Skip to content

Spyware

Pegasus

aka Q Suite · Trident (exploit chain)

Mercenary mobile spyware that uses zero-click exploits to fully compromise iOS and Android phones, repeatedly found targeting journalists and activists.

Pegasus is mercenary spyware developed by Israel's NSO Group and sold to government clients as "lawful intercept" tooling. Once installed it grants near-total access to a phone: messages (including end-to-end encrypted apps), calls, photos, location, and silent microphone/camera activation.

Zero-click compromise

Pegasus's most alarming capability is zero-click infection — exploit chains like FORCEDENTRY compromised iPhones with no user interaction, often via a single iMessage. It also employs aggressive anti-forensics to hide and self-remove.

Abuse and accountability

Investigations by Amnesty International, Citizen Lab and the Pegasus Project consortium documented its use against journalists, activists, lawyers and officials worldwide. Apple and WhatsApp have sued NSO. Notable cases are catalogued on Cyber Breaches; a zero-click exploit analysis lives on the Reverse Engineering Hub.

Defense

Patch promptly, enable iOS Lockdown Mode, reboot regularly, and seek forensic support for high-risk targets.