← All articles

Total current articles · 210

Pegasus (Spyware)

Published

01In brief

Pegasus is a sophisticated mobile-surveillance tool developed by the Israeli technology company NSO Group, which was founded in 2010 and is based in Herzliya. It can infiltrate smartphones, extract communications and other stored data, track location, and remotely activate a device's camera and microphone. Pegasus was publicly identified in August 2016 after Emirati human-rights activist Ahmed Mansoor forwarded a suspicious message to researchers rather than opening its link, enabling them to identify the spyware and previously undisclosed iOS vulnerabilities. NSO says Pegasus is sold only to government agencies for counterterrorism and law-enforcement purposes and that the company does not operate it for customers. The 2021 Pegasus Project, conducted by 17 news organizations with Forbidden Stories and Amnesty International, examined a leaked list of approximately 50,000 phone numbers and linked numbers on it to more than 1,000 people in over 50 countries, including heads of state, journalists, human-rights activists, and government officials. Inclusion on the list did not by itself establish that a device had been infected. In November 2021, the U.S. Department of Commerce added NSO Group to its Entity List, restricting exports of covered American technology to the company. Litigation, government inquiries, and export-control debates have since made Pegasus a central case in controversies over commercial spyware.

02Overview

Pegasus sits at the intersection of national security, privacy, human rights, and the global trade in dual-use technology. NSO's product description presents it as a cyber-intelligence system for law-enforcement and intelligence agencies that covertly extracts information from mobile devices without cooperation from mobile-network operators or physical proximity to the target.[2]

The central dispute is whether a tool marketed for counterterrorism and serious-crime investigations has been used by purchasing governments against journalists, political dissidents, human-rights defenders, and other civilians. NSO cites client vetting and contractual restrictions, while investigative reporting and government proceedings have reported or alleged misuse.[1][8]

Israel's Defense Ministry has stated that Israeli cyber products are exported only to governmental entities for lawful use in preventing or investigating crime and terrorism.[1] A June 2022 policy paper submitted to members of the Knesset Foreign Affairs and Defense Committee said reports of Pegasus misuse continued to have international repercussions and placed the affair within a broader debate over privately developed surveillance technologies.[9]

03Origins and Public Identification

Pegasus was publicly identified in August 2016 after Emirati human-rights activist Ahmed Mansoor received a message promising information about prisoners allegedly being tortured in the United Arab Emirates. Instead of opening its link, Mansoor forwarded the message to Citizen Lab at the University of Toronto.[3]

Researchers from Lookout and Citizen Lab found that the link would have exploited a chain of previously undisclosed vulnerabilities in Apple's iOS 9.3.5 and installed Pegasus. Apple subsequently issued a security update. Researchers reported that the spyware could track calls and contacts, collect passwords, read messages and emails, record calls, and trace the user's location.[3]

Citizen Lab later identified suspected Pegasus infections in 45 countries. A Washington Institute report named Algeria, Bahrain, Iraq, the Palestinian territories, and Saudi Arabia among the locations and identified two Amnesty International employees and Saudi dissident Omar Abdulaziz as reported targets.[5] Abdulaziz alleged that information obtained through Pegasus contributed to Saudi authorities' decision to murder journalist Jamal Khashoggi, but the report said no direct public link between Pegasus and the murder had been verified.[5]

04Practice and Technical Capabilities

NSO's product description lists support for BlackBerry, Android, iOS, and Symbian devices.[2] It describes collection of SMS messages, email, calendars, call history, instant messages, contacts, browsing history, audio, photographs, screen captures, files, and location data. Active functions include intercepting voice calls, recording environmental sound, taking photographs and screenshots, retrieving files, and tracking GPS location.[2]

The document says data is normally sent to a command-and-control center. When connectivity is unavailable, a hidden encrypted buffer stores data locally, up to five percent of the device's free space. Transmission stops when battery charge falls below five percent.[2] These specifications are manufacturer claims rather than independent test results.

