Pegasus
Pegasus is a sophisticated military-grade spyware developed by the Israeli cyber-intelligence company NSO Group. First identified around 2016, it is widely regarded as one of the most powerful and invasive surveillance tools ever documented in the public domain. Pegasus is capable of silently compromising smartphones — including both iOS and Android devices — granting operators complete access to calls, messages, emails, photos, location data, microphone, and camera, often without any interaction required from the target. Its deployment against journalists, human rights defenders, opposition politicians, and heads of state has made it a defining case study in the global weaponisation of surveillance technology and a critical reference point for researchers studying the Targeted Individual phenomenon, Cognitive Warfare, and the systematic dismantling of Cognitive Liberty.

Overview
Pegasus operates as what security researchers call a "zero-click" remote access trojan (RAT) — a tool that can invisibly infiltrate a device with no action required from its owner. Once installed, it effectively turns a smartphone into a listening and tracking device, transmitting data in real time to remote servers controlled by the operator. The implications extend far beyond individual privacy: Pegasus enables governments and agencies to monitor, predict, and suppress dissident activity at scale.
The existence of Pegasus and its widespread misuse was confirmed in 2021 through the Pegasus Project, a landmark investigation by a global consortium of journalists working with Amnesty International's Security Lab. The revelations demonstrated that the technology — ostensibly sold only to vetted government agencies for lawful counterterrorism purposes — had in practice been routinely turned against civil society, political opponents, and democratic institutions worldwide.
For researchers tracking the Targeted Individual Phenomenon, Pegasus provides documented, court-verified proof that covert, non-consensual surveillance of private individuals by state actors using advanced technical means is not theoretical — it is operational, globalised, and ongoing.
NSO Group Background
NSO Group Technologies was founded in 2010 in Herzliya, Israel, by Niv Carmi, Shalev Hulio, and Omri Lavie. The name "NSO" derives from the initials of its founders. The company positioned itself from the outset as a provider of "lawful intercept" technology — tools sold exclusively to government agencies and marketed as essential counterterrorism and law enforcement resources.
Israel's defence export regulatory framework — overseen by the Ministry of Defense — requires that NSO Group obtain government approval before selling Pegasus to any foreign client. This makes every Pegasus sale, in effect, an instrument of Israeli foreign policy as much as a commercial transaction.
Ownership and Investors
NSO Group's ownership history reveals deep connections to the global intelligence-financial complex:
- In 2014, US private equity firm Francisco Partners acquired a majority stake in NSO Group, valuing the company at approximately $130 million.
- Francisco Partners sold NSO Group back to its founders in 2019 for a reported $1 billion, with participation from the European private equity firm Novalpina Capital.
- NSO Group has repeatedly been linked, through various channels, to intelligence community investment networks. Although no direct investment by In-Q-Tel — the CIA's venture capital arm — in NSO Group has been confirmed, multiple In-Q-Tel-backed firms operate in adjacent markets and share overlapping technical ecosystems with NSO's capabilities.
- The company has employed numerous veterans of Unit 8200, the Israeli military's elite signals intelligence unit, widely regarded as one of the most technically advanced signals intelligence organisations in the world and a key partner within the broader Five Eyes-adjacent intelligence community.
NSO Group has maintained throughout its existence that it sells only to governments and that its tools are subject to rigorous human rights vetting. Documented evidence tells a different story.
Technical Capabilities
Pegasus represents the apex of commercial spyware engineering. Its capabilities, confirmed through forensic analysis by Citizen Lab, Amnesty International's Security Lab, and independent researchers, include:
- Full message interception: SMS, iMessage, WhatsApp, Signal, Telegram, and other encrypted messaging applications are all compromised at the device level, bypassing end-to-end encryption entirely.
- Call interception: Both standard cellular calls and VoIP calls through apps such as WhatsApp and FaceTime can be monitored in real time.
- Microphone activation: The microphone can be silently activated to record ambient audio without any indication to the user.
- Camera activation: Front and rear cameras can be activated remotely to capture images and video covertly.
- GPS and location tracking: Continuous real-time location data is transmitted to operator servers.
- Email and contact harvesting: Full email history, contacts, and calendar data are exfiltrated.
- Password extraction: Stored passwords and authentication tokens can be harvested from the device keychain.
- Persistent installation: Pegasus is engineered to survive device reboots and in some configurations can reinstall itself.
- Evidence removal: The spyware actively conceals its presence and can be remotely wiped from a device if discovery is imminent.
