Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Privacy

Inside Pegasus: NSO’s own files reveal the machine

Jesse William McGrawBy Jesse William McGrawJuly 22, 2026No Comments14 Mins Read157 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Inside Pegasus: how NSO Group's own court files expose the spyware system, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Newly unsealed internal NSO Group documents, filed in WhatsApp’s US lawsuit and analysed by Amnesty International’s Security Lab as technical partner to a new Forbidden Stories investigation, provide the most complete picture yet of how Pegasus spyware works. They confirm Pegasus is a vendor-run managed service rather than a weapon sold and forgotten, decode its zero-click infection vectors by name, and independently validate the leaked dataset behind the 2021 Pegasus Project.

For years, the inner workings of Pegasus were reconstructed from the outside: a forensic trace here, a patched exploit there, a leaked list of phone numbers. That guesswork is now unnecessary. In its July 2026 technical analysis, Amnesty’s Security Lab worked from NSO Group’s own product decks, engineering wikis, release notes and sworn testimony, all of which entered the public record in WhatsApp Inc. and Meta Platforms, Inc. v. NSO Group Technologies. Ransomnews reviewed the same catalogue of primary documents, republished by Amnesty on GitHub, to report this piece.

Where did these documents come from?

The material comes from discovery in WhatsApp’s case against NSO Group, filed in the US District Court for the Northern District of California (Case No. 4:19-cv-07123-PJH). WhatsApp and Meta sued in October 2019 after NSO customers used a WhatsApp zero-click exploit to target roughly 1,400 devices in April and May 2019. Over the course of the litigation, hundreds of pages of NSO’s internal product and engineering documents, along with depositions of four senior NSO executives, were unsealed and filed on the public docket.

Credit for turning that raw docket into intelligence belongs to Amnesty International’s Security Lab, which acted as technical partner to Forbidden Stories, the non-profit consortium that coordinated the original Pegasus Project. Amnesty republished the key exhibits on GitHub so other researchers can work from primary sources. Every page carries the court’s filing stamp and Bates numbers, so any claim below traces back to a specific filing. This is not a leak in the conventional sense: it is a company’s own paperwork, entered into evidence and made public by a court.

Pegasus is run like a software company, not handed over like a gun

The single most important theme running through the documents is mundane on its face and damning in its implications: NSO Group builds and operates Pegasus with the same discipline as any commercial software vendor. The exhibits include product requirement documents, Confluence wiki pages, Jenkins deployment runbooks, versioned release notes with beta and general-availability stages, QA test checklists and service level agreements. Pegasus 2.65, one release note records, tripled collection speed and multiplied exfiltration speed sixfold. This is a product roadmap, not a one-off cyberweapon.

That framing matters because NSO’s long-standing legal and public defence rests on the opposite claim: that it merely sells a tool to sovereign governments who alone decide how to use it. The documents undercut that. Amnesty’s analysis, supported by the exhibits, shows NSO develops every new exploit, registers and runs the anonymised delivery infrastructure, and staffs a Network Operations Center that monitors customer systems around the clock and receives alerts when an infection attempt fails or is exposed. Every operating-system security update from Apple or Google can break a vector, which means Pegasus needs continuous vendor maintenance to keep working. The blunt conclusion, in Amnesty’s words, is that the system cannot operate without NSO’s ongoing involvement. If you have followed how ransomware-as-a-service splits a criminal operation into a platform and its operators, the structure will look familiar.

Who runs what in a Pegasus deployment ransomnews.com CUSTOMER PREMISES – Pegasus dashboard (browser) – Storage servers (collected data) – Operators, analysts, supervisors – Groups, cases, permissions Local only. Cannot send an attack alone. RUN BY NSO GROUP – Exploit + vector development – “White Services” accounts + domains – PATN anonymising network – 24/7 Network Operations Center Ongoing. Every OS update needs a fix. The customer drives the dashboard; NSO keeps the machine alive. Neither works without the other.

How does a single Pegasus attack actually run?

