How to Detect Pegasus Spyware

Pegasus spyware detection on iPhone and Android - RSI Security

Pegasus was once discussed primarily as a threat to journalists, dissidents, and government officials — the kind of surveillance tool most organizations assumed was someone else’s problem. That assumption has become harder to sustain. Recent threat-hunting scans discovered multiple new Pegasus spyware infections targeting journalists, government officials, and corporate executives across both iPhone and Android devices, demonstrating that the threat extends well into the corporate environment. Dark Reading

For organizations managing executive mobile security, sensitive data on personal and corporate devices, or high-value individuals in their workforce, Pegasus represents a specific category of mobile security threat that conventional antivirus and MDM programs weren’t designed to address.

What Pegasus Is

Pegasus is a military-grade surveillance tool developed by the Israeli company NSO Group, designed to secretly access mobile devices and allow operators to read messages, track location, record calls, and activate a phone’s microphone or camera. Panda Security

NSO Group markets Pegasus as a law enforcement tool for fighting crime and terrorism — licensed exclusively to government agencies. The documented reality is different: Pegasus has been found on the devices of journalists, lawyers, human rights activists, and corporate executives across dozens of countries, often without any legitimate law enforcement justification. The Citizen Lab at the University of Toronto has been the leading academic organization tracking Pegasus deployments globally since its initial discovery.

The legal consequences for NSO have accelerated. A U.S. court ruled NSO Group liable for hacking 1,400 WhatsApp users’ devices, and a jury ordered it to pay roughly $167 million in punitive damages alongside about $445,000 in compensatory damages, though the punitive amount was later reduced on appeal. NSO continues to face international pressure, export restrictions, and ongoing litigation from multiple technology companies. Group-IB

None of that legal pressure makes the spyware less technically capable or eliminates the risk to individuals whose devices may already be compromised.

How Pegasus Gets on Devices

Understanding Pegasus’s infection vectors is the first step toward meaningful protection — because the methods it uses are specifically designed to bypass the safeguards most users rely on.

Zero-click attacks are the most dangerous infection method and the one Pegasus is most associated with. Zero-click exploits don’t require any action from the device user to establish unauthorized access — they exploit zero-day vulnerabilities to gain entry without any interaction. A device can be compromised while sitting idle. No suspicious link needs to be clicked. No malicious app needs to be installed. Group-IB

One-click attacks via malicious links are more conventional but still effective. A victim receives a text message containing a link to a malicious website, which then exploits vulnerabilities in the browser and implants the spyware. In February 2025, two investigative journalists were targeted in a Pegasus attack — the attackers relied on a phishing link sent via the Viber messaging app, demonstrating that even the less sophisticated delivery methods remain in active use. Norton

Physical installation is uncommon but possible when an attacker has brief physical access to a device — typically a high-targeted surveillance scenario rather than a broad campaign.

What Pegasus Can Access

Once on a device, Pegasus provides extensive access. Operators can read messages, track location, record calls, and activate the phone’s microphone or camera — all without any visible indication to the device owner. The spyware can access text messages and encrypted messaging apps, emails, photos and videos, call recordings, location history, passwords stored on the device, and contact lists. Panda Security

For organizational security purposes, this means a compromised device belonging to an executive, attorney, or employee with access to sensitive systems creates significant data exposure — including the potential compromise of credentials that provide access to organizational infrastructure well beyond the device itself.

Why Standard Antivirus Doesn’t Solve This

Conventional antivirus solutions are largely ineffective against Pegasus. The reason is structural — Pegasus exploits zero-day vulnerabilities, meaning vulnerabilities that the device manufacturer and security software vendors don’t yet know exist. Signature-based detection, which is how most antivirus works, can only detect threats it has signatures for.

This is why detection requires specialized tools and methodologies rather than standard endpoint security.

How to Detect Pegasus Spyware

Two primary detection tools are available to individuals and organizations concerned about Pegasus infection.

