Pegasus is
spyware
Spyware (a portmanteau for spying software) is any malware that aims to gather information about a person or organization and send it to another entity in a way that harms the user by violating their privacy, endangering their device's securit ...
developed by the Israeli
cyber-arms company
NSO Group
NSO Group Technologies (NSO standing for Niv, Shalev and Omri, the names of the company's founders) is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click surveillance ...
that is designed to be covertly and remotely installed on
mobile phone
A mobile phone or cell phone is a portable telephone that allows users to make and receive calls over a radio frequency link while moving within a designated telephone service area, unlike fixed-location phones ( landline phones). This rad ...
s running
iOS
Ios, Io or Nio (, ; ; locally Nios, Νιός) is a Greek island in the Cyclades group in the Aegean Sea. Ios is a hilly island with cliffs down to the sea on most sides. It is situated halfway between Naxos and Santorini. It is about long an ...
and
Android.
While NSO Group markets Pegasus as a product for fighting crime and terrorism, governments around the world have routinely used the spyware to surveil journalists, lawyers, political dissidents, and human rights activists.
The sale of Pegasus licenses to foreign governments must be approved by the
Israeli Ministry of Defense.
As of September 2023, Pegasus operators were able to remotely install the spyware on iOS versions through
16.6 using a
zero-click exploit.
While the capabilities of Pegasus may vary over time due to software updates, Pegasus is generally capable of
reading text messages,
call snooping,
collecting passwords,
location tracking, accessing the target device's microphone and camera, and harvesting information from apps.
The spyware is named after
Pegasus, the winged horse of
Greek mythology
Greek mythology is the body of myths originally told by the Ancient Greece, ancient Greeks, and a genre of ancient Greek folklore, today absorbed alongside Roman mythology into the broader designation of classical mythology. These stories conc ...
.
Cyber watchdog
Citizen Lab and Lookout Security published the first public technical analyses of Pegasus in August 2016 after they captured the spyware in a failed attempt to spy on the
iPhone
The iPhone is a line of smartphones developed and marketed by Apple that run iOS, the company's own mobile operating system. The first-generation iPhone was announced by then–Apple CEO and co-founder Steve Jobs on January 9, 2007, at ...
of a
human rights activist.
Subsequent investigations into Pegasus by
Amnesty International
Amnesty International (also referred to as Amnesty or AI) is an international non-governmental organization focused on human rights, with its headquarters in the United Kingdom. The organization says that it has more than ten million members a ...
, Citizen Lab, and others have garnered significant media attention, including in July 2021 with the release of the
Pegasus Project investigation, which centered on a leaked list of 50,000 phone numbers reportedly selected for targeting by Pegasus customers.
Background
NSO Group developed its first iteration of Pegasus spyware in 2011.
The company states that it provides "authorized governments with technology that helps them combat terror and crime."
NSO Group has published sections of contracts which require customers to use its products only for criminal and national security investigations and has stated that it has an industry-leading approach to human rights.
Discovery
Pegasus' iOS exploitation was identified in August 2016.
Emirati human rights defender
Ahmed Mansoor received a text message promising "secrets" about torture happening in prisons in the United Arab Emirates by following a link. Mansoor sent the link to
Citizen Lab of the
University of Toronto
The University of Toronto (UToronto or U of T) is a public university, public research university whose main campus is located on the grounds that surround Queen's Park (Toronto), Queen's Park in Toronto, Ontario, Canada. It was founded by ...
, which investigated, with the collaboration of Lookout, finding that if Mansoor had followed the link it would have jailbroken his phone and implanted the spyware into it, in a form of
social engineering.
Citizen Lab and Lookout discovered that the link downloaded software to exploit three previously unknown and unpatched
zero-day vulnerabilities in
iOS
Ios, Io or Nio (, ; ; locally Nios, Νιός) is a Greek island in the Cyclades group in the Aegean Sea. Ios is a hilly island with cliffs down to the sea on most sides. It is situated halfway between Naxos and Santorini. It is about long an ...
.
According to their analysis, the software can
jailbreak an
iPhone
The iPhone is a line of smartphones developed and marketed by Apple that run iOS, the company's own mobile operating system. The first-generation iPhone was announced by then–Apple CEO and co-founder Steve Jobs on January 9, 2007, at ...
when a malicious
URL
A uniform resource locator (URL), colloquially known as an address on the Web, is a reference to a resource that specifies its location on a computer network and a mechanism for retrieving it. A URL is a specific type of Uniform Resource Identi ...
is opened. The software installs itself and collects all communications and locations of targeted iPhones. The software can also collect
Wi-Fi
Wi-Fi () is a family of wireless network protocols based on the IEEE 802.11 family of standards, which are commonly used for Wireless LAN, local area networking of devices and Internet access, allowing nearby digital devices to exchange data by ...
passwords.
The researchers noticed that the software's code referenced an NSO Group product called "Pegasus" in leaked marketing materials.
Pegasus had previously come to light in a leak of records from
Hacking Team, which indicated the software had been supplied to the government of Panama in 2015.
Citizen Lab and Lookout notified
Apple
An apple is a round, edible fruit produced by an apple tree (''Malus'' spp.). Fruit trees of the orchard or domestic apple (''Malus domestica''), the most widely grown in the genus, are agriculture, cultivated worldwide. The tree originated ...
's security team, which patched the flaws within ten days and released an update for iOS.
A patch for
macOS
macOS, previously OS X and originally Mac OS X, is a Unix, Unix-based operating system developed and marketed by Apple Inc., Apple since 2001. It is the current operating system for Apple's Mac (computer), Mac computers. With ...
was released six days later.
Regarding how widespread the issue was, Lookout explained in a blog post: "We believe that this spyware has been in the wild for a significant amount of time based on some of the indicators within the code" and pointed out that the code shows signs of a "kernel mapping table that has values all the way back to
iOS 7
iOS 7 is the seventh major release of the iOS mobile operating system developed by Apple Inc., being the successor to iOS 6. It was announced at the company's Worldwide Developers Conference on June 10, 2013, and was released on September 18 ...
" (released 2013).
''
The New York Times
''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
'' and ''
The Times of Israel
''The Times of Israel'' (ToI) is an Israeli multi-language online newspaper that was launched in 2012 and has since become the largest English-language Jewish and Israeli news source by audience size. It was co-founded by Israeli journalist Dav ...
'' both reported that it appeared that the
United Arab Emirates
The United Arab Emirates (UAE), or simply the Emirates, is a country in West Asia, in the Middle East, at the eastern end of the Arabian Peninsula. It is a Federal monarchy, federal elective monarchy made up of Emirates of the United Arab E ...
was using this spyware as early as 2013.
It was used in Panama by former president
Ricardo Martinelli
Ricardo Alberto Martinelli Berrocal (born 11 March 1951) is a Panamanian politician and businessman who served as the 36th President of Panama from 2009 to 2014.
In 2024, Martinelli was sentenced to ten years in prison for embezzlement of pu ...
from 2012 to 2014, who established the ''Consejo de Seguridad Pública y Defensa'' Nacional (National Security Council) for its use.
Chronology
Several lawsuits outstanding in 2018 claimed that NSO Group helped clients operate the software and therefore participated in numerous violations of human rights initiated by its clients.
Two months after the murder and dismemberment of ''
The Washington Post
''The Washington Post'', locally known as ''The'' ''Post'' and, informally, ''WaPo'' or ''WP'', is an American daily newspaper published in Washington, D.C., the national capital. It is the most widely circulated newspaper in the Washington m ...
'' journalist
Jamal Khashoggi
Jamal Ahmad Hamza Khashoggi (13 October 1958 – 2 October 2018) was a Saudi journalist, Saudi dissidents, dissident, author, columnist for ''Middle East Eye'' and ''The Washington Post'', and a general manager and editor-in-chief of Al-Arab New ...
, a Saudi human rights activist, in the Saudi Arabian Consulate in
Istanbul, Turkey
Istanbul is the largest city in Turkey, constituting the country's economic, cultural, and historical heart. With a population over , it is home to 18% of the population of Turkey. Istanbul is among the largest cities in Europe and in th ...
, Saudi dissident
Omar Abdulaziz, a Canadian resident, filed suit in Israel against NSO Group, accusing the firm of providing the Saudi government with the surveillance software to spy on him and his friends, including Khashoggi.
In February 2024, a US court ordered NSO Group to hand over the code for Pegasus to
WhatsApp
WhatsApp (officially WhatsApp Messenger) is an American social media, instant messaging (IM), and voice-over-IP (VoIP) service owned by technology conglomerate Meta. It allows users to send text, voice messages and video messages, make vo ...
as part of an ongoing lawsuit filed by the
Meta Platforms
Meta Platforms, Inc. is an American multinational technology company headquartered in Menlo Park, California. Meta owns and operates several prominent social media platforms and communication services, including Facebook, Instagram, Threads ...
-owned communication app related to the alleged use of Pegasus against WhatsApp users.
In September 2024, Apple announced its intention to drop its court appeal against NSO. The company argued that the most critical files about the spyware tool might never be disclosed, while Apple's own disclosures could aid NSO and similar companies. Another reason cited was a US ban on doing business with NSO, and a perceived boost to Apple's threat detection technologies in the three years since the claim was first filed.
In December 2024, a US court ruled that NSO Group was liable for hacking 1,400 WhatsApp users' devices through Pegasus. The judge determined the NSO Group violated the
Computer Fraud and Abuse Act,
California Comprehensive Computer Data Access and Fraud Act, and WhatsApp's terms of service.
Technical details
The spyware can be installed on devices running certain versions of
iOS
Ios, Io or Nio (, ; ; locally Nios, Νιός) is a Greek island in the Cyclades group in the Aegean Sea. Ios is a hilly island with cliffs down to the sea on most sides. It is situated halfway between Naxos and Santorini. It is about long an ...
—Apple's mobile operating system—as well as some Android devices.
Rather than being a specific exploit, Pegasus is a suite of exploits that uses many vulnerabilities in the system. Infection vectors include clicking links, the
Photos app, the
Apple Music app, and
iMessage
iMessage is an instant messaging service developed by Apple Inc. and launched in 2011. iMessage functions exclusively on Apple platforms – including iOS, iPadOS, macOS, watchOS, and visionOS – as part of Apple ecosystem, Apple's approach t ...
. Some of the exploits Pegasus uses are
zero-click — that is, they can run without any interaction from the victim. Once installed, Pegasus has been reported to be able to run arbitrary code, extract contacts, call logs, messages, photos, web browsing history, settings,
as well as gather information from apps including but not limited to communications apps
iMessage
iMessage is an instant messaging service developed by Apple Inc. and launched in 2011. iMessage functions exclusively on Apple platforms – including iOS, iPadOS, macOS, watchOS, and visionOS – as part of Apple ecosystem, Apple's approach t ...
,
Gmail
Gmail is the email service provided by Google. it had 1.5 billion active user (computing), users worldwide, making it the largest email service in the world. It also provides a webmail interface, accessible through a web browser, and is also ...
,
Viber,
Facebook
Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
,
WhatsApp
WhatsApp (officially WhatsApp Messenger) is an American social media, instant messaging (IM), and voice-over-IP (VoIP) service owned by technology conglomerate Meta. It allows users to send text, voice messages and video messages, make vo ...