An operation begins in the Pegasus dashboard, a browser console installed on the customer’s own premises. Work is organised into “groups” and “cases”, with tiered roles (analyst, operator, supervisor, administrator) that limit who can see which targets. A case gathers targets around a “key intelligence topic”, and each target is entered by phone number, which is the primary identifier the system needs. In many cases, the documents state, the phone number is all that is required to launch an attack.

Before any exploit fires, Pegasus fingerprints the target. It checks whether the number belongs to a smartphone, whether it runs iOS or Android, whether the handset is switched on, which network it is using, whether it is roaming, and which apps such as WhatsApp or iMessage are installed. Part of this validation relies on a Home Location Register (HLR) lookup, a telecom query that reveals a subscriber’s current network and country without alerting them. Licensing terms are enforced at this step too: the number of targets, simultaneous infections and permitted countries are all capped, and certain countries such as the United States and Israel are barred for most customers by policy rather than by any technical limit.

How one Pegasus infection runs ransomnews.com Open case,add number Fingerprint:HLR, OS, apps Licence +country check Vector:Covert / 1-click Installagent Then collect: calls, messages, email, photos, files, location, saved credentials. Commands can pre-schedule the mic or camera to switch on during a target’s calendar meeting.

Once the agent is installed, the operation shifts from targeting to collection. The dashboard exposes exfiltrated data by type: calls, messages, email, calendar, contacts, browsing, files, apps and photos. It also presents a “credentials” tab of saved passwords and tokens, which lets an operator keep access to a victim’s cloud accounts long after the phone itself is clean. A 2018 product description boasts that cloud access delivers “a continual flow of information”. A separate “commands” module can actively trigger the phone’s microphone, camera or location, and other documents describe scheduling microphone recording to start automatically when the target has an important meeting in their calendar.

One capability deserves its own line. When a target cannot be reached directly, NSO’s own training material recommends “close-circle infection”: going after the colleagues, friends or family around the primary target instead. Pegasus has previously been documented against relatives of journalists and opposition figures, including people who were children at the time.

Heaven, Eden and Erised: the zero-click vectors, decoded

The documents finally put internal names to vectors that researchers had only observed forensically. The three successive WhatsApp zero-click vectors for Android, built between 2017 and 2020, were codenamed Heaven, Eden and Erised, grouped under the umbrella term Hummingbird. A Pegasus 2.50 release note, read into the record during the deposition of NSO chief executive Yaron Shohat, describes Heaven as the first zero-click installation vector for broad Android devices, approved for production in January 2018. NSO’s VP of research and development, Tamir Gazneli, testified about the team that built these WhatsApp vectors, and NSO VP Ramon Eshkar named the same family from the customer-facing side.

On the Apple side, a zero-click vector codenamed Diablo was available in 2018 and lines up with a forensically observed exploit against the Voice-over-WiFi implementation on iOS 11. NSO later shipped Dragonfly, an iOS 12 vector delivered over iMessage, used heavily through 2019 until it was likely broken by iOS 12.4.1 after Google Project Zero published research into the iMessage attack surface. Amnesty and Citizen Lab had already documented the later iOS chains: an iOS 13 vector against Apple Photos, the iOS 13 iMessage zero-click known publicly as KISMET, and the widely reported iOS 14 zero-click, FORCEDENTRY (also called Megalodon). Erised, the Samsung-only Android vector, used manipulated DNG image files against Samsung’s Quram parsing library, a technique that resembles later in-the-wild Samsung zero-clicks and is worth watching as a live thread.

Evolution of Pegasus infection vectors ransomnews.com 2013BlackBerry Jan 2018HeavenAndroid/WhatsApp 0-click 2018DiabloiOS 11 VoWiFi 2019DragonflyiOS 12 iMessage 2020KISMET 2021FORCEDENTRY Heaven, Eden and Erised (the Hummingbird family) targeted WhatsApp on Android; the iOS line ran through iMessage.

