android device, Pegasus provides complete access to the device: calls, messages, emails, contacts, photos, location history, and real-time microphone and camera activation. It is, by every technical measure, one of the most sophisticated pieces of software ever deployed commercially.

The 2021 Pegasus Project - a consortium of investigative journalists analyzing a leaked list of potential targets - found phone numbers of journalists, human rights activists, lawyers, dissidents, heads of state, and their immediate family members across 50 countries. Among the numbers: phones belonging to the president of France, the prime minister of Pakistan, the king of Morocco, and dozens of journalists investigating governments that were NSO clients. The story of Pegasus is the story of what happens when the most powerful surveillance capability in history is made available as a service to governments that don't share Western legal norms about when it's appropriate to use it.

What Pegasus Does

Pegasus is a full-device implant. Once installed, it has root or kernel-level access to the operating system and can access essentially all data on the device. This includes encrypted messages - not by breaking the encryption, but by reading them before they're encrypted and after they're decrypted, while they appear in the application's memory. Signal messages are as readable as SMS if Pegasus is on the device. Encrypted calls are as audible as an unencrypted call. The device's encryption protects data at rest against physical seizure; Pegasus reads data as it's used.

Real-time capabilities include microphone activation (listening to the room even when the phone appears idle), camera activation, and precise GPS location tracking. The spyware communicates with command-and-control servers over encrypted channels designed to blend with normal network traffic, and includes anti-forensics capabilities to resist detection. It can delete itself in response to a remote command, leaving minimal evidence.

[TECHNICAL NOTE]
Pegasus has used multiple zero-click exploit chains - vulnerabilities that install the spyware without any action by the target. Notable examples: FORCEDENTRY (2021), a zero-click iMessage vulnerability that exploited the image rendering library; KISMET (2020), exploiting iMessage; and earlier vectors via Safari browser. Zero-click means the target receives a message they never open - or in some cases, no message at all. The infection is silent and leaves no visible trace.

NSO Group and the Surveillance Industry

NSO Group was founded in 2010 by three veterans of Israeli military intelligence. The company positioned itself in the "lawful intercept" market - providing surveillance technology to governments for use in criminal and counter-terrorism investigations, legally authorized within the purchasing country. This positioning served a specific legal purpose: it made NSO's technology a product sold to sovereign governments for lawful use, not a weapon sold to criminals.

Israel's defense export regulations require NSO to obtain government approval for each country it sells to. NSO has consistently maintained that it sells only to vetted government clients, that the technology is used only for legitimate law enforcement and intelligence purposes, and that it has processes to prevent abuse. The Pegasus Project and subsequent investigations have provided substantial evidence that this self-regulation is inadequate.

The surveillance technology industry that NSO operates in - sometimes called the "surveillance-as-a-service" or "mercenary spyware" industry - includes multiple companies offering similar capabilities. Candiru (also Israeli), FinFisher (German), Hacking Team (Italian, effectively ended after a 2015 data breach exposed client lists), and various others have operated in this space. The economics are compelling: governments pay tens of millions of dollars for capability that would cost billions to develop internally.

The Pegasus Project

In July 2021, Forbidden Stories and Amnesty International published the first stories from what became known as the Pegasus Project. Working with 17 media organizations, they analyzed a leaked list of 50,000 phone numbers that had been identified as potential Pegasus targets or persons of interest to NSO clients. Amnesty International's Security Lab developed forensic techniques to identify Pegasus infections on devices belonging to people on the list.

The findings were politically explosive. Among confirmed or suspected targets: Jamal Khashoggi's circle (the Saudi journalist murdered in 2018 at the Saudi consulate in Istanbul, before which his associates were confirmed Pegasus targets), French President Emmanuel Macron, Pakistani Prime Minister Imran Khan, journalists at the New York Times, Washington Post, BBC, the Guardian, Le Monde, and dozens of other outlets, lawyers and activists in multiple countries, and private individuals with no apparent connection to security threats.

NSO disputed the findings, arguing that the leaked list was not a list of targets but rather a list of numbers from which potential targets might be selected, and that not all numbers on the list were actually infected. Technical forensic analysis confirmed infections on dozens of devices, including those belonging to close associates of Khashoggi and phones belonging to people who clearly should not have been legitimate intelligence targets.

FORCEDENTRY

The most technically significant revelation from the Pegasus Project was the FORCEDENTRY exploit. Discovered by Citizen Lab and analyzed by Apple's Security Engineering and Architecture team, FORCEDENTRY was a zero-click exploit that worked by sending a malformed PDF disguised as a GIF file through iMessage. The image rendering library - CoreGraphics - crashed while processing the malformed file, and the crash was used to execute arbitrary code. No user interaction was required; receiving the message was sufficient.