,
Telegram
Telegraphy is the long-distance transmission of messages where the sender uses symbolic codes, known to the recipient, rather than a physical exchange of an object bearing the message. Thus flag semaphore is a method of telegraphy, whereas pi ...
, and
Skype
Skype () was a proprietary telecommunications application operated by Skype Technologies, a division of Microsoft, best known for IP-based videotelephony, videoconferencing and voice calls. It also had instant messaging, file transfer, ...
.
In April 2017, after a Lookout report, Google researchers discovered
Android malware "believed to be created by NSO Group Technologies" and named it
Chrysaor (Pegasus' brother in
Greek mythology
Greek mythology is the body of myths originally told by the Ancient Greece, ancient Greeks, and a genre of ancient Greek folklore, today absorbed alongside Roman mythology into the broader designation of classical mythology. These stories conc ...
). According to Google, "Chrysaor is believed to be related to the Pegasus spyware". At the 2017 Security Analyst Summit held by
Kaspersky Lab
Kaspersky Lab (; ) is a Russian multinational cybersecurity and anti-virus provider headquartered in Moscow, Russia, and operated by a holding company in the United Kingdom. It was founded in 1997 by Eugene Kaspersky, Natalya Kaspersky a ...
, researchers revealed that Pegasus was available for Android in addition to iOS. Its functionality is similar to the iOS version, but the mode of attack is different. The Android version tries to gain
root access (similar to jailbreaking in iOS); if it fails, it asks the user for permissions that enable it to harvest at least some data. At the time Google said that only a few Android devices had been infected.
Pegasus hides itself as far as is possible and self-destructs in an attempt to eliminate evidence if unable to communicate with its command-and-control server for more than 60 days, or if on the wrong device. Pegasus can also self-destruct on command.
[ If it is not possible to compromise a target device by simpler means, Pegasus can be installed by setting up a wireless transceiver near a target device, or by gaining physical access to the device.]
Development of capabilities
The earliest version of Pegasus – which was identified in 2016 – relied on a spear-phishing attack which required the target to click a malicious link in a text message or email.
As of August 2016 – according to a former NSO employee – the U.S. version of Pegasus had 1-click capabilities for all phones apart from old Blackberry models which could be infiltrated with a 0-click attack.
In 2019, WhatsApp revealed Pegasus had employed a vulnerability in its app to launch zero-click attacks (the spyware would be installed onto a target's phone by calling the target phone; the spyware would be installed even if the call was not answered).
Since 2019, Pegasus has come to rely on iPhone iMessage vulnerabilities to deploy spyware.
By 2020, Pegasus shifted towards zero-click exploits and network-based attacks. These methods allowed clients to break into target phones without requiring user interaction.
Apple Inc
Apple Inc. is an American multinational corporation and technology company headquartered in Cupertino, California, in Silicon Valley. It is best known for its consumer electronics, software, and services. Founded in 1976 as Apple Computer ...
in a lawsuit against US-based cybersecurity startup, Corellium, alleged that it sold its virtualization
In computing, virtualization (abbreviated v12n) is a series of technologies that allows dividing of physical computing resources into a series of virtual machines, operating systems, processes or containers.
Virtualization began in the 1960s wit ...
technology to the NSO group and other such "bad actors" and actively encouraged them to find 0-day exploits.
Vulnerabilities
Lookout provided details of the three iOS vulnerabilities:
* CVE-2016-4655: Information leak in kernel – A kernel base mapping vulnerability that leaks information to the attacker allowing them to calculate the kernel's location in memory.
* CVE-2016-4656: Kernel memory corruption leads to jailbreak – 32 and 64 bit iOS kernel-level vulnerabilities that allow the attacker to secretly jailbreak the device and install surveillance software – details in reference.
* CVE-2016-4657: Memory corruption in the webkit – A vulnerability in the Safari WebKit that allows the attacker to compromise the device when the user clicks on a link.
Google's Project Zero documented another exploit, dubbed FORCEDENTRY
FORCEDENTRY, also capitalized as ForcedEntry, is a security exploit allegedly developed by NSO Group to deploy their Pegasus spyware. It enables the " zero-click" exploit that is prevalent in iOS 13 and below, but also compromises recent safegu ...
, in December 2021. According to Google's researchers, Pegasus sent an iMessage
iMessage is an instant messaging service developed by Apple Inc. and launched in 2011. iMessage functions exclusively on Apple platforms – including iOS, iPadOS, macOS, watchOS, and visionOS – as part of Apple ecosystem, Apple's approach t ...
to its targets that contained what appeared to be GIF
The Graphics Interchange Format (GIF; or , ) is a Raster graphics, bitmap Image file formats, image format that was developed by a team at the online services provider CompuServe led by American computer scientist Steve Wilhite and released ...
images, but which in fact contained a JBIG2 image. A vulnerability in the Xpdf implementation of JBIG2, re-used in Apple's iOS phone operating software, allowed Pegasus to construct an emulated computer architecture inside the JBIG2 stream which was then used to implement the zero-click attack. Apple fixed the vulnerability in iOS 14.8 in September 2021 as CVE-2021-30860.
As of July 2021, Pegasus likely uses many exploits, some not listed in the above CVEs.
Pegasus Anonymizing Transmission Network
Human rights group Amnesty International reported in the 2021 investigation that Pegasus employs a sophisticated command-and-control (C&C) infrastructure to deliver exploit payloads and send commands to Pegasus targets. There are at least four known iterations of the C&C infrastructure, dubbed the ''Pegasus Anonymizing Transmission Network'' (PATN) by NSO group, each encompassing up to 500 domain name
In the Internet, a domain name is a string that identifies a realm of administrative autonomy, authority, or control. Domain names are often used to identify services provided through the Internet, such as websites, email services, and more. ...
s, DNS servers, and other network infrastructure. The PATN reportedly utilizes techniques such as registering high port numbers for their online infrastructure as to avoid conventional internet scanning. PATN also uses up to three randomised subdomain
In the Domain Name System (DNS) hierarchy, a subdomain is a domain that is a part of another (main) domain. For example, if a domain offered an online store as part of their website it might use the subdomain.
Overview
The Domain Name System ...
s unique per exploit attempt as well as randomised URL
A uniform resource locator (URL), colloquially known as an address on the Web, is a reference to a resource that specifies its location on a computer network and a mechanism for retrieving it. A URL is a specific type of Uniform Resource Identi ...
paths.
Detecting Pegasus
Due to the covert nature of its installation, Pegasus was previously only able to be detected via digital forensics. On January 16, 2024, Kaspersky Labs announced in a press release a new method of detecting the spyware for iOS devices that involved inspecting the shutdown.log file, which logs reboot events, for indicators of compromise. Kaspersky developed a tool that extracts, analyzes, and parses the shutdown.log file to ease the process of locating the malicious signature. This method is only effective if the device is rebooted on the same day that it is infected with Pegasus.
Amnesty International released an open-source utility called Mobile Verification Toolkit that's designed to detect traces of Pegasus. The software runs on a personal computer and analyzes data including backup files exported from an iPhone or Android phone.
By country
Although Pegasus is stated as intended to be used against criminals and terrorists,[ it has also been used by both ]authoritarian
Authoritarianism is a political system characterized by the rejection of political plurality, the use of strong central power to preserve the political ''status quo'', and reductions in democracy, separation of powers, civil liberties, and ...
and democratic governments to spy on critics and opponents. A UN special rapporteur on freedom of opinion found that the use of the spyware by abusive governments could "facilitate extrajudicial, summary or arbitrary executions and killings, or enforced disappearance of persons."
Armenia
About twenty Armenian citizens were spied on via Pegasus spyware. Media expert Arthur Papyan said it targeted the key figures of the opposition and the government – current and past government employees who knew valuable state secrets and have political influence, including the former director of the National Security Service and current chairman of the center-right Homeland Party. The local experts suspected that they were targeted either by the government of Armenia or Azerbaijan, or perhaps both. Papyan said that NSO group appears to be jailbreaking a phone and provides interface for viewing the obtained data. Minister of high-tech industry Vahagn Khachaturyan also received a warning letter from Apple, he rejected the theory that the spying party could be the current Armenian government.
Azerbaijan
The list of spied-upon citizens included dozens of journalists and activists from Azerbaijan. It was alleged that their mobile phones were tapped. The head of Azerbaijani service of Radio Liberty/Radio Free Europe (Azadliq) Jamie Fly expressed his anger when it was revealed that the phones of his five current and former employees were tapped with Pegasus.
Bangladesh
Reports and investigations indicate Bangladesh is among 45 countries where Pegasus spyware infections were detected between 2016 and 2018, according to Citizen Lab's cybersecurity research. The spyware, developed by Israel's NSO Group, enables undetected access to smartphones' messages, cameras, and microphones.
Citizen Lab identified an operator codenamed **GANGES** using politically themed domains to target devices in Bangladesh, India, and Pakistan. During the 2018 elections, opposition figures reported phone intrusions consistent with Pegasus infections, though no direct government link was proven. The government denies purchasing or using Pegasus, calling allegations "baseless".
Bangladesh lacks comprehensive cybersecurity laws, relying on the ICT Act (2006) and Digital Security Act (2018), which prohibit unauthorized surveillance but remain inadequate against advanced spyware. Constitutional Article 43(B) and ICT Act Section 63 protect communication privacy, but enforcement gaps persist.
Israeli surveillance equipment reached Bangladeshi authorities through intermediaries despite no formal diplomatic ties. While Pegasus specifically remains unconfirmed in these transactions, the sales underscore Bangladesh's access to advanced monitoring tools.
Bahrain
Citizen Lab revealed the government of Bahrain used the NSO Group
NSO Group Technologies (NSO standing for Niv, Shalev and Omri, the names of the company's founders) is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click surveillance ...
's Pegasus to hack activists, bloggers, members of Waad (a secular Bahraini political society), a member of Al Wefaq (a Shiite Bahraini political society), and members of the Bahrain Center for Human Rights. Bahrain reportedly acquired access to spyware in 2017. As per the report, the mobile phones of a total of nine rights activists were "successfully hacked" between June 2020 and February 2021. Those hacked included three members of Waad, three of the BCHR, one of Al Wefaq, and two of the exiled dissidents who reside in London. The Citizen Lab attributed "with high confidence" that a Pegasus operator, LULU, was used by the Bahraini government to breach the phones of at least four of the nine activists.
In January 2022, Bahrain was accused of using the Pegasus spyware to hack a human rights defender, Ebtisam al-Saegh. The prominent activist's phone was hacked at least eight times between August and November 2019. As per the Citizen Lab, following the hacking attempt, al-Saegh faced incidents where she was harassed by the Bahrain authorities. It included being summoned to a police station, interrogation, rape threats, and physical and sexual assault. The attack left the rights defender in a state of "daily fear and terror".
In February 2022, an investigation by Citizen Lab and Amnesty International
Amnesty International (also referred to as Amnesty or AI) is an international non-governmental organization focused on human rights, with its headquarters in the United Kingdom. The organization says that it has more than ten million members a ...
revealed that the Pegasus spyware was used to infect the devices of a lawyer, an online journalist, and a mental health counsellor in Bahrain. All of the three activists were critical of the Bahraini authorities and were targeted with Pegasus between June and September 2021. One of the three activists remained anonymous, while the other two were Mohammed al-Tajer and Sharifa Swar (mental health counselor).