White Services, crypto, and the fingerprint that convicts

Perhaps the most consequential disclosure for investigators concerns a department NSO calls “White Services”. Its job is to register the email addresses, iCloud and WhatsApp accounts, domains and servers used to deliver attacks, and to do so anonymously, so that neither the customer nor NSO can be linked to them. Eshkar testified that the accounts were created in an “anonymized way”, using financial means not tied to the customer or the company, for example a credit card in someone else’s name. Much of the delivery infrastructure, NSO’s own terminology calls it “whitened”, appears to have been paid for with cryptocurrency to break the money trail. It is the same attribution-evasion instinct that drives ransomware crews to launder their ransom payments on-chain.

Here is the irony that makes this the strongest thread in the whole story. NSO built per-customer infrastructure for the customer’s protection, but that same isolation is exactly what lets researchers catch them. Because NSO creates a fresh, isolated set of accounts and domains for each customer, those accounts function as a customer fingerprint. When the same malicious iCloud account or infection domain shows up across multiple victims, forensic analysts can cluster those victims as targets of one customer. Across hundreds of cases, Amnesty says it has never once seen a single attacker account or domain shared between two customers. This is the same logic Ransomnews applies when we hunt shared threat infrastructure and attribute attacks by their indicators. The design choice meant to hide the customer is the design choice that names them.

“Abuse Prevention” that protects the operator, not the victim

NSO maintains a system it calls “Abuse Prevention”, governed by an “OpSec Rule Engine” whose product requirements document spells out its purpose: enforce quantity limits, cool-down periods and installation limits so that operations run “at minimal risk of exposure”. Read carefully, this is abuse prevention in name only. The abuse being prevented is not the surveillance of a journalist; it is the discovery of the surveillance. The system exists to stop a customer from burning a vector by hammering a target too often, not to stop the targeting itself.

Those same operational-security features left a trail that ended up validating the Pegasus Project. NSO’s system included a “whitelist” that let customers run repeated test infections against their own devices without the normal rate limits. Test numbers, including phone numbers belonging to NSO staff and sales representatives, were recorded in the system’s logs. Two clusters in the leaked Pegasus Project dataset map directly onto internal NSO demonstration systems the company labels “Sales 3” and “Sales 6”. A US number used by an NSO sales representative and a Peruvian number both appear in those clusters on the same days NSO’s own dashboards, filed in the WhatsApp case, show test infections against them in May 2019. NSO had told The Guardian in 2021 that it saw “no correlation” between the leaked lists and its technology. Its own paperwork now says otherwise.

Codename Morgan: what one customer did with it

The Amnesty technical analysis is the “how”. Forbidden Stories supplied the “who” in a parallel 2026 investigation, “Inside Morocco’s Spying Machine”. According to that reporting, NSO used the internal codename “Morgan” for its Moroccan customer, ran a Pegasus demonstration in Rabat in 2017 with an Emirati intermediary, and Morocco went on to select close to 13,000 phone numbers over roughly four years. The consortium documents targets that included a senior Spanish Guardia Civil officer, at a time when Spanish officers were training Morocco’s own service, and members of the French government. This is the human face of the dashboard and the vectors: real journalists, officials and opponents, chosen by phone number and infected without a tap.

Where does the case stand in 2026?

The litigation that pried these documents loose has not gone quietly. In December 2024 the court granted summary judgment against NSO on liability under the US Computer Fraud and Abuse Act and California’s equivalent statute. In May 2025 a jury awarded WhatsApp roughly 168 million dollars, made up of about 444,000 dollars in compensatory damages and 167.25 million in punitive damages. Judge Phyllis J. Hamilton later cut the punitive figure to 4 million dollars, but granted a permanent injunction: NSO is barred from targeting WhatsApp users and ordered to delete WhatsApp source code in its possession. NSO has appealed to the Ninth Circuit (No. 25-7380). In May 2026, Access Now and ten other civil society groups urged the appeals court to keep the injunction in place. WhatsApp has since accused NSO of violating that injunction and filed a contempt motion, alleging fresh Pegasus activity. The paper trail, in other words, is still growing.