Amnesty International’s Mobile Verification Toolkit (MVT) is the longest-established public resource for Pegasus detection. Developed through extensive forensic research, MVT allows users to scan device backups and forensic dumps for indicators of compromise — including domain names associated with Pegasus infrastructure, process names, and network artifacts linked to previous infections. MVT is available as an open-source tool on GitHub and supports both iOS and Android, though iOS coverage is more comprehensive.

Running MVT requires technical comfort — it’s a command-line tool, not a consumer app. For most individuals and many organizations, working with a qualified security professional to execute the scan and interpret results is more reliable than attempting a self-directed analysis.

iVerify is a mobile threat detection platform that has emerged as a more accessible detection option, particularly for organizational deployments. iVerify researchers discovered seven new Pegasus infections during a threat-hunting scan of 2,500 devices, targeting journalists, government officials, and corporate executives, demonstrating both the tool’s detection capability and the breadth of Pegasus targeting beyond traditional high-risk profiles. iVerify offers scanning for individuals and organizational fleet scanning for security teams managing device security at scale. Dark Reading

Detecting Pegasus on iOS

Create an encrypted backup of the device, then analyze the backup using MVT following Amnesty International’s published methodology. iVerify’s iOS app can also perform on-device scanning. Apple’s Lockdown Mode — available on iOS 16 and later — significantly reduces the attack surface for zero-click exploits by disabling the complex features Pegasus most commonly exploits, and is worth enabling for high-risk individuals.

Detecting Pegasus on Android

MVT can scan Android devices for malicious APKs and suspicious text messages that may indicate Pegasus activity. The forensic visibility on Android is generally more limited than on iOS due to platform architecture differences.

Behavioral Indicators to Watch For

Forensic tools provide the most reliable detection — but certain behavioral indicators may suggest spyware activity worth investigating:

  • Unusual battery drain outside of normal usage patterns
  • Unexpected data usage, particularly overnight or during periods of minimal active use
  • Device running warm when not in active use
  • Unexplained increases in cellular data consumption
  • Slower-than-normal device performance
  • Unfamiliar background processes or applications

None of these indicators alone confirms Pegasus infection — they have numerous innocent explanations. A combination of unusual behaviors on a high-risk device warrants forensic analysis.

What to Do If You Suspect Infection

If forensic analysis confirms or strongly suggests Pegasus infection, the remediation options are limited by the sophistication of the threat.

  1. Restart the device. Many Pegasus infections are non-persistent, meaning the active spyware agent runs in memory and doesn’t survive a reboot. Daily reboots don’t prevent re-infection but force the attacker to attempt a fresh compromise each time, increasing the likelihood of detection. This is recommended as an ongoing practice for high-risk individuals.
  2. Factory reset. This may remove the agent but is not guaranteed if the spyware has achieved deep system-level persistence. For confirmed cases, treat a factory reset as a starting point, not a certainty.
  3. Replace the device entirely. For confirmed high-risk targets — executives, journalists, legal professionals, government officials — the only reliable solution is discarding and replacing the compromised device. The new device should be activated from scratch, not restored from a backup of the potentially compromised device.
  4. Change all credentials. Immediately after moving to a new or reset device, change passwords for all accounts and sign out of those accounts on the compromised device. Assume any credentials entered on the device while infected may be known to the attacker.
  5. Enable iOS Lockdown Mode. If you use an iPhone and operate in a high-risk environment, Lockdown Mode significantly reduces the attack surface Pegasus exploits by disabling complex features — iMessage link previews, certain web technologies, and other capabilities Pegasus has historically targeted. It restricts functionality, but for the population most at risk, that trade-off is worth it.
  6. Contact your security team or a qualified mobile security specialist. For organizational incidents involving Pegasus on a corporate or executive device, this is not a DIY remediation. The forensic analysis, credential rotation, and organizational risk assessment that follow a confirmed Pegasus infection require professional support.