The product description also lists monitoring of Skype, WhatsApp, Viber, Facebook, and BlackBerry Messenger, with support for additional applications available in response to customer demand. Its analytical tools include geographic mapping, geofencing, alerts when two tracked targets share a location, connection alerts involving specified numbers, and content alerts triggered by defined terms.[2]

Installation methods described in the document include tailored SMS or email links, remote over-the-air installation without target action, network injection, and physical installation said to take less than five minutes.[2] Later versions were reported to use zero-click exploits requiring no action by the target.[10] Witnesses at a 2024 U.S. Senate hearing characterized commercial spyware of this kind as deeply intrusive and a threat to human rights, democracy, and U.S. national security.[8]

05The 2021 Pegasus Project Investigation

In July 2021, 17 news organizations working with Forbidden Stories and Amnesty International published findings drawn from a leaked list of approximately 50,000 phone numbers. The numbers were believed to have been selected by NSO clients for possible surveillance between 2016 and June 2021. Analysis linked numbers to more than 1,000 people in over 50 countries.[6]

The identified numbers included those of heads of state, prime ministers, Arab royal-family members, business executives, human-rights activists, journalists, politicians, and government officials. The investigation counted 189 journalists, 85 human-rights activists, and more than 600 politicians and government officials.[6] Governments linked to numbers in the data included Azerbaijan, Bahrain, Kazakhstan, Mexico, Morocco, Rwanda, Saudi Arabia, Hungary, India, and the United Arab Emirates.[6]

A separate report alleged that Morocco used Pegasus to target French politicians, including President Emmanuel Macron; the source presented this as an allegation rather than an established finding.[11] A 2024 Senate hearing cited reporting that at least 180 journalists were selected for potential targeting from 2016 through 2021 and distinguished potential targeting from confirmed infection.[8]

NSO denied that the leaked data constituted a list of Pegasus targets, rejected allegations of mass surveillance, and called the investigation a product of "wrong assumptions and uncorroborated theories."[6][4] The presence of a number on the list did not by itself establish that the corresponding phone had been infected.[6]

06NSO Group, Corporate Structure, and Israeli Export Controls

NSO Group was founded in 2010 and is based in Herzliya, Israel.[1] It describes its products as tools that allow governments to pursue criminals who evade authorities through encrypted communications. NSO has said it evaluates clients' human-rights records and governance, requires respect for privacy and freedom of expression, has blacklisted 55 countries, and has rejected more than $300 million in potential business.[1] It also reported reviewing 12 complaints in one year, one of which resulted in contract termination.[1]

In 2021, London-based private-equity firm Novalpina Capital controlled NSO's board and owned approximately two-thirds of its holding company, according to CAMERA UK.[4]

Israel's Defense Export Control Law of 2007 regulates defense equipment, software, services, and knowledge and generally requires authorization for defense exports.[9] Israel's Defense Export Controls Agency reportedly approved NSO's 2016 sale of Pegasus to an Arab company, and NSO has said its government sales require Defense Ministry approval.[12]

The 2022 policy paper submitted to Knesset committee members said the Defense Ministry had shortened the stated licensing period for offensive cyber tools from one year to four months and permitted some exemptions for specified products and destination countries.[9] It also criticized the law for not expressly addressing the human-rights consequences of offensive-cyber exports. The paper reported criticism by UN Special Rapporteur David Kaye of the stringency and transparency of Israel's export controls and of NSO's implementation of human-rights principles.[9]

The European Union revised its dual-use export-control framework in 2021. Regulation (EU) 2021/821, which entered into force in September, placed greater emphasis on human-rights risks and covered intrusion software, related development technology, and network-communications surveillance systems.[9]

08U.S. Government Response and FBI Acquisition

On November 3, 2021, the U.S. Department of Commerce added NSO Group and Candiru to the Entity List. The government said the companies had developed and supplied spyware to foreign governments that used it to maliciously target officials, journalists, businesspeople, activists, academics, and embassy workers.[7] A congressional document quoted the Commerce Department as describing such activity as enabling transnational repression.[10] The designation restricted exports, re-exports, and transfers of covered U.S. items to NSO and was based on conduct deemed contrary to U.S. national-security or foreign-policy interests.[7]

The FBI confirmed in February 2022 that it had purchased a limited Pegasus license in 2018 and tested the software for approximately two years at a secret facility in New Jersey.[10] Director Christopher Wray said the acquisition was for testing and evaluation, including assessment of security concerns and potential adversarial use. A 2018 FBI letter described a contemplated purpose of collecting mobile-device data to prevent and investigate crime and terrorism in compliance with privacy and national-security laws.[10]

The FBI stated that it never used Pegasus operationally or in support of an investigation.[10] Its purchase nevertheless became part of the congressional debate over U.S. policy toward commercial spyware.

