Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab
Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab
© Rectangle
We are presenting here our most complete analysis to date of the Pegasus spyware. This blog post builds on previous technical reports and forensic investigations by Amnesty International’s Security Lab. Significantly it also draws on previously unpublished internal NSO Group marketing material and internal technical material which was disclosed as part of a long-running civil case taken by WhatsApp and Meta against NSO Group in a U.S. court.
Amnesty International’s Security Lab has republished a selection of the key documents cited on GitHub, in the interest of making this important material more accessible for all researchers and advocates working on spyware accountability efforts.
We are working towards a longer report building on this investigation to be published at a later date.
This technical analysis provides the most detailed view yet into the inner workings of the Pegasus spyware system. This includes confirmation of key technical capabilities such as the infection vectors and methodologies used to infect devices, supported by analysis of internal NSO Group documents, that until now had only been identified via forensic investigations. It also presents new material further validating the accuracy and significance of the dataset underpinning the original Pegasus Project investigation. Finally, this research provides an updated analysis, drawing on previously published Pegasus forensic evidence and newly released materials, to validate the technical methodology used to forensically link Pegasus spyware attacks targeting different victims as originating from the same Pegasus customer.
A key aim of this publication is to document and demystify the functionality and operations of technological systems like Pegasus. We hope that it will inform the wider spyware accountability community on how complex surveillance systems such as Pegasus are used by government customers, and also illustrate the key and ongoing role of spyware vendors in keeping such systems operational. We believe this public understanding is of critical value to technologists, researchers, and policy makers and others with an interest in understanding the targeted surveillance ecosystem and threats posed to human rights by surveillance technologies.
The contents of this technical research draw heavily on a large pool of confidential NSO Group training material, presentations and internal technical documentation which were disclosed as part of a long-running civil case taken by WhatsApp and Meta against NSO Group in U.S. court. This new material provides an unprecedented insight into the evolution of NSO Group’s spyware. It also reveals the close and ongoing collaboration needed between Pegasus customers and NSO Group to keep the complex spyware system operational.
This technical analysis has been prepared by Amnesty International’s Security Lab in its role as a technical partner to a new Forbidden Stories investigation building on the findings of the 2021 Pegasus Project. As technical partner, Amnesty International’s Security Lab provided analysis of evidence relating to the use of surveillance technologies, including NSO Group’s Pegasus spyware.
1. The Pegasus infection process from the attacker perspective
Pegasus is sold to governments as an “end-to-end” cyber-intelligence solution. NSO Group is responsible for building and integrating the various technical components needed to perform spyware attacks, including creating exploits and infection vectors, deploying and monitoring anonymization servers, and designing a user interface which allows the ultimate end-user – a government customer – to perform highly technically sophisticated attacks with little need for technical capabilities of their own.
Key components of the system, including the Pegasus user dashboard and the storage servers which archive surveillance data gathered from a victim’s device, are installed locally in the customer country, often in a server room at the customer site or headquarters.
However, other important components of the Pegasus system, particularly those used to send attacks and securely transfer the surveillance data from infected devices, are run and managed by NSO Group.
To keep attacks from being traced back to the customer, NSO Group operates much of the delivery and relay infrastructure in a anonymized fashion. In NSO Group’s own terminology, this is referred to as "whitened” infrastructure. A dedicated NSO Group team, "White Services" is responsible for acquiring this infrastructure while aiming to prevent any attributable connection to NSO Group or the Pegasus customer. Much of the server infrastructure appears to be paid for with cryptocurrencies in order to achieve that goal. (Source: “Video...