In December 2022, an exiled Bahraini activist, Yusuf al-Jamri filed a lawsuit against the Bahraini government and the NSO Group, alleging his phone was hacked using the Pegasus spyware in August 2019. The hacking was confirmed by the Citizen Lab researchers, who claimed that the servers that targeted al-Jamri were connected to Bahrain. Yusuf al-Jamri fled to the UK with his family in 2017, after facing multiple detentions, and episodes of interrogation, torture, sexual assault, and rape threats. Experts claimed that he was hacked days after posting tweets about Moosa Mohammed, the Bahraini activist who protested the executions in Bahrain and climbed to the roof of the country's embassy in London.
Djibouti
In 2018, the U.S. Central Intelligence Agency
The Central Intelligence Agency (CIA; ) is a civilian foreign intelligence service of the federal government of the United States tasked with advancing national security through collecting and analyzing intelligence from around the world and ...
purchased Pegasus for the Djibouti government to conduct counter-terrorism operations (despite Djibouti's poor human rights record).
Dominican Republic
In 2023, an investigation by Amnesty International
Amnesty International (also referred to as Amnesty or AI) is an international non-governmental organization focused on human rights, with its headquarters in the United Kingdom. The organization says that it has more than ten million members a ...
and Citizen Lab found that Nuria Piera, a Dominican Republic journalist known for her investigations into corruption in the country, was targeted by an unknown actor using Pegasus spyware at least three times between 2020 and 2021.
Egypt
Egyptian PM Mostafa Madbouly
Mostafa Kamal Madbouly (born 28 April 1966) is an Egyptian politician who serves as the 54th and current Prime Minister of Egypt. He was appointed by President Abdel Fattah el-Sisi to succeed Sherif Ismail following his government's resignation i ...
was selected for potential targeting by Pegasus – apparently by Saudi Arabia.
El Salvador
In January 2022, El Faro, a prominent Salvadoran news outlet, revealed that a majority of its staff had their phones infiltrated using Pegasus. The targeting was uncovered in an investigation conducted by Citizen Lab, and Access Now; the investigation revealed that the journalists of another 13 Salvadoran news organisations were targeted as well. Between July 2020 and November 2021, Pegasus was deployed on the phones of 22 employees of El Faro, including reporters, editors, and other staff. At the time of the targeting, El Faro was looking into governmental corruption scandals, and the government's clandestine dealings with the country's gangs. The Salvadoran government denied responsibility for the espionage, and NSO Group declined to reveal whether the Salvadoran government was a client.
Estonia
Estonia entered negotiations to procure Pegasus in 2018, and had made a $30 million down payment for the tool. Estonia hoped to use the tool against Russian phones (presumably for gathering intelligence). Israel initially approved the export of Pegasus to Estonia, but after a senior Russian defense official approached the Israeli defense agencies and revealed that Russia had learned of Estonia's intentions to obtain Pegasus, Israel decided to disallow Estonia from using Pegasus against any Russian phone number (following a heated debate among Israeli officials) so as to avoid damaging Israeli relations with Russia.
Estonia gained access to Pegasus spyware in 2019. Citizen Lab has uncovered that Estonia has deployed Pegasus outside its borders, against targets in "many" EU countries.
Finland
In January 2022 the Finnish Ministry for Foreign Affairs reported that several phones of Finnish diplomats had been infected with the Pegasus spyware. Antti Pelttari, the Director of the Finnish Security and Intelligence Service (Supo), stated that a Foreign Government was most likely behind the infection.
France
In July 2021, ''Le Monde
(; ) is a mass media in France, French daily afternoon list of newspapers in France, newspaper. It is the main publication of Le Monde Group and reported an average print circulation, circulation of 480,000 copies per issue in 2022, including ...
'' reported that President of France Emmanuel Macron and 14 French ministers were flagged as potential Pegasus targets for Pegasus spying by Morocco; Moroccan authorities denied Pegasus use and labelled the allegation as "unfounded and false" which a consortium of journalists and Amnesty International have demonstrated that there are "technical elements that prove listening".
Germany
Pegasus is in use by German Federal Criminal Police Office (BKA). BKA acquired Pegasus in 2019 with "utmost secrecy", despite hesitations from its legal council. The use of Pegasus by BKA was later revealed by German media. Sources from Germany's security services have told journalists that Germany's iteration of Pegasus spyware features built-in safeguards to prevent abuse and comply with EU privacy laws. However, officials have not publicly confirmed or elaborated on this.
In February 2023, the independent Russian journalist and Putin critic Galina Timchenko had her iPhone infected with Pegasus while located in Berlin.
Hungary
The government of Viktor Orbán
Viktor Mihály Orbán (; born 31 May 1963) is a Hungarian lawyer and politician who has been the 56th prime minister of Hungary since 2010, previously holding the office from 1998 to 2002. He has also led the Fidesz political party since 200 ...
authorized the use of Pegasus by Hungarian intelligence and law enforcement services to target the government's political opponents. The Orbán government has been accused of using it to spy on members of media as well as on Hungarian opposition. According to the findings released in July 2021, journalists and managers of media holdings appear to have been spied on by the Hungarian government with Pegasus. Phone numbers of at least 10 lawyers, at least 5 journalists, and an opposition politician were included on a leaked list of potential Pegasus surveillance targets.
In November 2021, Lajos Kósa, head of a parliamentary defense and law enforcement committee, was the first Hungarian senior official who acknowledged that the country's Interior Ministry purchased and used Pegasus. Kósa admitted that Hungary had indeed purchased and used Pegasus, stating "I don't see anything objectionable in it ..large tech companies carry out much broader monitoring of citizens than the Hungarian state does."
India
In late 2019, Facebook initiated a suit against NSO, claiming that Pegasus had been used to intercept the WhatsApp communications of a number of activists, journalists, and bureaucrats in India, leading to accusations that the Indian government was involved. 17 individuals including human rights activists, scholars, and journalists confirmed to an Indian publication they had been targeted.
Phone numbers of Indian ministers, opposition leaders, ex-election commissioners and journalists were allegedly found on a database of NSO hacking targets by Pegasus Project in 2021. Phone numbers of Koregaon Bhima activists who had compromising data implanted on their computers through a hack were found on a Pegasus surveillance phone number list.
Independent digital forensic analysis conducted on 10 Indian phones whose numbers were present in the data showed signs of either an attempted or successful Pegasus hack. The results of the forensic analysis threw up shows sequential correlations between the time and date a phone number is entered in the list and the beginning of surveillance. The gap usually ranges between a few minutes and a couple of hours.
Eleven phone numbers associated with a female employee of the Supreme Court of India
The Supreme Court of India is the supreme judiciary of India, judicial authority and the supreme court, highest court of the Republic of India. It is the final Appellate court, court of appeal for all civil and criminal cases in India. It also ...
and her immediate family, who accused the former Chief Justice of India, Ranjan Gogoi, of sexual harassment, were also allegedly found on a database indicating possibility of their phones being snooped.
Records also indicate that phone numbers of some of the key political players in Karnataka
Karnataka ( ) is a States and union territories of India, state in the southwestern region of India. It was Unification of Karnataka, formed as Mysore State on 1 November 1956, with the passage of the States Reorganisation Act, 1956, States Re ...
appear to have been selected around the time when an intense power struggle was taking place between the Bharatiya Janata Party and the Janata Dal (Secular)-Congress-led state government in 2019.
In October 2023, Apple
An apple is a round, edible fruit produced by an apple tree (''Malus'' spp.). Fruit trees of the orchard or domestic apple (''Malus domestica''), the most widely grown in the genus, are agriculture, cultivated worldwide. The tree originated ...
warned Indian journalists and opposition politicians that they may have been targets of state-sponsored attacks using Pegasus spyware. A Washington Post
''The Washington Post'', locally known as ''The'' ''Post'' and, informally, ''WaPo'' or ''WP'', is an American daily newspaper published in Washington, D.C., the national capital. It is the most widely circulated newspaper in the Washington m ...
investigation found that the Indian government officials pressured Apple to rescind the warnings. Apple instead sent out emails saying the warnings could have been a false alarm and asked media to mention the same in their articles, while government officials told media that it could have been an "algorithmic malfunction". Minister of Commerce Piyush Goyal said that the warnings were a "prank" by Apple. An advisor to the government, Sanjeev Sanyal, alleged that the warnings were part of a conspiracy involving Access Now, George Soros, Apple and opposition politicians to falsely accuse the government of hacking.
Iraq
The phone of Iraqi President Barham Salih was found on a list of potential Pegasus surveillance targets (however, actual targeting – attempted or successful – could not be determined). The targeting of Salih appeared to have been linked to Saudi Arabia and UAE.
Israel
Israeli police use
In January 2022, it was reported that Pegasus was unlawfully used by the Israeli Police to monitor citizens as well as foreign nationals who were accidentally or intentionally infected by the software. The surveillance was ordered by high-ranking police officers, and was carried out without warrants or judicial supervision. The legal basis for use of spyware against citizens is disputed. The police had allegedly targeted civilians not suspected of any crime, including organisers of antigovernmental protesters, mayors, anti-LGBT parade activists, employees of government-owned companies, an associate of a senior politician, and former government employees. In one case, it was alleged that police targeted an activist who was not suspected of a crime, allegedly to gather information about the activist's extra-marital affairs and use it as leverage.["Police targeted activist with NSO software, saved info on his sex life — report."](_blank)
''The Times of Israel
''The Times of Israel'' (ToI) is an Israeli multi-language online newspaper that was launched in 2012 and has since become the largest English-language Jewish and Israeli news source by audience size. It was co-founded by Israeli journalist Dav ...
'', January 20, 2022.
In some cases, Pegasus was used to obtain information unrelated to an ongoing investigation to be used later to pressure the subject of an investigation. In some cases, police used Pegasus to obtain incriminating information from suspects' devices, and then concealed the source of the incriminating information claiming it would expose intelligence assets. While the Israeli Police formally denied the allegations in the report, some senior police officials have hinted that the claims were true. The report led to the announcement of a number of parallel investigations into the police's conduct, with some officials demanding a Commission of inquiry.["'To form a Commission of inquiry to review the police and NSO affair. An internal probe will not be enough'"](_blank)
(Hebrew). '' Ynet'', January 21, 2022. Although the Attorney General
In most common law jurisdictions, the attorney general (: attorneys general) or attorney-general (AG or Atty.-Gen) is the main legal advisor to the government. In some jurisdictions, attorneys general also have executive responsibility for law enf ...
launched an internal probe into the allegations, the Privacy Protection Council (which advises the Minister of Justice), demanded that a state commission of inquiry be created.
On February 1, the police admitted that there was, in fact, misuse of the software. On February 7, the widespread extent of the warrantless surveillance was further revealed to have included politicians and government officials, heads of corporations, journalists, activists, and even Avner Netanyahu, the son of then-Prime Minister, Benjamin Netanyahu
Benjamin Netanyahu (born 21 October 1949) is an Israeli politician who has served as the prime minister of Israel since 2022, having previously held the office from 1996 to 1999 and from 2009 to 2021. Netanyahu is the longest-serving prime min ...
