- This is the most comprehensive analysis of Pegasus spyware to date, based on internal NSO Group documents and forensic investigations.
- Pegasus is sold as an end-to-end cyber-intelligence solution, with NSO Group managing key infrastructure like anonymized servers and relay networks.
- The system includes a user-friendly dashboard for operators, with tiered permissions and case management for targeting.
- Infection vectors include zero-click (covert) and one-click (triggered) attacks, which have evolved over time.
- Newly disclosed material independently validates the Pegasus Project leak dataset, linking clusters to NSO internal systems like Sales 3 and Sales 6.
- Customer-specific indicators of compromise (e.g., iCloud accounts) allow forensic attribution of attacks to specific Pegasus customers.
- NSO Group provides ongoing maintenance and support, making the system dependent on their involvement for operation.