Pegasus
In short: A highly sophisticated, commercial spyware from the Israeli company NSO Group — it can often compromise smartphones completely without any interaction from the victim (“zero-click”).
In more detail: Pegasus exploits expensive, previously unknown security holes (zero-day exploits) in apps such as iMessage or WhatsApp to install itself without the victim having to click a link or open a file. Officially it’s only sold to governments, but it has repeatedly been involved in scandals over the surveillance of journalists and activists.
In Depth
A typical Pegasus attack sequence via a so-called zero-click hole:
1. The attacker sends a specially prepared message (e.g. iMessage,
WhatsApp) to the target device
2. The message exploits an unknown, unpatched security hole
(zero-day) in the messaging app
3. Malicious code is executed WITHOUT the victim having to
open the message or react to it at all
4. Pegasus obtains root access to the entire device
5. Access to microphone, camera, messages, location, contacts -
everything in real time, unnoticed by the victim
The zero-click character makes Pegasus particularly dangerous: classic security advice (“don’t click suspicious links”, “don’t open unknown attachments”) doesn’t help here, because no interaction from the victim is needed at all. This makes such attacks almost impossible to prevent through user behaviour alone — protection is practically only possible by promptly installing security updates as soon as the vendor closes the exploited hole.
NSO Group officially sells Pegasus exclusively to state bodies for fighting terrorism and serious crime — however, research by networks of journalists (including the “Pegasus Project” in 2021) revealed that the software was repeatedly used against journalists, human rights activists, lawyers and opposition politicians too, which led to sharp international criticism and sanctions against the company.
The billion-dollar market for zero-day exploits
Pegasus is just the best-known representative of a flourishing, largely legal market for “zero-day” vulnerabilities (see Zero-day): specialised companies and individual researchers sell previously undiscovered vulnerabilities in popular software (operating systems, messaging apps, browsers) for six- to seven-figure sums to government bodies, intelligence agencies or security companies such as NSO Group — instead of reporting them to the affected vendor so they can be fixed (responsible disclosure). This market sits in a fundamental ethical tension: the longer a hole stays undiscovered and unpatched, the longer all the NON-intended targets (ordinary users of the same software) remain vulnerable to ANYONE who independently finds the same hole.
Technical operation in detail
Zero-click exploits like those of Pegasus typically exploit weaknesses in the processing of incoming data — for example in the image or file preview of messaging apps, which is executed automatically as soon as a message is received, before the user even opens it. A well-known example was the “FORCEDENTRY” vulnerability (2021) in Apple’s iMessage image processing, which allowed code to be executed on the target device merely by RECEIVING a specially prepared file (without any opening). Apple responded with BlastDoor, an additional security sandbox specifically for incoming iMessage content, which is meant to make exactly such attacks harder by isolating incoming data and processing it with considerably restricted rights before it can reach the rest of the system.
Detection and protective measures for those affected
Because Pegasus is designed to remain undetected, detecting it afterwards is difficult — specialised organisations such as Citizen Lab (University of Toronto) and Amnesty International’s Security Lab developed forensic methods for proving traces of an infection in device logs, often only months after the actual attack. For particularly at-risk people (journalists, activists, opposition politicians), security experts recommend the so-called “lockdown mode” of modern smartphones (an extremely restrictive security setting that deactivates many attack surfaces at the cost of reduced functionality) as well as consistent, prompt installation of security updates, since vendors regularly close Pegasus holes that have become known after the fact.