. This has led to renewed calls for a public inquiry, including from the current police commissioner Kobi Shabtai himself (appointed January 2021), as well as from the Minister of the Interior
An interior minister (sometimes called a minister of internal affairs or minister of home affairs) is a cabinet official position that is responsible for internal affairs, such as public security, civil registration and identification, emergency ...
, Ayelet Shaked and others.
Later in the day, the Minister of Public Security (the minister responsible for the police), Omer Bar-Lev
Omer Israel Bar-Lev (; born 2 October 1953) is an Israeli politician who formerly served as Ministry of Public Security (Israel), Minister of Public Security. He was previously a member of the Knesset for the Israeli Labor Party. He was placed se ...
, announced that he would be forming a commission of inquiry, to be chaired by a retired judge. Bar-Lev stressed that this commission will essentially be granted all the powers of a state commission (whose formation requires full cabinet support), including having the authority to subpoena witnesses, "regardless of seniority," whose testimony may be used in future prosecutions. Despite this, calls for a state commission persisted from several ex-ministry heads who were targeted. The next day, the State Comptroller Matanyahu Englman, calling the crisis a "trampling on the values of democracy and privacy," said that the investigation launched by his office will also be extensive, adding that it will not only include the police, but also the Ministry of Justice and the State Attorney's Office.
In September 2023, Apple
An apple is a round, edible fruit produced by an apple tree (''Malus'' spp.). Fruit trees of the orchard or domestic apple (''Malus domestica''), the most widely grown in the genus, are agriculture, cultivated worldwide. The tree originated ...
issued an emergency software patch after it was warned that Israel's NSO Group had injected its Pegasus spyware remotely and surreptitiously on to iPhones and iPads.
Jordan
Between August 2019 and December 2021, Apple phones of four Jordanian human rights activists, lawyers and journalists were hacked by a NSO government client (apparently Jordanian government agencies). The Jordanian government denied involvement.
In January 2022, it was revealed that Jordanian lawyer and activist Hala Ahed Deeb's phone was targeted with Pegasus.
In February 2024,
report
released by the digital rights group Access Now revealed that the phones of more than 30 people in Jordan, including journalists, lawyers and activists, had their phones infected with Pegasus between 2020 and 2023.
Kazakhstan
Activists in Kazakhstan
Kazakhstan, officially the Republic of Kazakhstan, is a landlocked country primarily in Central Asia, with a European Kazakhstan, small portion in Eastern Europe. It borders Russia to the Kazakhstan–Russia border, north and west, China to th ...
were targeted, in addition to top-level officials, like Kassym-Jomart Tokayev
Kassym-Jomart Kemeluly Tokayev (born 17 May 1953) is a Kazakhstani politician and diplomat who has served as the second president of Kazakhstan since 2019. He previously served as Prime Minister of Kazakhstan, Prime Minister from 1999 to 2002 ...
, Askar Mamin and Bakytzhan Sagintayev. Among the 2000 targeted Kazak numbers were government critic Bakhytzhan Toregozhina, as well as journalists Serikzhan Mauletbay and Bigeldy Gabdullin. Most of these victims were involved in a civic youth movement Oyan, Qazaqstan.
Latvia
Citizen Lab first noted the use of Pegasus in Latvia in 2018; Citizen Lab believes Pegasus is still being used by Latvia as of 2023.
In February 2023, the iPhone of Galina Timchenko, Russian journalist and co-founder of the Latvia-based Russian news publication ''Meduza
''Meduza'' (Russian: Медуза, named after the Greek goddess Medusa) is a Russian- and English-language independent news website, headquartered in Riga, Latvia. It was founded in 2014 by a group of former employees of the then-independent ...
'', was infected with Pegasus. Timchenko received a notification about a state-sponsored attack against her device from Apple, with experts from Citizen Lab and Access Now subsequently confirming that the device had indeed been compromised with Pegasus, with the attacker having gained full access to the device. The attack occurred the day before a conference of exiled independent Russian media in Berlin which Timchenko attended; her phone could have been used to evesdrop on the journalists' conversations during the conference. This attack is the first confirmed instance of Pegasus being used against a Russian journalist. It is unclear which state carried out the attack: a European intelligence agency have also sought to surveil prominent Russian expatriates, and while NSO Group does not export Pegasus to Russia, a third country could also have carried out the attack on Russia's behest. Timchenko was in Germany during the attack but had a phone with a Latvian sim card.
''The Guardian
''The Guardian'' is a British daily newspaper. It was founded in Manchester in 1821 as ''The Manchester Guardian'' and changed its name in 1959, followed by a move to London. Along with its sister paper, ''The Guardian Weekly'', ''The Guardi ...
'' subsequently ascertained that three other Russian expatriate journalists with Latvian phone numbers also received notifications about state-sponsor attacks against their devices from Apple (as well as one additional Russian journalist with a non-Latvian phone number).
Mexico
According to the ''New York Times'', Mexico has been "the first and most prolific user of Pegasus". Mexico in 2011 became the first country to purchase Pegasus, seeing it as a novel tool in the country's struggle against drug cartels. Mexican authorities also sought to cultivate autonomous intelligence capabilities, having hitherto been highly reliant on the United States for intelligence gathering capabilities.
Early versions of Pegasus were used to surveil the phone of Joaquín Guzmán, known as El Chapo. In 2011, Mexican President Felipe Calderón
Felipe de Jesús Calderón Hinojosa (; born 18 August 1962) is a Mexican politician and lawyer who served as the 63rd president of Mexico from 2006 to 2012 and Secretary of Energy during the presidency of Vicente Fox between 2003 and 2004. ...
reportedly called NSO to thank the company for its role in Guzmán's capture.
Within years, authorities began to use Pegasus to target civil society (including human rights advocates, anti-corruption activists, and journalists). When a list of 50,000 phone numbers of potential Pegasus surveillance targets (selected by individual client governments) was leaked in 2021, a third of them were Mexican.
President Andrés Manuel López Obrador (who took office in 2018) had pledged to halt the use of the spyware by Mexican authorities, nonetheless, reports of use and abuse of Pegasus have continued throughout his presidency (including an opposition politician). After federal police and intelligence agency reforms by the Obrador government, the Mexican military became the sole Pegasus user in 2019. The Mexican armed forces have been a prolific user of Pegasus. The Mexican armed forces have taken on an ever more prominent role during Obrador's presidency, and may have grown into an independent power center capable of autonomously spying on civilian detractors and critics, with the government powerless to reign in its abuses. The military went so far as to target Alejandro Encinas, the country's under-secretary for human rights (and a close ally of President Obrador), a prominent critic of the military who was investigating human rights abuses committed by the Mexican military at the time of the targeting, as well as other government officials involved in this inquiry.
As of 2023, Mexico's spending on Pegasus had totaled over $60 million.
Targeting of scientists and health campaigners
In 2017, Citizen Lab researchers revealed that NSO exploit links may have been sent to Mexican scientists and public health campaigners. The targets supported measures to reduce childhood obesity, including Mexico's "Soda Tax."
2014 Iguala mass kidnapping
In July 2017, the international team assembled to investigate the 2014 Iguala mass kidnapping publicly complained they thought they were being surveilled by the Mexican government. They stated that the Mexican government used Pegasus to send them messages about funeral homes containing links which, when clicked, allowed the government to surreptitiously listen to the investigators. The Mexican government has repeatedly denied any unauthorized hacking.
In 2023, it was revealed that Mexican Army intelligence was using Pegasus to monitor Guerreros Unidos cartel members and police officials in the area at the time of the kidnapping, capturing a cartel boss and the police commander discussing where to take the students that night. The Army had soldiers on the streets and a local battalion had an informant embedded with the students. Intercepted communications days later revealed two suspects talking about releasing students, indicating they may still have been alive. Despite this, the military never shared any of this information with officials searching for the students, and there is no evidence to suggest they attempted a rescue.
Assassination of journalist Cecilio Pineda Birto
Cecilio Pineda Birto, a Mexican freelance journalist was assassinated by hitmen while resting in a hammock by a carwash. Brito had been reporting on the ties between local politicians and criminal organizations, and had received anonymous death threats during the weeks preceding the assassination; at about the same time, his phone number was selected as a possible target for Pegasus surveillance by a Mexican Pegasus client. Pegasus spyware may have been used to ascertain Brito's location to carry out the hit by geolocating his phone; the deployment of Pegasus on his phone, however, could not be confirmed as his phone disappeared from the scene of the murder.
Targeting of presidential candidate Obrador
In the run-up to the 2018 Mexican presidential election, dozens of close associates of the presidential candidate Andrés Manuel López Obrador (who was subsequently elected) were selected as potential targets. Potential targets included close family members, his cardiologist, and members of his personal and political inner circle. Recordings of Obrador's conversations with family and party colleagues were subsequently leaked to the public in an attempt to disrupt his electoral campaign.
Use by Mexican drug cartels
Pegasus has been used by drug cartels and cartel-entwined government actors to target and intimidate Mexican journalists.
Other
A widow of slain renowned Mexican journalist was a target of an attempted Pegasus attack 10 days after her husband was assassinated.
Morocco
In 2019, two Moroccan pro-democracy campaigners were notified by WhatsApp that their phones had been compromised with Pegasus.
In June 2020, an investigation by Amnesty International
Amnesty International (also referred to as Amnesty or AI) is an international non-governmental organization focused on human rights, with its headquarters in the United Kingdom. The organization says that it has more than ten million members a ...
alleged that Moroccan journalist Omar Radi was targeted by the Moroccan government using the Israeli spyware Pegasus. The rights group claimed that the journalist was targeted three times and spied on after his device was infected with an NSO tool. Meanwhile, Amnesty also claimed that the attack came after the NSO group updated their policy in September 2019.
In July 2021, it was revealed that the Moroccan PM Saad Eddine el-Othamani and Moroccan King Mohammed VI were selected for targeting – apparently by Moroccan state actors themselves.
According to revelations from July 2021, Morocco had targeted more than 6,000 Algerian phones, including those of politicians and high-ranking military officials, with the spyware. The Algerian government subsequently severed diplomatic relations with Morocco in August 2021, citing alleged Moroccan deployment of Pegasus against Algerian officials as one of the "hostile actions" that undergirded the decision.
Netherlands
The Netherlands is a suspected Pegasus user. Pegasus spyware was used to spy on Ridouan Taghi, a high-profile criminal. After the murder of the lawyer Derk Wiersum, the Dutch General Intelligence and Security Service (AIVD) was asked to help with the process of catching Ridouan Taghi.
Panama
President of Panama Ricardo Martinelli
Ricardo Alberto Martinelli Berrocal (born 11 March 1951) is a Panamanian politician and businessman who served as the 36th President of Panama from 2009 to 2014.