Apple patched FORCEDENTRY in September 2021 after being notified. What made FORCEDENTRY particularly significant from a security research perspective was that it bypassed BlastDoor - a security feature Apple had specifically added to iMessage in iOS 14 to process messages in a sandboxed environment, explicitly to prevent this category of attack. FORCEDENTRY found a way to exploit a component outside the BlastDoor sandbox. This quality of exploit - specifically engineered to defeat targeted mitigations - is characteristic of well-funded, long-term development programs.

[WARNING]
Apple has filed suit against NSO Group in US federal court. The US Department of Commerce added NSO Group to the Entity List in November 2021, effectively prohibiting US companies from providing NSO with technology. Congress has held multiple hearings on commercial surveillance technology. Despite this, NSO continues to operate, and the broader mercenary spyware industry continues to develop new capabilities.

Targeting Journalists

The documented targeting of journalists is among the most consequential aspects of the Pegasus story. When governments with active press suppression agendas are given capabilities to read every message a journalist sends, access their confidential source communications, and track their physical location in real time, the effect on press freedom is severe.

Multiple journalists covering the Saudi government, the Mexican government, the Indian government, and others were confirmed Pegasus targets. In some cases, the infections were detected through forensic analysis after the journalists noticed suspicious phone behavior. In most cases, there would have been no indication. Sources who believed their communications were confidential were exposed. The chilling effect on journalism in affected regions is substantial and not easily quantified.

The targeting of Jamal Khashoggi's inner circle with Pegasus before his murder at the Saudi consulate in Istanbul did not directly implicate NSO Group in the murder. But the timeline - Saudi Arabia, a confirmed NSO client, using Pegasus against people close to a journalist it subsequently killed - represents the most extreme possible illustration of how surveillance tools can be components of a campaign that ends in physical violence.

Defensive Measures and Limitations

Apple introduced Lockdown Mode in iOS 16 as a direct response to sophisticated attacks like Pegasus. Lockdown Mode significantly restricts the attack surface of an iPhone by disabling most message attachment functionality, limiting Safari JavaScript, blocking FaceTime calls from unknown contacts, and other measures. It is explicitly designed for the small number of individuals - journalists, activists, lawyers, dissidents - who are likely to be targeted by state-sponsored spyware. For most users it is too restrictive; for those facing active targeting, it represents meaningful additional protection.

The fundamental limitation is that mobile devices are extraordinarily complex systems with large attack surfaces, and zero-day vulnerabilities in that attack surface will always exist. Companies like NSO employ or contract teams of researchers whose sole job is finding these vulnerabilities. Apple and Google invest heavily in reducing the attack surface and detecting infections, but the economics of zero-day research favor the attackers in the short term. A vendor can be paid tens of millions for a single working zero-click chain; defending against all possible chains is a much harder problem.

For individuals who believe they may be targets of sophisticated spyware: device rotation (using a phone for a limited period and then destroying and replacing it), complete device restores, and physical isolation of sensitive communications are imperfect but meaningful mitigations. The most effective approach is to assume that any mobile device may be compromised if you are a high-value target for a nation-state or a client of the mercenary spyware industry - and conduct the most sensitive communications in ways that don't rely on phone security.

The Legal and Policy Landscape

The Pegasus Project triggered a cascade of regulatory responses. The US Entity List designation limits NSO's access to US technology. The European Parliament established a committee to investigate Pegasus use within EU member states - Hungary, Poland, and others had used it against domestic opponents and journalists. Multiple countries opened investigations.

But the fundamental legal architecture around commercial surveillance technology remains inadequate. Export control regimes designed for physical weapons don't map cleanly to software. Countries that purchase surveillance technology and use it against their own citizens are making sovereign decisions about domestic law enforcement that are difficult for other countries to constrain through commercial regulations. The people most at risk - journalists, activists, lawyers in authoritarian or semi-authoritarian states - have the least political capacity to influence the policies that govern the tools used against them.

NSO's story is not unique. It is the most documented example of an industry that continues to operate. Newer entrants with lower profiles operate in the same market with less scrutiny. The capability continues to advance. The question of whether commercial spyware should exist, under what conditions it is legitimate, and how governments with legitimate law enforcement needs can meet them without enabling the systematic surveillance of journalists and dissidents is a question the international community has not answered.