What this means if you could be a target

The uncomfortable truth of a zero-click vector is that ordinary vigilance does not help. There is no link to avoid and no attachment to distrust. That does not leave high-risk users powerless. Keep devices patched, because most Pegasus vectors die the moment the underlying bug is fixed. On iPhone, enable Lockdown Mode, which disables much of the attack surface these iMessage and WhatsApp chains rely on. Reduce your exposure by trimming the apps and accounts that can be probed, and remember that “close-circle” targeting means your risk is partly your contacts’ risk. If you have real reason for concern, Amnesty’s open-source Mobile Verification Toolkit lets a technically capable person check a device against known Pegasus indicators. For a broader hardening baseline, our 2026 privacy stack guide and our look at the wider surveillance stack are good starting points.

The deeper lesson sits above any one device. Pegasus is not a rogue tool that slipped its leash. It is a maintained product, sold with a licence and a service agreement, kept alive by a vendor that stays in the loop for every attack. That is precisely why the accountability fight has moved from forensics into courtrooms and export-control offices. The forensic methods still matter, and Amnesty’s work shows they hold up under NSO’s own documentation. But the machine, as these files make plain, has a manufacturer.

Frequently asked questions

What is Pegasus spyware?

Pegasus is mercenary spyware developed by Israel’s NSO Group and sold to government customers as an end-to-end surveillance system. Once installed on a phone it can read messages, calls, email and files, capture saved credentials, and remotely switch on the microphone, camera and location.

What did the WhatsApp v NSO documents reveal?

The unsealed NSO documents confirm Pegasus is a vendor-run managed service, name its zero-click vectors (Heaven, Eden, Erised and the iOS chains), detail the Pegasus dashboard and targeting workflow, and show internal test data that independently validates the leaked 2021 Pegasus Project dataset.

What is a zero-click attack?

A zero-click, or “Covert”, attack infects a device without any action from the target, typically by exploiting a messaging app such as WhatsApp or iMessage. Because there is no link to click, the user cannot avoid it through caution, which is why patching and reducing attack surface matter most.

How are Pegasus attacks attributed to a specific government?

NSO’s “White Services” team builds separate, anonymised attack infrastructure for each customer. Because a given attack account or infection domain is never shared between customers, it acts as a fingerprint: when the same account or domain appears across multiple victims, researchers can cluster them as targets of one customer.

Can Pegasus run without NSO Group?

No. The documents show NSO develops the exploits, registers and operates the anonymised delivery network, and runs a 24/7 operations center. Because operating-system updates constantly break vectors, the system needs continuous vendor maintenance, which undercuts NSO’s claim that customers operate it alone.

How can I check if my phone has Pegasus?

Amnesty International’s open-source Mobile Verification Toolkit (MVT) can check an iOS or Android device against known Pegasus indicators of compromise, though it requires technical skill to run and interpret. Keeping the device updated and enabling iPhone Lockdown Mode reduce the risk of infection in the first place.

Sources and further reading

  • Amnesty International Security Lab — Inside Pegasus: the evolution of the world’s most notorious spyware (primary analysis)
  • AmnestyTech / inside-pegasus — catalogue of unsealed WhatsApp v NSO exhibits (primary documents)
  • Forbidden Stories — Pegasus Project: Inside Morocco’s Spying Machine (primary investigation)
  • Meta Newsroom — deposition designations, WhatsApp v NSO (primary, party filing)
  • CourtListener — Dkt. 796, unsealed NSO exhibits (court record)
  • The Record — judge bars NSO from targeting WhatsApp users, lowers damages
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleMaltego tutorial: OSINT link analysis in 2026
Next Article Codename Morgan: inside Morocco’s Pegasus machine
Jesse William McGraw

Jesse William McGraw, also known as GhostExodus, is a former insider threat and threat actor. He became the first person in recent U.S. history to be convicted of corrupting industrial control systems. Today he focuses on threat intelligence, OSINT, and public speaking, using his knowledge to bring awareness to the security risks that organisations and individuals face.

Related Posts

Codename Morgan: inside Morocco’s Pegasus machine

July 22, 2026

Stealer logs bypassing MFA in 2026 [Field Guide]

May 16, 2026

SEC 4-day cyber rule: 2.5 years in, what CISOs learned

May 11, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.