Pegasus Spyware on Android: Risks, Detection and Response

Reviewed: August 12, 2026

Pegasus is sophisticated commercial spyware associated with NSO Group and documented by research organizations including Citizen Lab and Amnesty International’s Security Lab. It has been used in highly targeted surveillance operations against phones, including devices belonging to journalists, activists and human-rights defenders.

This defensive guide explains infection concepts at a safe level, why common “symptoms” cannot diagnose Pegasus, what ordinary Android users can do, and how a person at elevated risk should preserve evidence and obtain expert help. It does not include exploit code, infrastructure indicators that could expose an investigation, or instructions for deploying spyware.

Pegasus is a targeted-surveillance problem

Pegasus should not be used as a catch-all label for every suspicious battery, advertisement or unknown Android app. Public investigations describe an expensive, operator-driven surveillance capability used against selected targets. That threat model differs from commodity adware distributed through mass downloads.

A useful risk assessment considers:

  • whether the person is a journalist, activist, lawyer, political figure, researcher or another high-risk individual;
  • whether a state or well-resourced actor has a reason to target their communications;
  • whether colleagues or members of the same community have received suspicious links or confirmed warnings;
  • whether the device contains information valuable enough to justify an expensive operation;
  • whether a qualified lab has found technical indicators rather than only unusual phone behavior.

A low likelihood does not make basic security unnecessary. Updating a phone and protecting accounts reduces many common attacks even when Pegasus is not the probable explanation.

How targeted mobile spyware can reach a phone

Documented mobile-spyware campaigns have used more than one delivery path. Exact exploit chains change as vulnerabilities are discovered and patched, so a timeless list of “the Pegasus methods” would be misleading.

One-click targeting

The target receives a carefully designed message containing a link. The destination may imitate a news story, delivery notice, security alert or account page connected to the person’s work. Visiting it can expose the device to an exploit chain. Social context matters: a tailored message from an apparently relevant sender is more persuasive than obvious spam.

Zero-click exploitation

A zero-click chain does not require the owner to tap a link. It may target software that automatically receives and processes network content, such as a messaging or calling component. This is why “I never clicked anything” does not rule out sophisticated compromise and why timely operating-system and application patches matter.

Network and physical-access scenarios

Research over the years has also described infection or redirection scenarios involving network position or direct device access. The relevance depends on the campaign, device and date. Defenders should not turn these broad categories into a claim about one phone without forensic evidence.

What happens after compromise

Research reports describe capabilities that can collect communications, files, location and device data and, under some conditions, access sensors. End-to-end encryption protects messages while they travel between endpoints; it cannot protect content after an endpoint itself is compromised and displays or stores that content.

Battery drain is not proof of Pegasus

Fast battery loss, heat, crashes and higher data use have many ordinary causes: an aging battery, poor signal, a system update, media backup, a broken app or legitimate background work. Sophisticated spyware is designed to avoid obvious signs, and a clean-looking phone is not proof that no compromise occurred.

ObservationWhat it can justifyWhat it cannot prove
Battery or heat changeCheck battery health and per-app usageAttribution to Pegasus
Unexpected account loginSecure the account and preserve the alertThat the phone operating system was infected
Suspicious tailored linkDo not open; preserve and request expert triageThat successful infection occurred
Official threat notificationTake the warning seriously and seek specialized helpThe exact exploit without further analysis
Unknown appVerify publisher, install source and permissionsThat it is Pegasus rather than another app or system component
Forensic indicator matchRequires expert interpretation and corroborationA final conclusion by itself

Reliable conclusions come from multiple artifacts, validated indicators, timestamps and an understood collection method. A consumer antivirus result alone is not a complete forensic examination.

Practical protection for Android users

Install operating-system and security updates

Google’s Android help documentation shows where to check the Android version, security update and Google Play system update. Install updates available for the device. Update schedules vary by manufacturer and carrier; if a phone no longer receives security patches, move sensitive work to a supported device.

Reduce message and account exposure

  • Do not open unexpected links, even when the message uses real names or current events.
  • Confirm unusual requests through a separate, known channel.
  • Use a password manager and unique passwords so one stolen credential does not unlock other accounts.
  • Use passkeys or hardware-backed security keys where suitable.
  • Review active account sessions and recovery details.
  • Limit sensitive information in notifications visible on the lock screen.

Keep the device in its supported security model

Avoid unknown app stores, untrusted APK files and unnecessary rooting. Google warns that modified Android versions can lose built-in protections and automatic security updates. Review apps with accessibility, device-administrator, VPN, notification and install-unknown-apps privileges.