09Documented Deployments and Reported Targets

A 2024 report said Access Now identified Pegasus infections on at least 30 phones belonging to journalists, lawyers, human-rights activists, and political activists in Jordan. The reported attacks occurred from early 2020 through November 2023.[15] NSO responded that it sells Pegasus only to vetted intelligence and law-enforcement agencies for use against terrorists and serious criminals.[15]

An essay in SAPIR Journal reported that traces of Pegasus had been detected on devices belonging to people in various organizations in the Palestinian territories, including organizations designated as terrorist organizations by the Israeli government.[16]

NSO has sold Pegasus to dozens of countries. Governments have presented its use as supporting investigations into terrorist networks, child-sex-abuse rings, and drug-trafficking leaders, while reports have described use against journalists, human-rights activists, and political dissidents.[10] The leaked 2021 list did not establish that every listed person had been hacked, and NSO denied that the list was connected to its system.[1]

10Pegasus and the Israel Police Controversy

At the start of 2022, Calcalist journalist Tomer Ganon alleged that the Israel Police had used Pegasus against Israeli citizens without court orders.[16] Reported targets included anti-Netanyahu protesters, mayors, government employees, and a person close to a senior politician. Police denied the allegations. Reports said police had acquired Pegasus in 2013 and made it operational in 2015.[17]

The allegations generated controversy involving police, the attorney general, privacy advocates, and the Knesset Constitution, Law, and Justice Committee.[16] It intensified after reports that Pegasus had been deployed against Shlomo Filber, a state witness in Prime Minister Benjamin Netanyahu's criminal trial. SAPIR Journal later reported that the government had established a commission of inquiry into police use of Pegasus, with authority to examine its possible role in the Netanyahu cases.[16]

On January 31, 2022, the then attorney general appointed an examination team chaired by Deputy Attorney General Amit Marari. It was tasked with determining whether phones associated with people named in published reports had been infected, whether Pegasus had been used, and whether any infection occurred without a judicial warrant.[18]

The team examined Pegasus's user interface and internal database, including data extracted by NSO from servers at Israel Police facilities. It reviewed successful infections, infection attempts, and records deleted by users, but did not examine intercepted communications.[18]

The team found that infection attempts had been made against two people for whom court warrants had been issued and that one attempt succeeded. The remaining numbers attributed to people on the published list did not appear in the system's database.[18] The report concluded that its technological examination found no indication that police had infected the phone of anyone on the published list with Pegasus without a judicial warrant. It stressed that the conclusion was limited to the specified allegations, systems, and technological data and anticipated further review of police tools, authority, use, and supervision.[18]

11Antisemitism in Online Discourse About Pegasus

The Pegasus affair also generated antisemitic online commentary. A report by the Decoding Antisemitism research project, archived by the Institute for Jewish Policy Research, analyzed French-language reactions on Facebook and Twitter pages associated with major French media outlets. Researchers examined 33 discussion threads containing 3,196 comments.[11]

Five percent of the comments were classified as antisemitic.[11] The report identified recurring themes of Jewish global power, domination, control, alleged amorality, alienness, and portrayals of Israel as a "spy state." It argued that some users interpreted the affair through conspiracy theories and antisemitic stereotypes rather than as a complex technology and policy controversy.[11]

The report also found that some commenters treated Israel's normalization agreement with Morocco as evidence that Morocco had been given Israeli-designed spyware. It presented this as an example of a conventional diplomatic relationship being reframed as proof of a broader conspiracy.[11]

12Significance and Broader Policy Implications

Pegasus has raised questions about the obligations of spyware vendors, purchasing governments, and exporting states when surveillance tools are used across borders. A 2019 UN Special Rapporteur report quoted in the Knesset policy paper recommended a moratorium on the export, sale, transfer, use, and servicing of privately developed surveillance tools until a human-rights-compliant safeguards regime is established.[9] It also recommended that purchasing states restrict surveillance to legally authorized, necessary, and legitimate objectives and provide effective remedies for victims.[9]