How Organizations Should Approach Mobile Spyware Risk

For most enterprise environments, Pegasus is a targeted threat — it’s expensive, state-grade surveillance technology that isn’t deployed indiscriminately. But the population of people who represent legitimate targets is broader than it once was. Corporate executives, legal counsel, healthcare leaders, financial sector professionals, defense contractors, and anyone handling sensitive government or commercial data may represent a credible target.

Organizations managing mobile device security for these populations should build a program that accounts for targeted spyware specifically, not just commodity mobile malware:

  • A formal mobile device security policy defining approved device configurations, app permissions, and update requirements
  • Routine device scanning using tools like iVerify for fleet-level detection — not just relying on individual users to self-report concerns
  • Clear escalation paths when a device is flagged as potentially compromised
  • Executive and high-value employee education on the behavioral indicators worth reporting
  • A device replacement protocol that defines when a device should be physically replaced rather than wiped and reused

Where RSI Security Fits

RSI Security helps organizations assess their mobile security posture, evaluate device management programs, and build governance frameworks that account for advanced mobile threats including targeted spyware.

We don’t provide Pegasus-specific forensic device analysis directly — the specialized tooling for that sits with Amnesty International’s MVT, iVerify, and dedicated mobile forensics practitioners. Our role is helping organizations build the security programs, policies, and governance structures that make devices harder to target, easier to monitor, and faster to respond to when incidents occur.

If your organization manages sensitive data on mobile devices and hasn’t evaluated your mobile security posture recently, schedule a security conversation or take the Cyber Risk Assessment to understand your current exposure.

Frequently Asked Questions

What is Pegasus spyware?
Pegasus is a military-grade surveillance tool developed by Israeli company NSO Group that secretly infects iOS and Android smartphones, allowing operators to read messages, track location, record calls, and activate the camera and microphone without the user’s knowledge. NSO Group markets Pegasus to government agencies for law enforcement purposes, but it has been documented on the devices of journalists, lawyers, human rights activists, and corporate executives in dozens of countries.
How does Pegasus get on a phone?
Pegasus uses two primary infection methods. Zero-click attacks exploit vulnerabilities in applications like iMessage or WhatsApp to install spyware without any action from the target — no link needs to be clicked. One-click attacks deliver a malicious link via SMS or messaging apps; clicking it triggers the installation. Zero-click attacks are more dangerous because the target has no way to avoid infection through behavioral caution alone.
How can I tell if my phone has Pegasus?
The most reliable detection methods are Amnesty International’s Mobile Verification Toolkit (MVT) and iVerify’s mobile threat scanning tool. Behavioral indicators — unusual battery drain, unexpected data usage, device running warm when idle — may suggest spyware activity but aren’t definitive on their own. Standard antivirus solutions generally cannot detect Pegasus because it exploits zero-day vulnerabilities unknown to security software vendors.
Can Pegasus be removed from a phone?
Not with certainty through software alone. Restarting the device interrupts non-persistent infections temporarily. A factory reset may remove the agent but isn’t guaranteed against deep-persistence variants. For confirmed high-risk targets, discarding and physically replacing the device is the only reliable remediation. All credentials should be rotated on a new, clean device regardless of which approach is taken.
Who is most at risk from Pegasus spyware?
Historically, Pegasus has targeted journalists, political dissidents, lawyers, and human rights activists. More recent documented cases include corporate executives, government officials, and financial sector professionals. The threat has expanded beyond its original profile — any individual with access to sensitive government, legal, financial, or commercial information may represent a credible target depending on who is operating Pegasus infrastructure against them.
Is NSO Group still operating?
Yes, though under significant legal and regulatory pressure. A U.S. court ruled NSO Group liable in December 2024 for hacking 1,400 WhatsApp users’ devices through Pegasus, and a jury ordered NSO to pay roughly $167 million in punitive damages alongside about $445,000 in compensatory damages in May 2025, though the punitive amount was later reduced on appeal. NSO continues to appeal and continues operating. The legal and regulatory environment around NSO has intensified, but Pegasus remains an active threat.

Version: 2.0 | Updated September 2026