In 2024, Martinelli was sentenced to ten years in prison for embezzlement of pu ...
personally sought to obtain cyberespionage tools after his election in 2009. After a rebuff by the U.S. in 2009, Martinelli successfully sought such tools from Israeli vendors, expressing an interest in acquiring a tool capable of hacking into mobile phones in a 2010 private meeting with Israeli PM Netanyahu. In 2012, NSO systems were installed in Panama City. The equipment was subsequently widely used for illicit domestic and foreign spying, including for spying on political opponents, magistrates, union leaders, and business competitors, with Martinelli allegedly going so far as to order the surveillance of his mistress using Pegasus.
Palestine
The mobile phones of six Palestinian activists were hacked using Pegasus with some of the attacks reportedly occurring as far back as July 2020, according to a report from Front Line Defenders
Front Line Defenders, or The International Foundation for the Protection of Human Rights Defenders, is an Irish-based human rights organisation founded in Dublin, Republic of Ireland, Ireland in 2001 to protect those who work non-violently to uph ...
. Salah Hammouri, a French-Palestinian human rights defender and one of the six victims of the Pegasus attack, has filed a lawsuit against NSO in France, accusing the company of a privacy rights violation.
Poland
Pegasus licenses were agreed on between Benjamin Netanyahu
Benjamin Netanyahu (born 21 October 1949) is an Israeli politician who has served as the prime minister of Israel since 2022, having previously held the office from 1996 to 1999 and from 2009 to 2021. Netanyahu is the longest-serving prime min ...
and Beata Szydło in July 2017. Citizen Lab revealed that several members of political opposition groups in Poland
Poland, officially the Republic of Poland, is a country in Central Europe. It extends from the Baltic Sea in the north to the Sudetes and Carpathian Mountains in the south, bordered by Lithuania and Russia to the northeast, Belarus and Ukrai ...
were hacked by Pegasus spyware, raising alarming questions about the Polish government's use of the software. A lawyer representing Polish opposition groups and a prosecutor involved in a case against the ruling Law and Justice party were also compromised. A subsequent investigation by the prosecutor general's office revealed Pegasus was used against 578 people from 2017 to 2022, by three separate government agencies: the Central Anticorruption Bureau, the Military Counterintelligence Service and the Internal Security Agency.
In December 2021, Citizen Lab announced that Pegasus was used against lawyer Roman Giertych and prosecutor Ewa Wrzosek, both critical of the ruling Law and Justice
Law and Justice ( , PiS) is a Right-wing populism, right-wing populist and National conservatism, national-conservative List of political parties in Poland, political party in Poland. The party is a member of European Conservatives and Refo ...
(PiS) government, with Giertych's phone suffering 18 intrusions. 33 hacks to the phone of Krzysztof Brejza, a senator
A senate is a deliberative assembly, often the upper house or Legislative chamber, chamber of a bicameral legislature. The name comes from the Ancient Rome, ancient Roman Senate (Latin: ''Senatus''), so-called as an assembly of the senior ...
from the opposition Civic Platform
The Civic Platform (, PO)The party is officially the Civic Platform of the Republic of Poland (''Platforma Obywatelska Rzeczypospolitej Polskiej''). is a Centre-right politics, centre-right liberal conservative political party in Poland. Since ...
(PO) were uncovered, and confirmed by Amnesty International
Amnesty International (also referred to as Amnesty or AI) is an international non-governmental organization focused on human rights, with its headquarters in the United Kingdom. The organization says that it has more than ten million members a ...
. Leading to the 2019 European and Polish parliamentary elections, Brejza's text messages were stolen as he was leading the opposition parties' campaign. The texts were doctored by state-run media, notably TVP, and used in a smear campaign against the opposition. This prompted the Polish Senate to begin an inquiry into the deployment of the spyware.
On January 25, 2022, more victims were confirmed by Citizen Lab, including Michał Kołodziejczak of the agrarian movement Agrounia
The AGROunion (, AU) is a left-wing politics, left-wing agrarian socialism, agrarian socialist political movement in Poland formed by Michał Kołodziejczak. AGROunia criticizes the actions of current politicians in relation to the state of agric ...
, and Tomasz Szwejgiert, a journalist and alleged former associate of the CBA.
According to the Supreme Audit Office (NIK), 544 of its employees' devices were under surveillance over 7,300 times, some could be infected with Pegasus.
In January 2024, Poland's Sejm
The Sejm (), officially known as the Sejm of the Republic of Poland (), is the lower house of the bicameralism, bicameral parliament of Poland.
The Sejm has been the highest governing body of the Third Polish Republic since the Polish People' ...
, the lower house of its parliament, established a special commission to investigate the use of Pegasus by the PiS. Appearing in front of the commission in March 2024, former prime minister Jarosław Kaczyński testified that “use of Pegasus was in accordance with the law, there were no shortcomings, and in 99% it was used against criminals.”
On 31 January 2025, former justice minister Zbigniew Ziobro was arrested over allegations of the misuse of Pegasus spyware.
Rwanda
Political activists in Rwanda
Rwanda, officially the Republic of Rwanda, is a landlocked country in the Great Rift Valley of East Africa, where the African Great Lakes region and Southeast Africa converge. Located a few degrees south of the Equator, Rwanda is bordered by ...
have been targeted with Pegasus, including the daughter and the nephew of Paul Rusesabagina.
Saudi Arabia
In December 2020, it was reported that Saudi Arabia
Saudi Arabia, officially the Kingdom of Saudi Arabia (KSA), is a country in West Asia. Located in the centre of the Middle East, it covers the bulk of the Arabian Peninsula and has a land area of about , making it the List of Asian countries ...
and the United Arab Emirates
The United Arab Emirates (UAE), or simply the Emirates, is a country in West Asia, in the Middle East, at the eastern end of the Arabian Peninsula. It is a Federal monarchy, federal elective monarchy made up of Emirates of the United Arab E ...
deployed a zero-click iMessage Pegasus exploit against two London
London is the Capital city, capital and List of urban areas in the United Kingdom, largest city of both England and the United Kingdom, with a population of in . London metropolitan area, Its wider metropolitan area is the largest in Wester ...
-based reporters and 36 journalists at the ''Al Jazeera
Al Jazeera Media Network (AJMN; , ) is a private-media conglomerate headquartered in Wadi Al Sail, Doha, funded in part by the government of Qatar. The network's flagship channels include Al Jazeera Arabic and Al Jazeera English, which pro ...
'' television network in Qatar
Qatar, officially the State of Qatar, is a country in West Asia. It occupies the Geography of Qatar, Qatar Peninsula on the northeastern coast of the Arabian Peninsula in the Middle East; it shares Qatar–Saudi Arabia border, its sole land b ...
.
Jamal Khashoggi
Pegasus was used by Saudi Arabia to spy on Jamal Kashoggi, who was later assassinated in Turkey. In October 2018, Citizen Lab reported on the use of NSO software to spy on the inner circle of Jamal Khashoggi
Jamal Ahmad Hamza Khashoggi (13 October 1958 – 2 October 2018) was a Saudi journalist, Saudi dissidents, dissident, author, columnist for ''Middle East Eye'' and ''The Washington Post'', and a general manager and editor-in-chief of Al-Arab New ...
just before his murder. Citizen Lab's October report stated with high confidence that NSO's Pegasus had been placed on the iPhone of Saudi dissident Omar Abdulaziz, one of Khashoggi's confidantes, months before. Abdulaziz stated that the software revealed Khashoggi's "private criticisms of the Saudi royal family," which according to Abdulaziz "played a major role" in Khashoggi's death.[ Updated January 26]
In December 2018, a ''New York Times
''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
'' investigation concluded that Pegasus software played a role in the Khashoggi's murder, with a friend of Khashoggi stating in a filing that Saudi authorities had used the Israeli-made software to spy on the dissident. NSO CEO Shalev Hulio stated that the company had not been involved in the "terrible murder", but declined to comment on reports that he had personally traveled to the Saudi capital Riyadh
Riyadh is the capital and largest city of Saudi Arabia. It is also the capital of the Riyadh Province and the centre of the Riyadh Governorate. Located on the eastern bank of Wadi Hanifa, the current form of the metropolis largely emerged in th ...
for a $55 million Pegasus sale.
In 2021, allegations arose that the software may also have been used to spy on members of Kashoggi's family. The wife of Jamal Khashoggi, Hanan Elatr, intended to sue the NSO Group, alleging that she was targeted with Pegasus spyware. She also prepared a lawsuit in the US against the governments of Saudi Arabia and the United Arab Emirates for their involvement in the attempts to install the software on her mobile phone. Elatr was arrested in Dubai
Dubai (Help:IPA/English, /duːˈbaɪ/ Help:Pronunciation respelling key, ''doo-BYE''; Modern Standard Arabic, Modern Standard Arabic: ; Emirati Arabic, Emirati Arabic: , Romanization of Arabic, romanized: Help:IPA/English, /diˈbej/) is the Lis ...
in April 2018. Activity on Etatr's confiscated phone, while she was in the custody of UAE intelligence services, further suggested that an attempt was made to install the software at that time.
Targeting of Jeff Bezos
Pegasus was also used to spy on Jeff Bezos
Jeffrey Preston Bezos ( ;; and Robinson (2010), p. 7. ; born January 12, 1964) is an American businessman best known as the founder, executive chairman, and former president and CEO of Amazon, the world's largest e-commerce and clou ...
after Mohammed bin Salman
Mohammed bin Salman Al Saud (; born 31 August 1985), also known as MBS or MbS, is the ''de facto'' ruler of the Saudi Arabia, Kingdom of Saudi Arabia, formally serving as Crown Prince of Saudi Arabia, Crown Prince and Prime Minister of Sa ...
, the crown-prince of Saudi Arabia, exchanged messages with him that exploited then-unknown vulnerabilities in WhatsApp.
Targeting of journalist Ben Hubbard
Ben Hubbard, a Middle East
The Middle East (term originally coined in English language) is a geopolitical region encompassing the Arabian Peninsula, the Levant, Turkey, Egypt, Iran, and Iraq.
The term came into widespread usage by the United Kingdom and western Eur ...
correspondent for the ''New York Times'', revealed in October 2021 that Saudi Arabia used the NSO Group's Pegasus software to hack into his phone. Hubbard was targeted repeatedly over a three-year period between June 2018 to June 2021 while he was reporting on Saudi Arabia
Saudi Arabia, officially the Kingdom of Saudi Arabia (KSA), is a country in West Asia. Located in the centre of the Middle East, it covers the bulk of the Arabian Peninsula and has a land area of about , making it the List of Asian countries ...
, and writing a book about the Saudi Crown Prince Mohammed bin Salman
Mohammed bin Salman Al Saud (; born 31 August 1985), also known as MBS or MbS, is the ''de facto'' ruler of the Saudi Arabia, Kingdom of Saudi Arabia, formally serving as Crown Prince of Saudi Arabia, Crown Prince and Prime Minister of Sa ...
. Hubbard was possibly targeted for writing the book about the Crown Prince, and for his involvement in revealing the UAE's hacking and surveillance attempt of Project Raven. Saudis attempted to peek into Hubbard's personal information twice in 2018, one through a suspicious text message and the other through an Arabic WhatsApp
WhatsApp (officially WhatsApp Messenger) is an American social media, instant messaging (IM), and voice-over-IP (VoIP) service owned by technology conglomerate Meta. It allows users to send text, voice messages and video messages, make vo ...
message inviting him to a protest at a Saudi embassy in Washington.