The Knesset paper summarized criticism from international-law experts, UN officials, and privacy and human-rights organizations concerning the potential misuse of offensive cyber tools. It discussed Saudi Arabia, China, Sudan, Malaysia, and the United Arab Emirates while cautioning that the discussion did not establish that each country had used Pegasus.[9]

Israeli experts have warned that exports of surveillance technology can create reputational and diplomatic risks when tools are used by autocratic governments against civil society. The Institute for National Security Studies described the controversy as exposing risks in Israel's "spy-tech diplomacy," in which advanced cyber products contribute to relations with governments that might not otherwise be close partners.[1]

The WhatsApp litigation and reported $167 million damages award illustrated potential financial consequences for spyware vendors.[13] The EU's 2021 dual-use framework established controls expressly addressing intrusion software and network-communications surveillance systems.[9] Within Israel, the debate also concerns how to preserve the legitimate security uses and international standing of its cyber industry while improving oversight of offensive tools.[9][1]

13Controversies

The 2021 leaked list became the basis for much reporting about Pegasus, but its provenance was unclear and the presence of a number did not prove infection.[6][4] NSO denied that the list was connected to its system and said it had not received evidence that listed people had been attacked by Pegasus.[1]

Allegations about particular governments and individuals vary in evidentiary strength, ranging from reported potential targeting to forensic findings. Claims that Pegasus-derived intelligence contributed to Jamal Khashoggi's murder remain particularly serious and contested; the Washington Institute said no direct public link had been verified.[5]

The Israeli Ministry of Justice found no indication of warrantless Pegasus infections among the people included in the specific list it examined, but it limited that conclusion to the examined allegations, systems, and available data.[18] Likewise, NSO's descriptions of Pegasus's capabilities and its claims about vetting clients, blacklisting countries, and rejecting business are statements from the company rather than independent government findings.[1][2]

The Defense Export Control Law has been criticized for not expressly addressing the human-rights consequences of offensive-cyber exports. The adequacy and transparency of Israel's export-control regime remain subjects of policy disagreement between Israeli authorities and international critics.[9]

Sources

  1. 1Institute for National Security Studies, Pegasus Scandal and Spy-Tech Diplomacy (accessed September 9, 2026)
  2. 2NSO Pegasus Product Description, Internet Archive (accessed September 9, 2026)
  3. 3The Times of Israel — Apple Boosts iPhone Security (accessed September 9, 2026)
  4. 4CAMERA UK — BBC and the Spyware Story (accessed September 9, 2026)
  5. 5Washington Institute for Near East Policy, Gulf Cyber Cooperation with Israel (accessed September 9, 2026)
  6. 6The Times of Israel — Worldwide Probe Finds Tech by Israel's NSO (accessed September 9, 2026)
  7. 7U.S. Department of State, Entity List for Malicious Cyber Activities (accessed September 9, 2026)
  8. 8Congress.gov, U.S. Senate Hearing on Commercial Spyware (accessed September 9, 2026)
  9. 9Israeli Knesset, Sale of Dual-Use Technology to Authoritarian Regimes (accessed September 9, 2026)
  10. 10Congress.gov, FBI Told Israel It Wanted Pegasus for Investigations (accessed September 9, 2026)
  11. 11JPR — Decoding Antisemitism, Discourse Report 4 (accessed September 9, 2026)
  12. 12The Times of Israel — Israeli Government Okayed Sale of Spyware (accessed September 9, 2026)
  13. 13The Jerusalem Post — NSO WhatsApp Damages (accessed September 9, 2026)
  14. 14Library of Congress, Global Legal Monitor — Sovereign Immunity Ruling (accessed September 9, 2026)
  15. 15The Times of Israel — Phones Hacked in Jordan (accessed September 9, 2026)
  16. 16SAPIR Journal — Israel's Snowden Moment (accessed September 9, 2026)
  17. 17Jewish News Syndicate — Israel Police and NSO Spyware (accessed September 9, 2026)
  18. 18State of Israel, Ministry of Justice, Pegasus Examination Findings (accessed September 9, 2026)

IsraelPedia Question & Answers

  • What is Pegasus spyware?

