Pegasus spyware: how it works and how to protect your phone
Pegasus targets selected phones and may require no action from the owner. Here is a calm, evidence-based guide to risk and response.
The short answer
Pegasus is commercial spyware associated with the Israeli company NSO Group. It is designed to provide covert access to selected smartphones. When an intrusion succeeds, an operator may be able to collect data and use device sensors, depending on the operating-system version, exploit chain and level of access obtained.
This is not the typical malware delivered through a random advert. Tools of this class are expensive and generally used against specific people. Journalists, human-rights defenders, politicians, diplomats, lawyers, opposition figures and people close to them can face elevated risk.
What changed by 2026
Research from Amnesty International, Citizen Lab, Apple, Google and Meta shows a continuing contest between mobile-platform defenders and commercial spyware vendors. When one attack chain is closed, operators look for another, while defenders add restrictions, notifications and forensic evidence sources.
In 2026, Amnesty Security Lab described further Pegasus evolution, Citizen Lab reported a confirmed infection involving a member of a European Parliament committee, and Meta published a new WhatsApp update on its work against NSO. Google also introduced Intrusion Logging, a protected log source on supported Android devices that can help specialists investigate sophisticated targeted attacks.
This does not mean that every smartphone is infected. It means the threat remains relevant to a small group of high-risk targets and cannot always be assessed with a routine antivirus scan.
How Pegasus reaches a phone
Interaction-based attacks
Earlier campaigns often used links in text messages or chat apps. The target was persuaded to open a page that triggered a chain of vulnerabilities. This method remains possible, so unexpected messages still deserve independent verification.
Zero-click attacks
The more dangerous scenario requires no tap. Specially prepared data reaches a component that automatically processes messages, images, calls or other network content. If that component contains an unknown or unpatched flaw, code may run before the user sees anything.
Public research has documented chains involving iMessage and other system services. Technical details differ, but the pattern is similar: an initial weakness enables code execution, later stages escape isolation and gain additional access, and a covert agent is deployed.
Which data may be exposed
Capabilities depend on the success of the specific intrusion. Public investigations have associated Pegasus with access to:
- messages, email and contacts;
- photographs, documents and calendars;
- call history and some application data;
- location information;
- microphone or camera access after sufficient privileges are gained;
- keys or session tokens that may expose data already decrypted on the device.
End-to-end encryption protects messages while they travel between devices. It cannot fully protect information after decryption if an attacker controls an endpoint.
Can you recognise an infection yourself?
There is no reliable household symptom. Battery drain, heat or additional network traffic have many ordinary causes and do not prove Pegasus is present. A lack of symptoms is not proof of safety either.
The most important signal is an official targeted-attack notification from Apple or another platform provider. Apple explains that notifications appear in the account portal and are sent to verified contact details. A genuine notification does not ask you to follow an unrelated link, install a profile or disclose a password.
What to do after a threat notification
- Do not immediately erase or reset the device; that may destroy evidence needed for assessment.
- From a separate trusted device, contact a qualified digital-security organisation or mobile-forensics specialist.
- Update the operating system and apps unless the specialist asks you to preserve the current state first.
- Enable Lockdown Mode on a supported iPhone if your risk profile justifies it.
- Protect primary accounts with hardware keys or passkeys and review active sessions.
- Do not automatically restore a complete backup to a replacement phone before agreeing on a safe migration plan.
- Treat the event as wider than one device: review email, cloud storage and sensitive communication workflows.
This sequence helps preserve evidence and limit damage. It is not a substitute for a professional investigation.
How specialists examine devices
Amnesty International maintains Mobile Verification Toolkit (MVT), a set of tools for examining backups, system records and known indicators. MVT is intended for trained researchers; results can be misinterpreted without forensic context.
On supported Android devices, Intrusion Logging may provide another source of evidence. Logs should be exported and shared only with trusted specialists because they can include sensitive device and activity information.
A negative result does not always prove that no attack occurred. Available traces depend on the operating-system version, time elapsed, reboots, the intrusion method and the indicators known to researchers.
Practical protection for higher-risk people
Update without delay
Install stable operating-system and messaging updates promptly. Replace devices that no longer receive security fixes when they are used for sensitive work.
Reduce the attack surface
Remove unnecessary apps and profiles, limit message previews, avoid untrusted app stores and review permissions. Higher-risk iPhone users should consider Lockdown Mode. WhatsApp also offers Strict Account Settings, which applies several stronger defaults for people concerned about targeted attacks.
Separate roles and channels
Avoid keeping every sensitive activity on one device. Separate accounts for public and confidential work can reduce the impact of compromise. Agree on a backup communication channel and a process for verifying urgent requests.
Protect connected accounts
Unique passwords, a password manager, hardware keys, passkeys and session reviews do not directly stop a zero-click exploit. They can, however, reduce subsequent access to cloud data.
Legal and public-interest context
NSO Group states that its technology is supplied to government customers for investigating serious crime. Multiple independent investigations have nevertheless documented Pegasus use against civil-society figures. The US Department of Commerce added NSO Group to the Entity List in 2021. The European Parliament has called for stronger investigations, export controls and safeguards against abuse.
The Pegasus Project consortium examined a leaked list of more than 50,000 phone numbers that may have been of interest to NSO clients. A number appearing on the list is not proof that the device was infected; confirmation requires technical examination.
Frequently asked questions
Does rebooting remove Pegasus?
A reboot may interrupt one non-persistent component, but it is not a reliable cleanup method and may change available evidence. After an official warning, seek specialist advice before taking destructive action.
Is antivirus enough?
No. Mobile security software may provide one defensive layer, but sophisticated zero-click operations are built to avoid routine detection.
Does Pegasus affect only iPhones?
No. Public investigations have documented attacks involving both iOS and Android. Forensic evidence and defensive controls differ between the platforms.
Should everyone use Lockdown Mode?
Apple designed it for people who may be targeted by exceptionally sophisticated attacks. It intentionally limits some features, so the choice should reflect the individual risk profile.
Verified sources
- Amnesty Security Lab: the evolution of Pegasus in 2026
- Citizen Lab: European Parliament committee member infected with Pegasus
- Meta: a WhatsApp update on fighting NSO spyware
- Google: Android security and privacy updates for 2026
- Apple: official targeted-attack notifications
- MVT: analysing Android Intrusion Logs
- Citizen Lab: the BLASTPASS exploit chain
- US Department of Commerce: NSO Group added to the Entity List
- European Parliament: recommendations on spyware safeguards
- OCCRP: Pegasus Project methodology and context