Two other attacks were launched against him in 2020 and 2021 using the zero-click hacking capabilities. Lastly, on June 13, 2021, an iPhone belonging to Hubbard was successfully hacked using the FORCEDENTRY exploit. Citizen Lab said in "high confidence" that the four attacks were attempted using Pegasus.
Other targets
Another Saudi exile Omar Abdulaziz in Canada was identified by McKinsey & Company
McKinsey & Company (informally McKinsey or McK) is an American multinational strategy and management consulting firm that offers professional services to corporations, governments, and other organizations. Founded in 1926 by James O. McKinse ...
as being an influential dissident, and hence had two brothers imprisoned by the Saudi authorities, and his cell phone hacked by Pegasus.
In June 2018, a Saudi satirist, Ghanem Almasarir, was targeted by Saudi Arabia with Pegasus software. The targeting and hacking of Almasarir's phone by a network linked to Saudi Arabia was confirmed by researchers at the Citizen Lab. On 28 May 2019, the letter of claim was delivered to the Saudi embassy in London on behalf of Ghanem Almasarir. In August 2022, a British judge ruled that the prominent dissident in London
London is the Capital city, capital and List of urban areas in the United Kingdom, largest city of both England and the United Kingdom, with a population of in . London metropolitan area, Its wider metropolitan area is the largest in Wester ...
can sue Saudi Arabia for Pegasus hacking.
Slovakia
The Slovak Information Service (SIS) has acquired the Pegasus software under the fourth government of Prime Minister Robert Fico. Four anonymous sources from SIS have revealed to the daily newspaper Denník N that Pegasus has moved from testing phase to full operation in September 2024. The presence of "New systems that allow to hack into phones" has also been confirmed by the opposition politician and former chairman of the National Assembly Committee for Defence and Security Juraj Krúpa (SaS party) who warned that SIS had its powers expanded and can now spy on citizens without the need for court approval. The SIS has refused to either confirm or deny these accusations, citing state secrecy. The members of government denied the information of Denník N. Interior Minister Matúš Šutaj Eštok ( Voice – Social Democracy) said at today's press conference that he had no information about the purchase of the Pegasus system and questioned the veracity of the Denník N article.
South Africa
South African president Cyril Ramaphosa
Matamela Cyril Ramaphosa (born 17 November 1952) is a South African businessman and politician serving as the 5th and current President of South Africa since 2018. A former Anti-Apartheid Movement, anti-apartheid activist and trade union leade ...
was revealed to have been selected as a potential target of Pegasus surveillance, possibly by the Rwandan state.
Spain
Use against Catalan and Basque officials and independence proponents
According to an investigation by ''The Guardian'' and ''El País'', Pegasus software was used by the government of Spain
Spain, or the Kingdom of Spain, is a country in Southern Europe, Southern and Western Europe with territories in North Africa. Featuring the Punta de Tarifa, southernmost point of continental Europe, it is the largest country in Southern Eur ...
to compromise the phones of several politicians active in the Catalan independence movement, including President of the Parliament of Catalonia Roger Torrent, and former member of the Parliament of Catalonia
The Parliament of Catalonia (, ; ; ) is the Unicameralism, unicameral legislature of the Autonomous communities of Spain, autonomous community of Catalonia. The Parliament is currently made up of 135 members, known as Deputy (legislator), deput ...
Anna Gabriel i Sabaté.
The scandal resurfaced in April 2022 following the publication of a report of a CitizenLab investigation that revealed widespread use of Pegasus against Catalan politicians and citizens, as well as Basque politician Arnaldo Otegi
Arnaldo Otegi Mondragón (born 6 July 1958) is a politician from the Basque Country (greater region), Basque Country who has been the General Secretary of Basque nationalist party EH Bildu since 2017. He was member of the Basque Parliament for bo ...
and MP Jon Iñarritu. A total of 63 victims was identified, with targets including elected officials (including high-ranking ones) and civil society members (including activists, journalists, lawyers, and computer scientists). The true extent of the targeting was potentially far larger as Android devices are far more common in Spain while CitizenLab tools are specialised to uncover infiltration of Apple devices. Citizen Lab did not attribute the responsibility for the attacks to any perpetrators, but did note that circumstantial evidence strongly suggests the attacks were perpetrated by the Spanish Government. On May 5, 2022, the Spanish Defense Minister admitted to surveillance of 20 people involved in the Catalan independence movement.
Use against Spanish government officials
In May 2022, the Spanish Government revealed that the smartphones of Prime Minister Pedro Sánchez and Defense Minister Margarita Robles had been targeted by Pegasus in May 2021. Prime Minister Sanchez's device was infected twice, and Robles' device was infected once. A total of over 2.7GB of data was exfiltrated from the PM device, while only 9MB of data was extracted from the Defense Minister's device. The espionage is, as of today, denied yet attributed to Moroccan entities, given the diplomatic tensions between the two at the time of the target.
Thailand
According to a report by Citizen Lab and Digital Reach, at least 30 political activists and government critics from Thailand were affected by the spyware. A spokesperson for the Ministry of Digital Economy and Society
The Ministry of Digital Economy and Society (Abbreviation, Abrv: MDES; , ), formerly known as the Ministry of Information and Communication Technology (MICT), , is a List of government ministries of Thailand, cabinet ministry of Thailand. MICT wa ...
stated his ministry was not aware of any Pegasus usage by the government. A researcher from Citizen Lab has said that while 30 targets were confirmed definitively, they expect the actual number to be much higher.
Tibet
Senior advisers of the Dalai Lama
The Dalai Lama (, ; ) is the head of the Gelug school of Tibetan Buddhism. The term is part of the full title "Holiness Knowing Everything Vajradhara Dalai Lama" (圣 识一切 瓦齐尔达喇 达赖 喇嘛) given by Altan Khan, the first Shu ...
(who does not carry a personal phone himself), Tibet's president-in-exile, staff of a prominent Tibetan Buddhist spiritual leader Gyalwang Karmapa, as well as several other Tibetan activists and clerics – all of whom are living in exile in India – were selected for potential targeting by Pegasus, likely by the Indian government.
Togo
A joint investigation by ''The Guardian'' and ''Le Monde'' alleged that Pegasus software was used to spy on six critics of the government in Togo
Togo, officially the Togolese Republic, is a country in West Africa. It is bordered by Ghana to Ghana–Togo border, the west, Benin to Benin–Togo border, the east and Burkina Faso to Burkina Faso–Togo border, the north. It is one of the le ...
.
Uganda
It has been reported that Muhoozi Kainerugaba brokered a deal to use Pegasus in Uganda, paying between $10 and $20 million in 2019. The software was later used to hack the phones of 11 US diplomats and employees of the US embassy in Uganda some time during 2021.
Ukraine
At least since 2019, Ukraine had sought to obtain Pegasus in its effort to counter what it saw as an increasing threat of Russian aggression and espionage. However, Israel had imposed a near-total ban on weapons sales to Ukraine (which also encompassed cyberespionage tools), wary of selling Pegasus to states that would use the tool against Russia so as not to damage relations with Russia. In August 2021, at a time when Russian troops were amassing on the Ukrainian border, Israel again rebuffed a request from a Ukrainian delegation asking to obtain Pegasus; according to a Ukrainian official familiar with the matter, Pegasus could have provided critical support in Ukraine's effort to monitor Russian military activity. In the wake of the 2022 Russian invasion of Ukraine
On 24 February 2022, , starting the largest and deadliest war in Europe since World War II, in a major escalation of the Russo-Ukrainian War, conflict between the two countries which began in 2014. The fighting has caused hundreds of thou ...
, Ukrainian officials rebuked Israel's tepid support of Ukraine and Israeli efforts to maintain amicable relations with Russia.
United Arab Emirates
In December 2020, it was reported that Saudi Arabia
Saudi Arabia, officially the Kingdom of Saudi Arabia (KSA), is a country in West Asia. Located in the centre of the Middle East, it covers the bulk of the Arabian Peninsula and has a land area of about , making it the List of Asian countries ...
and the United Arab Emirates
The United Arab Emirates (UAE), or simply the Emirates, is a country in West Asia, in the Middle East, at the eastern end of the Arabian Peninsula. It is a Federal monarchy, federal elective monarchy made up of Emirates of the United Arab E ...
deployed a zero-click iMessage Pegasus exploit against two London
London is the Capital city, capital and List of urban areas in the United Kingdom, largest city of both England and the United Kingdom, with a population of in . London metropolitan area, Its wider metropolitan area is the largest in Wester ...
-based reporters and 36 journalists at the ''Al Jazeera
Al Jazeera Media Network (AJMN; , ) is a private-media conglomerate headquartered in Wadi Al Sail, Doha, funded in part by the government of Qatar. The network's flagship channels include Al Jazeera Arabic and Al Jazeera English, which pro ...
'' television network in Qatar
Qatar, officially the State of Qatar, is a country in West Asia. It occupies the Geography of Qatar, Qatar Peninsula on the northeastern coast of the Arabian Peninsula in the Middle East; it shares Qatar–Saudi Arabia border, its sole land b ...
.
Qatar reportedly attempted to hire Israeli-based cybersecurity firm Sdema Group for a "several dozen million-euro contract to provide physical and cyber-security services to Qatar's World Cup facilities.".
The United Arab Emirates used Pegasus to spy on the members of Saudi-backed Yemeni government according to an investigation published in July 2021. The UAE used the spyware to monitor and spy on the ministers of the internationally recognized government of President Abdrabbuh Mansur Hadi
Abdrabbuh Mansour Hadi (born 1 September 1945) is a Yemeni politician and former military officer who served as the second president of Yemen from 2012 until his resignation in 2022. He previously served as the second vice president of Yemen fro ...
, including Yemeni president and his family members, former Prime Minister Ahmed Obaid Bin Dagher
Ahmed Obaid Bin Dagher (; born 2 December 1952) is a Yemeni politician currently serving as chairman of Yemen's Shura Council since 17 January 2021. He was Prime Minister of Yemen from 4 April 2016 to 15 October 2018 as part of the internationa ...
, former Foreign Minister Abdulmalik Al-Mekhlafi, and current Minister of Youth and Sports, Nayef al-Bakri.
In August 2021, Amnesty International confirmed that David Haigh, a prominent British Human Rights lawyer and founder of Human Rights NGO Detained International, was the first British person to have evidence on his mobile phone that it had been hacked by NSO spyware. It is believed the illegal hacking was carried out in August 2020 by the government of Dubai
Dubai (Help:IPA/English, /duːˈbaɪ/ Help:Pronunciation respelling key, ''doo-BYE''; Modern Standard Arabic, Modern Standard Arabic: ; Emirati Arabic, Emirati Arabic: , Romanization of Arabic, romanized: Help:IPA/English, /diˈbej/) is the Lis ...
. At the time of the infection, David Haigh was the lawyer representing Dubai Princess Latifa bint Mohammed Al Maktoum who was being held hostage, and he was assisting Princess Haya bint Hussein and her legal team as well. Haigh had been exchanging videos and text messages in secret for more than a year and a half with Princess Latifa through a phone that had been smuggled into the Dubai villa where she was being held. She stopped responding on July 21, 2020, according to a screenshot of the messages Haigh shared. The analysis shows that Haigh's phone was hacked two weeks later.