    Pegasus is a sophisticated mobile-surveillance tool developed by the Israeli technology company NSO Group, which was founded in 2010 and is based in Herzliya. It can infiltrate smartphones, extract communications and other stored data, track location, and remotely activate a device's camera and microphone. NSO says Pegasus is sold only to government agencies for counterterrorism and law-enforcement purposes and that the company does not operate it for customers.

  • How was Pegasus first publicly identified?

    Pegasus was publicly identified in August 2016 after Emirati human-rights activist Ahmed Mansoor received a message promising information about prisoners allegedly being tortured in the United Arab Emirates. Instead of opening its link, Mansoor forwarded the message to Citizen Lab at the University of Toronto. Researchers from Lookout and Citizen Lab found that the link would have exploited a chain of previously undisclosed vulnerabilities in Apple's iOS 9.3.5 and installed Pegasus, after which Apple issued a security update.

  • What did the 2021 Pegasus Project investigation find?

    The 2021 Pegasus Project, conducted by 17 news organizations working with Forbidden Stories and Amnesty International, examined a leaked list of approximately 50,000 phone numbers and linked numbers on it to more than 1,000 people in over 50 countries. The identified numbers included those of heads of state, prime ministers, journalists, human-rights activists, and government officials. The investigation counted 189 journalists, 85 human-rights activists, and more than 600 politicians and government officials among the numbers analyzed. NSO denied that the leaked data constituted a list of Pegasus targets, and the presence of a number on the list did not by itself establish that the corresponding phone had been infected.

  • What surveillance capabilities does Pegasus have according to NSO's own product description?

    According to NSO's product description, Pegasus supports collection of SMS messages, email, calendars, call history, instant messages, contacts, browsing history, audio, photographs, screen captures, files, and location data. Active functions include intercepting voice calls, recording environmental sound, taking photographs and screenshots, and tracking GPS location. The document also describes installation methods ranging from tailored SMS or email links to remote over-the-air installation requiring no action by the target, as well as physical installation said to take less than five minutes. These specifications are manufacturer claims rather than independent test results.

  • What action did the U.S. government take against NSO Group?

    On November 3, 2021, the U.S. Department of Commerce added NSO Group and Candiru to its Entity List, restricting exports, re-exports, and transfers of covered U.S. items to the companies. The government said NSO had developed and supplied spyware to foreign governments that used it to maliciously target officials, journalists, businesspeople, activists, academics, and embassy workers, conduct the Commerce Department described as enabling transnational repression. The FBI separately confirmed that it had purchased a limited Pegasus license in 2018 and tested the software for approximately two years at a secret facility in New Jersey, though it stated that Pegasus was never used operationally or in support of an investigation.

  • What did the Israeli attorney general's examination find about police use of Pegasus against Israeli citizens?

    An examination team appointed by the then attorney general on January 31, 2022, and chaired by Deputy Attorney General Amit Marari investigated allegations that the Israel Police had used Pegasus against Israeli citizens without court orders. The team examined Pegasus's user interface and internal database, including data extracted by NSO from servers at Israel Police facilities. It found that infection attempts had been made against two people for whom court warrants had been issued and that one attempt succeeded, but concluded that its technological examination found no indication that police had infected the phone of anyone on the published list without a judicial warrant. The report stressed that the conclusion was limited to the specified allegations, systems, and technological data.

  • What broader policy debates has Pegasus sparked?

    Pegasus has raised questions about the obligations of spyware vendors, purchasing governments, and exporting states when surveillance tools are used across borders. A UN Special Rapporteur report recommended a moratorium on the export, sale, transfer, use, and servicing of privately developed surveillance tools until a human-rights-compliant safeguards regime is established. Israeli experts have warned that exports of surveillance technology can create reputational and diplomatic risks when tools are used by autocratic governments against civil society, and Israel's Defense Export Control Law has been criticized for not expressly addressing the human-rights consequences of offensive-cyber exports. The European Union revised its dual-use export-control framework in 2021 to place greater emphasis on human-rights risks and to cover intrusion software and network-communications surveillance systems.