
Pegasus and Commercial Spyware: How It Works
· By Archivo Bélico editorial team
What Pegasus is, how commercial spyware from NSO Group and similar firms operates, documented cases, and the regulatory response so far.
Pegasus is a surveillance program developed by the Israeli company NSO Group and sold, according to the company itself, exclusively to governments and state agencies for terrorism and organized-crime investigations. Its public relevance stems from the fact that, once installed on a mobile phone, it grants very broad access to the device, and its use has been documented against journalists, lawyers, activists and politicians in various countries.
What mercenary spyware is
The term "mercenary spyware" refers to the private industry that develops and sells intrusion capabilities to states that couldn't develop them on their own. It's a market with several known players — NSO Group, the Intellexa alliance with its Predator product, Cytrox, Candiru, Italy's Hacking Team and Germany's FinFisher, the latter two affected by leaks and subsequent closure or restructuring — and a fragmented regulatory landscape.
How it works, in general terms
Without going into technical detail that doesn't belong in an educational encyclopedia, the scheme documented by researchers is as follows: the product exploits unpatched vulnerabilities in the phone's operating system to install itself and gain elevated privileges. Analyses by Citizen Lab and Amnesty International's Security Lab have described infections requiring no interaction from the victim — so-called zero-click attacks — where simply receiving a message or a call is enough. Once active, the operator can access messages, contacts, location, microphone and camera, which renders the end-to-end encryption of messaging apps irrelevant, because the information is captured on the device itself.
Documented cases
In July 2021, the Forbidden Stories consortium, together with Amnesty International and about fifteen media outlets, published the Pegasus Project based on a leaked list of more than 50,000 phone numbers flagged as possible targets of NSO clients. Forensic analysis of a sample of devices confirmed infections on phones belonging to journalists and human rights defenders. NSO Group has consistently rejected the interpretation of the list and stated that its products are sold under state license and Israeli export controls.
In Spain, the so-called CatalanGate case, documented by Citizen Lab in April 2022, described the infection of dozens of phones belonging to Catalan pro-independence politicians and activists; shortly after, the Spanish government reported infections on the phones of the prime minister and several ministers. The judicial investigation has moved forward with difficulty due to a lack of international cooperation. Other analyzed cases affect Mexico, Saudi Arabia, the United Arab Emirates, Hungary, Poland and Greece, the latter involving the Predator product.
| Company or product | Country of origin | Documented status |
|---|---|---|
| NSO Group / Pegasus | Israel | On the US Commerce Department blacklist since 2021 |
| Intellexa / Predator | Greece, Israel, Cyprus | Sanctioned by the US in 2024 |
| Candiru | Israel | Included alongside NSO on the US Entity List |
| Hacking Team | Italy | Massive leak in 2015; later restructured |
Legal and regulatory response
- In November 2021, the US Commerce Department added NSO Group and Candiru to its Entity List.
- WhatsApp (Meta) and Apple sued NSO Group in 2019 and 2021 respectively; in 2024 a US court ruled in WhatsApp's favor on key aspects of the case.
- The European Parliament set up the PEGA committee in 2022, whose final 2023 report found abusive use in several member states and called for common rules.
- In 2023, a US executive order restricted the use of commercial spyware by federal agencies.
This article describes the phenomenon in journalistic and public-policy terms. It doesn't include technical guidance on how the vulnerabilities work or how to detect or replicate them; for digital self-defense, the organizations cited publish their own guides.
Frequently asked questions
- What is Pegasus?
- A surveillance program from the Israeli company NSO Group, sold to governments, that provides broad access to the content and sensors of an infected mobile phone.
- Does encryption help against this kind of program?
- Not on the compromised device itself: if the program runs on the phone, it captures the information before it's encrypted or after it's decrypted.
- What other companies operate in this sector?
- Intellexa with Predator, Candiru, and previously Hacking Team and FinFisher, among others. Several have been sanctioned or have ceased operating.
Sources and references
- Citizen Lab, research on Pegasus, Predator and mercenary spyware
- Amnesty International Security Lab, «Forensic Methodology Report: How to catch NSO Group's Pegasus»
- Forbidden Stories, «The Pegasus Project» (2021)
- US Department of Commerce, addition of NSO Group and Candiru to the Entity List (2021)
- European Parliament, final report of the PEGA committee (2023)
- Citizen Lab, «CatalanGate: Extensive Mercenary Spyware Operation against Catalans» (2022)