On 24 September 2021, ''The Guardian
''The Guardian'' is a British daily newspaper. It was founded in Manchester in 1821 as ''The Manchester Guardian'' and changed its name in 1959, followed by a move to London. Along with its sister paper, ''The Guardian Weekly'', ''The Guardi ...
'' reported that the telephone of Alaa al-Siddiq, executive director of ALQST, who died in a car accident in London
London is the Capital city, capital and List of urban areas in the United Kingdom, largest city of both England and the United Kingdom, with a population of in . London metropolitan area, Its wider metropolitan area is the largest in Wester ...
on 20 June 2021, was infected with the Pegasus spyware for 5 years until 2020. Citizen Lab confirmed that the Emirati activist was hacked by a government client of Israel's NSO Group. The case represented a worrying trend for activists and dissidents, who escaped the UAE to live in the relative safety, but were never out of the reach of Pegasus.
In October 2021, the British High Court ruled that agents of Mohammed bin Rashid Al Maktoum
Sheikh Mohammed bin Rashid Al Maktoum (; born 15 July 1949) is an Emirati politician and royal who is the current ruler of Dubai, and serves as the Vice President of the United Arab Emirates, vice president and Prime Minister of the United Arab ...
used Pegasus to hack
Hack may refer to:
Arts, entertainment, and media Games
* Hack (Unix video game), ''Hack'' (Unix video game), a 1984 roguelike video game
* .hack (video game series), ''.hack'' (video game series), a series of video games by the multimedia fran ...
the phones of his (ex)-wife, Princess Haya bint Hussein, her solicitors (including baroness Fiona Shackleton), a personal assistant and two members of her security team in the summer of 2020. The court ruled that the agents acted "with the express or implied authority" of the sheikh; he denied knowledge of the hacking. The judgment referred to the hacking as "serial breaches of (UK) domestic criminal law", "in violation of fundamental common law and ECHR rights", "interference with the process of this court and the mother's access to justice" and "abuse of power" by a head of state. NSO had contacted an intermediary in August 2020 to inform Princess Haya of the hack and is believed to have terminated its contract with the UAE.
On 7 October 2021, the NSO Group
NSO Group Technologies (NSO standing for Niv, Shalev and Omri, the names of the company's founders) is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click surveillance ...
stated that it had terminated its contract with the UAE to use its Pegasus spyware tool after the ruling by UK's High Court that Dubai
Dubai (Help:IPA/English, /duːˈbaɪ/ Help:Pronunciation respelling key, ''doo-BYE''; Modern Standard Arabic, Modern Standard Arabic: ; Emirati Arabic, Emirati Arabic: , Romanization of Arabic, romanized: Help:IPA/English, /diˈbej/) is the Lis ...
's ruler misused the firm's Pegasus software to spy on his ex-wife and her legal advisers.
In 2022, sources revealed that a unit of Abu Dhabi's Mubadala Investment Company, Mubadala Capital was one of the largest investors in €1 billion Novalpina Capital private equity fund
A private equity fund (abbreviated as PE fund) is a collective investment scheme used for making investments in various equity (and to a lesser extent debt) securities according to one of the investment strategies associated with private equity.
...
, which bought the NSO Group in 2019. Since then, Mubadala has been an investor in the firm with its commitment of €50 million, acquiring a seat on the committee of largest investors of the equity fund. Journalists, human rights defenders and the women of Dubai's royal family were traced to have been hacked using the Pegasus spyware during the same time.
A report by the Citizen Lab revealed that Pegasus spyware linked to an Emirati operative was used to hack into the phones at the Downing Street
Downing Street is a gated street in City of Westminster, Westminster in London that houses the official residences and offices of the Prime Minister of the United Kingdom and the Chancellor of the Exchequer. In a cul-de-sac situated off Whiteh ...
and the Foreign Office. One of the spyware attack on No 10 was on 7 July 2020, which was asserted to have infected the phone of British Prime Minister Boris Johnson
Alexander Boris de Pfeffel Johnson (born 19 June 1964) is a British politician and writer who served as Prime Minister of the United Kingdom and Leader of the Conservative Party (UK), Leader of the Conservative Party from 2019 to 2022. He wa ...
. Besides, at least five attacks were identified on Foreign Office phones by UK allies, including the UAE, between July 2020 and June 2021. The UAE was also accused of hiring a firm to "monitor" Jeremy Corbyn
Jeremy Bernard Corbyn (; born 26 May 1949) is a British politician who has been Member of Parliament (United Kingdom), Member of Parliament (MP) for Islington North (UK Parliament constituency), Islington North since 1983. Now an Independent ...
.
United Kingdom (UK)
In April 2022, Citizen Lab released a report stating that 10 Downing Street
10 Downing Street in London is the official residence and office of the Prime Minister of the United Kingdom, prime minister of the United Kingdom. Colloquially known as Number 10, the building is located in Downing Street, off Whitehall in th ...
staff had been targeted by Pegasus, and that the United Arab Emirates
The United Arab Emirates (UAE), or simply the Emirates, is a country in West Asia, in the Middle East, at the eastern end of the Arabian Peninsula. It is a Federal monarchy, federal elective monarchy made up of Emirates of the United Arab E ...
was suspected of originating the attacks in 2020 and 2021.
United States (US)
NSO Group pitched its spyware to the Drug Enforcement Administration (DEA), which declined to purchase it due to its high cost.
In August 2016, NSO Group (through its U.S. subsidiary Westbridge) pitched its U.S. version of Pegasus to the San Diego Police Department (SDPD). In the marketing material, Westbridge emphasized that the company is U.S.-based and majority-owned by a U.S. parent company. An SDPD Sergeant responded to the sales pitch with "sounds awesome". The SDPD declined to purchase the spyware as it was too expensive.
In July 2021, it was revealed that the phone numbers of about a dozen U.S. citizens – including diplomats, journalists, aid workers, and dissident expatriates – were on a list of prospective targets for Pegasus infiltration, but it was not known whether an attack was ever attempted or completed against any of their devices. Among the phone numbers discovered on the list were those of the Obama administration's chief negotiator of the Joint Comprehensive Plan of Action
The Joint Comprehensive Plan of Action (JCPOA; (, BARJAM)), also known as the Iran nuclear deal or Iran deal, is an agreement to limit the Iranian nuclear program in return for sanctions relief and other provisions. The agreement was finalize ...
as well as those of several United Nations diplomats residing in the U.S. NSO Group has said that Pegasus is not deployed against any device located within the territory of the U.S., but it has been suggested that U.S. citizens can become targets when abroad.
In December 2021, it was reported that Pegasus spyware was found in the preceding months on the iPhones of at least nine U.S. State Department employees, all of whom were either stationed in Uganda or worked on matters related to Uganda. Later the same month, AP reported that a total of 11 U.S. State Department employees stationed in Uganda had their iPhones hacked with Pegasus. The US government blacklisted the NSO Group to stop what it called " transnational repression".
In January 2022, it was reported that the Federal Bureau of Investigation
The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
had secretly bought the Pegasus spyware in 2019 and had seen a demonstration of Phantom, a newer tool capable of targeting American phone numbers. The FBI went on to test both tools, and considered their use for domestic surveillance in the U.S., which reportedly led to discussions between the FBI and United States Department of Justice
The United States Department of Justice (DOJ), also known as the Justice Department, is a United States federal executive departments, federal executive department of the U.S. government that oversees the domestic enforcement of Law of the Unite ...
; ultimately the FBI decided against using NSO spyware. However, despite the 2021 decision rejecting use of NSO software, Pegasus equipment is still in the FBI's possession at a New Jersey facility. Responding to the reports, FBI officials played down the domestic surveillance aspect of the Pegasus testing, instead stressing counter-intelligence
Counterintelligence (counter-intelligence) or counterespionage (counter-espionage) is any activity aimed at protecting an agency's intelligence program from an opposition's intelligence service. It includes gathering information and conducting ac ...
as their purported main goal. A document later obtained by ''The New York Times
''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
'' clearly showed that the agency weighed using Pegasus and Phantom in domestic law enforcement cases.
L3Harris, a U.S. defense contractor, was in talks to acquire NSO Group, the maker of Pegasus. L3Harris reportedly had the backing of U.S. intelligence in undertaking the acquisition negotiations. After months of negotiations, the talks were scuttled after they were made known to the public by the news media in June 2022, with the U.S. government publicly rebuking the acquisition attempt.
In March 2023, President Joe Biden
Joseph Robinette Biden Jr. (born November 20, 1942) is an American politician who was the 46th president of the United States from 2021 to 2025. A member of the Democratic Party (United States), Democratic Party, he served as the 47th vice p ...
signed an executive order
In the United States, an executive order is a directive by the president of the United States that manages operations of the federal government. The legal or constitutional basis for executive orders has multiple sources. Article Two of the ...
that prohibited "operational use by the United States Government of commercial spyware that poses risks to national security or has been misused by foreign actors to enable human rights abuses around the world."
Yemen
The forensic analysis of UN independent investigator Kamel Jendoubi's mobile phone revealed on 20 December 2021 that he was targeted using spyware while probing war crimes of Yemen
Yemen, officially the Republic of Yemen, is a country in West Asia. Located in South Arabia, southern Arabia, it borders Saudi Arabia to Saudi Arabia–Yemen border, the north, Oman to Oman–Yemen border, the northeast, the south-eastern part ...
. Jendoubi was targeted while he was examining possible war crimes in Yemen. Jendoubi's mobile number was also found in the leaked database of the Pegasus Project. According to the data, Jendoubi was one of the potential targets of one of NSO Group's long-time clients, Saudi Arabia. However, NSO spokesperson denied Kamel Jendoubi as any of its client's targets.
International organizations
European Union
In April 2022, according to two EU officials and documentation obtained by Reuters, the European Justice Commissioner Didier Reynders
Didier Reynders (; born 6 August 1958) is a Belgian politician and a member of the Reformist Movement, Mouvement Réformateur (MR) that served as List of European Commissioners for Justice and Equality, European Commissioner for Justice until 30 ...
and other European Commission
The European Commission (EC) is the primary Executive (government), executive arm of the European Union (EU). It operates as a cabinet government, with a number of European Commissioner, members of the Commission (directorial system, informall ...
officials had been targeted by NSO's software. The commission learned of this after Apple notified thousands of iPhone users in November 2021 that they were targeted by state-sponsored hackers. According to the same two sources, IT experts examined some of the smartphones, but the results were inconclusive.
Pegasus Project
A leak of a list of more than 50,000 telephone numbers believed to have been identified as those of people of interest by clients of NSO since 2016 became available to Paris-based media nonprofit organisation Forbidden Stories and Amnesty International
Amnesty International (also referred to as Amnesty or AI) is an international non-governmental organization focused on human rights, with its headquarters in the United Kingdom. The organization says that it has more than ten million members a ...
. They shared the information with seventeen news media organisations in what has been called ''Pegasus Project'', and a months-long investigation was carried out, which reported from mid-July 2021. The Pegasus Project involved 80 journalists from the media partners including ''The Guardian
''The Guardian'' is a British daily newspaper. It was founded in Manchester in 1821 as ''The Manchester Guardian'' and changed its name in 1959, followed by a move to London. Along with its sister paper, ''The Guardian Weekly'', ''The Guardi ...