Consider Advanced Protection if you are high risk

Google recommends its Advanced Protection Program for people at elevated risk of targeted online attacks, including journalists, activists, campaign staff, business leaders and IT administrators. It strengthens account sign-in and applies additional controls, but it does not make a phone invulnerable or replace timely device patches and expert incident response.

What to do if you may be a targeted person

  1. Move the conversation. Contact a trusted security specialist from another known-clean device. Do not discuss the suspected compromise only through the phone in question.
  2. Preserve the trigger. Keep suspicious messages, links, sender details, warning emails and timestamps. Do not forward an active link casually to colleagues.
  3. Avoid destructive changes before advice. A factory reset, app cleanup or operating-system reinstall may destroy forensic evidence. Ask the investigator what to preserve first.
  4. Reduce immediate exposure. Follow the responder’s guidance about powering down, isolating or replacing the device. The correct choice depends on safety needs and evidence collection.
  5. Protect related accounts. From a clean device, review sessions and recovery settings and change credentials where the incident responder recommends it.
  6. Document impact. List sensitive accounts, sources, contacts, locations and organizational systems that the phone could access.
  7. Plan communications. Coordinate legal, security and public statements. An early unsupported accusation can harm an investigation or expose other targets.

If you face immediate physical danger, prioritize personal safety and contact an appropriate trusted organization. Technical evidence collection should not put a person at greater risk.

What Mobile Verification Toolkit can and cannot do

Mobile Verification Toolkit (MVT) is an open-source project created by Amnesty International’s Security Lab for consensual forensic analysis of Android and iOS devices. Its documentation explains how analysts collect supported artifacts and compare them with indicators of compromise.

MVT is not a one-click “Pegasus scanner.” The current Android methodology notes that Android forensic sources can be limited and inconsistent across versions and manufacturers. The project has removed its older direct ADB analysis workflow and documents collection through supported artifacts such as AndroidQF output and bug reports.

Important limitations include:

  • a lack of findings does not prove a device was never compromised;
  • an indicator match needs context and corroboration;
  • public indicators may not cover a new or private campaign;
  • collection itself can change device state;
  • results may expose sensitive contacts, messages and browsing data;
  • chain of custody matters if evidence may be used in legal or organizational proceedings.

Do not ask a random online service to analyze a full phone backup. That backup may contain more sensitive information than the suspected attacker already obtained.

Where high-risk civil-society users can seek help

Amnesty International’s Security Lab publishes targeted-surveillance research and provides access to digital-forensics resources. Access Now’s Digital Security Helpline offers free, 24/7 technical support for eligible civil-society users, including activists, journalists, bloggers, human-rights defenders and media organizations.

Contact an organization through the address on its official domain and do so from a device you reasonably trust. Explain your risk context and evidence without sending confidential archives until the responder establishes a secure process.

A safe organizational readiness exercise

Organizations supporting high-risk staff can prepare without collecting exploit details:

  1. identify who receives a targeted-threat report;
  2. maintain a second secure contact channel;
  3. keep an inventory of devices and patch-support dates;
  4. define when a replacement device is issued;
  5. name an approved digital-forensics partner;
  6. write evidence-preservation and data-minimization rules;
  7. practice a tabletop scenario involving one suspected phone;
  8. record lessons and update the plan.

Continue with MetaCyberGuru’s free cybersecurity course for structured lessons on identity, networks, monitoring, vulnerability management and incident response.

Frequently asked questions

Can Pegasus infect Android without a click?

Zero-click mobile-spyware chains have been documented. Whether a specific device and version were vulnerable depends on the campaign, software and patch state. “No click” is not proof of infection, and “I clicked nothing” does not rule it out.

Can antivirus detect Pegasus?

A security product may detect some known artifacts, but sophisticated targeted spyware requires careful forensic analysis. No single consumer scan can prove a phone is clean.

Should I factory-reset immediately?

If evidence or legal accountability matters, obtain expert advice first because a reset can destroy artifacts. If you cannot obtain help and face immediate safety risk, prioritize safety and secure critical accounts from another trusted device.

Does end-to-end encryption stop Pegasus?

Encryption protects content in transit between endpoints. If an endpoint is compromised, spyware may access content where it is displayed or stored.

Is unusual battery drain evidence?

No. It is a reason to investigate battery health and app use, not a diagnosis of Pegasus. Forensic evidence and context are required.

Authoritative resources

Safety note: This is defensive information for device owners and authorized responders. It deliberately omits exploit instructions and does not claim to diagnose any device.

Similar Posts

Leave a Reply