The combination of these capabilities means Pegasus does not merely surveil — it provides total situational awareness of the target's personal, professional, and political life.

Zero-Click Exploits
The most alarming technical feature of Pegasus is its exploitation of so-called "zero-click" vulnerabilities — security flaws that allow device compromise with zero user interaction. The target does not need to click a link, open an attachment, or respond to a message in any way.
Documented zero-click attack vectors include:
- iMessage exploit chains: Pegasus has exploited multiple undisclosed (zero-day) vulnerabilities in Apple's iMessage processing libraries, allowing infection via a specially crafted message that is silently processed and then deleted.
- WhatsApp buffer overflow (2019): A critical vulnerability in WhatsApp's VOIP stack allowed Pegasus to be installed by placing a missed call to the target's number — no answer required.
- FORCEDENTRY (2021): Perhaps the most sophisticated exploit ever documented in the commercial spyware space, FORCEDENTRY exploited an integer overflow vulnerability in Apple's CoreGraphics image rendering engine. A malicious PDF disguised as a GIF was silently processed, triggering full device compromise. Apple patched the vulnerability following Citizen Lab's disclosure and filed suit against NSO Group.
Zero-click exploits are extraordinarily valuable because they leave the target with no opportunity to detect or avoid the attack. From the perspective of covert surveillance operations, they are functionally equivalent to breaking into a property and planting a listening device — without ever entering the building.
Documented Targets
The Pegasus Project investigation and subsequent research by Citizen Lab have confirmed or credibly alleged Pegasus infections across an extraordinary range of targets:
Journalists and Media
- Reporters from outlets including Al Jazeera, the Financial Times, CNN, the New York Times, Le Monde, the Guardian, and the Indian Express.
- Associates and family members of Jamal Khashoggi, the Saudi journalist murdered inside the Saudi consulate in Istanbul in 2018. Forensic analysis confirmed Pegasus had been used to surveil members of Khashoggi's inner circle in the period before his death.
Human Rights Defenders and Activists
- Civil society activists in Mexico, Saudi Arabia, Bahrain, Azerbaijan, the United Arab Emirates, India, Rwanda, Morocco, and Hungary.
- Women's rights advocates in Saudi Arabia targeted by Saudi government clients.
Political Figures and Heads of State
- Emmanuel Macron (France), Charles Michel (European Council President), Cyril Ramaphosa (South Africa), and the Prime Ministers of Pakistan and Morocco appeared on leaked target lists.
- Opposition politicians and their legal counsel across multiple democracies.
Systematic Patterns
The data suggests Pegasus was not deployed primarily against terrorists or criminals — the ostensible justification for its sale — but systematically against political opposition, civil society organisations, and the free press.
The Pegasus Project Investigation
In July 2021, Forbidden Stories, a Paris-based nonprofit investigative journalism organisation, together with Amnesty International's Security Lab and a consortium of seventeen major media outlets, published findings from what became known as the Pegasus Project.
The investigation was based on analysis of a leaked list of over 50,000 phone numbers that NSO Group clients had selected for targeting. Key findings included:
- Forensic confirmation of Pegasus infections on dozens of devices belonging to journalists, activists, and politicians.
- Evidence that at least ten governments were actively using Pegasus to target individuals beyond any credible law enforcement justification: Azerbaijan, Bahrain, Hungary, India, Kazakhstan, Mexico, Morocco, Rwanda, Saudi Arabia, and the United Arab Emirates.
- Confirmation that Pegasus can completely bypass the encryption offered by Signal, WhatsApp, and other privacy-focused communications platforms.
- The Security Lab's publication of detailed technical indicators of compromise (IoCs), enabling individuals to check their own devices using the Mobile Verification Toolkit (MVT).
The Pegasus Project prompted emergency debates in the European Parliament, multiple national parliamentary inquiries, and a global reassessment of the lawfulness of commercial spyware markets.

Government Use and Misuse
NSO Group's stated policy is that Pegasus may only be used against "criminals and terrorists" and that it cannot be targeted against citizens of the purchasing country. Documented reality contradicts both claims:
- Mexico used Pegasus under multiple administrations to target journalists, anti-corruption investigators, and public health advocates campaigning against sugary drinks — individuals with no conceivable national security profile.
- Saudi Arabia used Pegasus against dissidents and journalists including individuals connected to Jamal Khashoggi.
- India reportedly targeted opposition figures, journalists, and constitutional court judges during electoral periods.