'' (UK), Radio France
Radio France () is the French national public radio broadcaster.
Stations
Radio France offers seven national networks:
*France Inter — Radio France's "generalist media, generalist" station, featuring entertaining and informative talk mixed wi ...
and ''Le Monde
(; ) is a mass media in France, French daily afternoon list of newspapers in France, newspaper. It is the main publication of Le Monde Group and reported an average print circulation, circulation of 480,000 copies per issue in 2022, including ...
'' (France), ''Die Zeit
(, ) is a German national weekly newspaper published in Hamburg in Germany. The newspaper is generally considered to be among the German newspapers of record and is known for its long and extensive articles.
History
The first edition of was ...
'' and ''Süddeutsche Zeitung
The ''Süddeutsche Zeitung'' (; ), published in Munich, Bavaria, is one of the largest and most influential daily newspapers in Germany. The tone of ''SZ'' is mainly described as centre-left, liberal, social-liberal, progressive-liberal, and ...
'' (Germany), ''The Washington Post
''The Washington Post'', locally known as ''The'' ''Post'' and, informally, ''WaPo'' or ''WP'', is an American daily newspaper published in Washington, D.C., the national capital. It is the most widely circulated newspaper in the Washington m ...
'' (United States), ''Haaretz
''Haaretz'' (; originally ''Ḥadshot Haaretz'' – , , ) is an List of newspapers in Israel, Israeli newspaper. It was founded in 1918, making it the longest running newspaper currently in print in Israel. The paper is published in Hebrew lan ...
'' (Israel), ''Aristegui Noticias'', ''Proceso'' (Mexico), the Organized Crime and Corruption Reporting Project, ''Knack'', ''Le Soir
''Le Soir'' (, ) is a French-language Belgian daily newspaper. Founded in 1887 by Émile Rossel, it was intended as a politically independent source of news. Together with '' La Libre Belgique'', it is one of the most popular Francophone newsp ...
'', ''The Wire'', ''Daraj'', Direkt36 (Hungary), and ''Frontline''. Evidence was found that many phones with numbers in the list had been targets of Pegasus spyware.[ However, The CEO of NSO Group categorically claimed that the list in question is unrelated to them, the source of the allegations can't be verified as reliable one. "This is an attempt to build something on a crazy lack of information... There is something fundamentally wrong with this investigation".
French intelligence ( ANSSI) confirmed that Pegasus spyware had been found on the phones of three journalists, including a journalist of ]France 24
France 24 ( in French) is a French state-owned publicly funded international news television network based in Paris. Its channels, broadcast in French, English, Arabic and Spanish, are aimed at the overseas market.
Based in the Paris suburb ...
, in what was the first time an independent and official authority corroborated the findings of the investigation.
On 26 January 2022, the reports revealed that mobile phones of Lama Fakih, a US-Lebanese citizen and director of crisis and conflict at Human Rights Watch
Human Rights Watch (HRW) is an international non-governmental organization that conducts research and advocacy on human rights. Headquartered in New York City, the group investigates and reports on issues including War crime, war crimes, crim ...
, were repeatedly hacked by a client of NSO Group at a time when she was investigating the 2020 Beirut explosion that killed more than 200 people.
In July 2021, a joint investigation conducted by seventeen media organisations, revealed that Pegasus spyware was used to target and spy on heads of state, activists, journalists, and dissidents, enabling "human rights violations around the world on a massive scale". The investigation was launched after a leak of 50,000 phone numbers of potential surveillance targets. Amnesty International
Amnesty International (also referred to as Amnesty or AI) is an international non-governmental organization focused on human rights, with its headquarters in the United Kingdom. The organization says that it has more than ten million members a ...
carried out forensic
Forensic science combines principles of law and science to investigate criminal activity. Through crime scene investigations and laboratory analysis, forensic scientists are able to link suspects to evidence. An example is determining the time and ...
analysis of mobile phones of potential targets. The investigation identified 11 countries as NSO clients: Azerbaijan, Bahrain, Hungary, India, Kazakhstan, Mexico, Morocco, Rwanda, Saudi Arabia, Togo, and the United Arab Emirates. The investigation also revealed that journalists from multiple media organizations including ''Al Jazeera
Al Jazeera Media Network (AJMN; , ) is a private-media conglomerate headquartered in Wadi Al Sail, Doha, funded in part by the government of Qatar. The network's flagship channels include Al Jazeera Arabic and Al Jazeera English, which pro ...
'', CNN, the ''Financial Times
The ''Financial Times'' (''FT'') is a British daily newspaper printed in broadsheet and also published digitally that focuses on business and economic Current affairs (news format), current affairs. Based in London, the paper is owned by a Jap ...
'', the Associated Press
The Associated Press (AP) is an American not-for-profit organization, not-for-profit news agency headquartered in New York City.
Founded in 1846, it operates as a cooperative, unincorporated association, and produces news reports that are dist ...
, ''The New York Times
''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
'', ''The Wall Street Journal
''The Wall Street Journal'' (''WSJ''), also referred to simply as the ''Journal,'' is an American newspaper based in New York City. The newspaper provides extensive coverage of news, especially business and finance. It operates on a subscriptio ...
'', ''Bloomberg News
Bloomberg News (originally Bloomberg Business News) is an international news agency headquartered in New York City and a division of Bloomberg L.P. Content produced by Bloomberg News is disseminated through Bloomberg Terminals, Bloomberg T ...
'' and ''Le Monde
(; ) is a mass media in France, French daily afternoon list of newspapers in France, newspaper. It is the main publication of Le Monde Group and reported an average print circulation, circulation of 480,000 copies per issue in 2022, including ...
'' were targeted, and identified at least 180 journalists from 20 countries who were selected for targeting with NSO spyware between 2016 and June 2021.
Reactions
NSO Group response
Responding to August 2016 reports of a targeting of an Arab activist, NSO Group stated that they provide "authorized governments with technology that helps them combat terror and crime", although the Group told him that they had no knowledge of any incidents.
In December 2024, a U.S. court held NSO Group
NSO Group Technologies (NSO standing for Niv, Shalev and Omri, the names of the company's founders) is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click surveillance ...
liable for attacks on approximately 1,400 WhatsApp
WhatsApp (officially WhatsApp Messenger) is an American social media, instant messaging (IM), and voice-over-IP (VoIP) service owned by technology conglomerate Meta. It allows users to send text, voice messages and video messages, make vo ...
users, including activists and journalists. The court ruled that NSO violated the Computer Fraud and Abuse Act and the California Comprehensive Computer Data Access and Fraud Act, dismissing the company's defense that it was not liable because Pegasus was operated by their clients.
Bug-bounty program skepticism
In the aftermath of the news, critics asserted that Apple's bug-bounty program, which rewards people for finding flaws in its software, might not have offered sufficient rewards to prevent exploits being sold on the black market
A black market is a Secrecy, clandestine Market (economics), market or series of transactions that has some aspect of illegality, or is not compliant with an institutional set of rules. If the rule defines the set of goods and services who ...
, rather than being reported back to Apple. Russell Brandom of ''The Verge
''The Verge'' is an American Technology journalism, technology news website headquarters, headquartered in Lower Manhattan, New York City and operated by Vox Media. The website publishes news, feature stories, guidebooks, product reviews, cons ...
'' commented that the reward offered in Apple's bug-bounty program maxes out at $200,000, "just a fraction of the millions that are regularly spent for iOS exploits on the black market". He goes on to ask why Apple doesn't "spend its way out of security vulnerabilities?", but also writes that "as soon as he Pegasusvulnerabilities were reported, Apple patched them—but there are plenty of other bugs left. While spyware companies see an exploit purchase as a one-time payout for years of access, Apple's bounty has to be paid out every time a new vulnerability pops up."
Brandom also wrote; "The same researchers participating in Apple's bug bounty could make more money selling the same finds to an exploit broker." He concluded the article by writing: "It's hard to say how much damage might have been caused if Mansoor had clicked on the spyware link... The hope is that, when the next researcher finds the next bug, that thought matters more than the money."
Complaints
WhatsApp
On 20 October 2019, Meta Platforms
Meta Platforms, Inc. is an American multinational technology company headquartered in Menlo Park, California. Meta owns and operates several prominent social media platforms and communication services, including Facebook, Instagram, Threads ...
Inc.’s WhatsApp filed a lawsuit against Israel's NSO Group for exploiting a bug in its WhatsApp messaging app to install spyware (Pegasus) that allowed the surveillance of 1400 people in 20 countries, including journalists, human rights activists, political dissidents and diplomats. WhatsApp said it was seeking a permanent demand to block NSO from using its service, and asked lawmakers to bar the use of cyberweapon
Cyberweapons are commonly defined as malware agents employed for military, paramilitary, or intelligence objectives as part of a cyberattack. This includes computer viruses, trojans, spyware, and worms that can introduce malicious code into ex ...
s like those NSO Group has sold to governments. On 9 January 2023, the Supreme Court of the United States
The Supreme Court of the United States (SCOTUS) is the highest court in the federal judiciary of the United States. It has ultimate appellate jurisdiction over all Federal tribunals in the United States, U.S. federal court cases, and over Stat ...
denied the appeal of NSO of the lower court's decision to continue the lawsuit and allowed WhatsApp to pursue its lawsuit against Israel's NSO Group.
On 7 May 2025, Meta Platforms
Meta Platforms, Inc. is an American multinational technology company headquartered in Menlo Park, California. Meta owns and operates several prominent social media platforms and communication services, including Facebook, Instagram, Threads ...
Inc. announced they won a lawsuit against NSO Group, receiving $167.3 million in punitive damages and $444,719 in compensatory damages.
Apple
On 23 November 2021, Apple
An apple is a round, edible fruit produced by an apple tree (''Malus'' spp.). Fruit trees of the orchard or domestic apple (''Malus domestica''), the most widely grown in the genus, are agriculture, cultivated worldwide. The tree originated ...
announced that it has filed a lawsuit against Israeli cyber company NSO Group and its parent company OSY Technologies for allegedly surveillance and targeting iPhone users with its Pegasus spyware. Apple stated that contrary to NSO's claim of targeting terrorists and criminals, this spyware has also been used against activists, politicians, and journalists. Apple's statement said the company is seeking a permanent injunction to bar NSO Group from using Apple's software, services, or devices to prevent further abuse and harm to users.
Reuses
In August 2024, security experts revealed code similar to NSO Pegasus were reused by Russia-linked agencies. They pointed out the uncontrolled proliferation of surveillance tools to authoritarian actors.
See also
* DROPOUTJEEP
* Hermit (spyware)
* IMSI-catcher
* List of spyware programs
* RCSAndroid from Hacking Team
* '' Surveilled''
Further reading
*
References
External links
*
*
*
*
*
*
*
{{Hacking in the 2010s
Hacking in the 2010s
Malware toolkits
Android (operating system) malware
IOS malware
Espionage scandals and incidents
Spyware
Spyware used by governments
Israeli inventions
Products introduced in 2016