Pegasus spyware is the world's most documented advanced commercial surveillance tool. This hub consolidates RedSec LTD's intelligence resources on Pegasus — from technical mechanics and targeting analysis to detection strategies and anti-spyware defense.
Pegasus spyware is the defining surveillance technology of the 21st century — a tool so capable that its mere existence has changed the security calculus for high-risk individuals and organizations worldwide. This intelligence hub brings together RedSec LTD's analysis of Pegasus: how it works, who it targets, why it's so dangerous to detect, and what effective defense looks like.
NSO Group Technologies, founded in Israel in 2010, developed Pegasus as a lawful interception tool for government intelligence and law enforcement agencies. The company markets the product as a critical tool for fighting terrorism and serious crime — enabling authorities to access the encrypted communications of suspects. The reality of its deployment has been substantially documented as far broader than this framing suggests.
What distinguishes Pegasus from all previous commercial surveillance tools is its zero-click capability — the ability to infect a device without any user interaction. By exploiting vulnerabilities in how operating systems process incoming data, Pegasus can silently install itself when a specially crafted message is received. The target never clicks anything. They may not even see the message that delivered the attack.
The 2021 Pegasus Project investigation, involving 17 media organizations and Amnesty International, analyzed a leaked list of approximately 50,000 phone numbers selected as targets of interest by Pegasus clients. The list included journalists from major international outlets, heads of state, cabinet ministers, diplomats, military officials, lawyers, human rights activists, and business executives across dozens of countries.
Standard mobile security advice — keep your device updated, use encrypted messaging, don't click suspicious links — provides insufficient protection against Pegasus. The tool exploits vulnerabilities that don't yet have patches, in software that users trust, without requiring any user action. The encryption of Signal, WhatsApp, or iMessage is irrelevant because Pegasus reads messages after they are decrypted on the device.
Detecting Pegasus requires specialized forensic tools and expertise. The spyware is designed to minimize its footprint, self-destruct in forensic environments, and continuously evolve to defeat detection methodologies. Amnesty International's Mobile Verification Toolkit (MVT) provides the best publicly available detection capability, but it requires technical expertise and physical device access, and its IOC database is always somewhat behind current Pegasus variants.
Effective protection against Pegasus requires an intelligence-first approach. Understanding exactly how Pegasus operates — its delivery mechanisms, persistence techniques, command-and-control patterns, and behavioral footprint — is the foundation for designing defenses that can actually reduce exposure. This includes device hardening protocols, secure communications architecture, behavioral monitoring, and regular forensic auditing by specialists.
Operational standards that govern every engagement we undertake
Valukoja 8,
11415 Tallinn, Estonia