- Hungary — the only confirmed EU member state — used Pegasus to target investigative journalists and the close associates of opposition politicians.
- Rwanda reportedly targeted opposition figures who had fled the country and were living in exile.
These deployments reveal Pegasus functioning as a tool of political repression rather than legitimate law enforcement — a pattern consistent with the broader Information Warfare and Cognitive Warfare frameworks documented elsewhere in this wiki.
Legal and Regulatory Response
US Blacklisting
In November 2021, the United States Department of Commerce added NSO Group to its Entity List (commonly called the "blacklist"), finding that NSO Group had "acted contrary to the foreign policy and national security interests of the United States." US companies are prohibited from exporting technology to blacklisted entities without a licence.
Apple v. NSO Group
In November 2021, Apple Inc. filed suit against NSO Group in the Northern District of California, seeking a permanent injunction barring NSO from using Apple products and services. Apple simultaneously committed $10 million to cybersecurity research and began notifying users whose devices had been targeted by state-sponsored attackers.
EU Parliamentary Inquiry
The European Parliament established the PEGA Committee (Committee of Inquiry to Investigate the Use of Pegasus and Equivalent Surveillance Spyware) in 2022, which concluded that several EU member states had violated EU law through their deployment of Pegasus against political targets.
WhatsApp v. NSO Group
WhatsApp (Meta) filed suit against NSO Group in 2019, alleging that NSO had exploited the WhatsApp vulnerability to infect approximately 1,400 devices. The US Supreme Court declined NSO's appeal in 2024, allowing the case to proceed — a significant legal milestone in holding commercial spyware developers liable for downstream misuse.
Despite these actions, NSO Group continues to operate, and comparable tools from competing vendors — including Paragon Solutions, Candiru, and FinFisher — continue to be sold globally.
Implications for Targeted Individuals
The Pegasus revelations carry profound implications for the Targeted Individual community and for researchers investigating Electronic Harassment, Gang Stalking, and non-consensual covert surveillance:
Documented Proof of State-Level Covert Device Surveillance
Pegasus demonstrates beyond any reasonable doubt that governments routinely deploy covert, deniable surveillance technology against private individuals — without judicial oversight, without disclosure, and without the knowledge of the target. The experience of being comprehensively monitored without awareness — conversations captured, movements tracked, relationships mapped — closely mirrors accounts given by many Targeted Individuals.
The "Conspiracy Theory" Deflection
For decades, claims by individuals that their devices had been secretly compromised by state actors were dismissed as paranoid or delusional. Pegasus provides a forensically verified, judicially acknowledged precedent that such operations are real, technically feasible, and widespread. This has significant implications for how the psychiatric and legal establishment treats Targeted Individual accounts.
Convergence with Broader Surveillance Ecosystems
Pegasus does not operate in isolation. It exists within a globalised surveillance infrastructure that includes:
- NSA bulk collection programs revealed by Edward Snowden
- Five Eyes intelligence sharing agreements
- Stingray IMSI-catcher technology deployed by law enforcement
- Gotham and Palantir's data aggregation platforms
- In-Q-Tel-backed companies developing adjacent interception and analytics capabilities
- Corporate data brokers selling location and behavioural data to intelligence agencies
Within this ecosystem, Pegasus represents the targeted, individualised layer of a much larger architecture of mass and individual surveillance. The Targeted Individual Phenomenon may in some cases represent individuals who have intersected with or been selected by systems operating within this infrastructure.
Cognitive Liberty and Bodily Autonomy
The covert activation of a device's microphone and camera without consent is, in effect, an intrusion into the most intimate spaces of a person's life. Many researchers and legal scholars argue this constitutes a violation of Cognitive Liberty — the right to mental self-determination — and of principles of Bodily Autonomy as extended into the digital domain. When a device is used as a proxy body-sensor by a state actor, the boundary between physical and digital surveillance dissolves entirely.
See Also
- NSA
- CIA
- Five Eyes
- In-Q-Tel
- Targeted Individual
- Targeted Individuals
- Targeted Individual Phenomenon
- Electronic Harassment
- Gang Stalking
- Gangstalking
- Surveillance Technology
- Information Warfare
- Cognitive Warfare
- Cognitive Liberty
- Bodily Autonomy
- Stingray
- Gotham
- DARPA
- Project Paperclip
- COINTELPRO
- Full Spectrum Dominance
- Neuroweapons
- Social Credit System
- Digital Identity