Pegasus Spyware on Android: Risks, Detection and Response
Pegasus is sophisticated commercial spyware associated with NSO Group and documented by research organizations including Citizen Lab and Amnesty International’s Security Lab. It has been used in highly targeted surveillance operations against phones, including devices belonging to journalists, activists and human-rights defenders.
This defensive guide explains infection concepts at a safe level, why common “symptoms” cannot diagnose Pegasus, what ordinary Android users can do, and how a person at elevated risk should preserve evidence and obtain expert help. It does not include exploit code, infrastructure indicators that could expose an investigation, or instructions for deploying spyware.
Pegasus is a targeted-surveillance problem
Pegasus should not be used as a catch-all label for every suspicious battery, advertisement or unknown Android app. Public investigations describe an expensive, operator-driven surveillance capability used against selected targets. That threat model differs from commodity adware distributed through mass downloads.
A useful risk assessment considers:
- whether the person is a journalist, activist, lawyer, political figure, researcher or another high-risk individual;
- whether a state or well-resourced actor has a reason to target their communications;
- whether colleagues or members of the same community have received suspicious links or confirmed warnings;
- whether the device contains information valuable enough to justify an expensive operation;
- whether a qualified lab has found technical indicators rather than only unusual phone behavior.
A low likelihood does not make basic security unnecessary. Updating a phone and protecting accounts reduces many common attacks even when Pegasus is not the probable explanation.
How targeted mobile spyware can reach a phone
Documented mobile-spyware campaigns have used more than one delivery path. Exact exploit chains change as vulnerabilities are discovered and patched, so a timeless list of “the Pegasus methods” would be misleading.
One-click targeting
The target receives a carefully designed message containing a link. The destination may imitate a news story, delivery notice, security alert or account page connected to the person’s work. Visiting it can expose the device to an exploit chain. Social context matters: a tailored message from an apparently relevant sender is more persuasive than obvious spam.
Zero-click exploitation
A zero-click chain does not require the owner to tap a link. It may target software that automatically receives and processes network content, such as a messaging or calling component. This is why “I never clicked anything” does not rule out sophisticated compromise and why timely operating-system and application patches matter.
Network and physical-access scenarios
Research over the years has also described infection or redirection scenarios involving network position or direct device access. The relevance depends on the campaign, device and date. Defenders should not turn these broad categories into a claim about one phone without forensic evidence.
What happens after compromise
Research reports describe capabilities that can collect communications, files, location and device data and, under some conditions, access sensors. End-to-end encryption protects messages while they travel between endpoints; it cannot protect content after an endpoint itself is compromised and displays or stores that content.
Battery drain is not proof of Pegasus
Fast battery loss, heat, crashes and higher data use have many ordinary causes: an aging battery, poor signal, a system update, media backup, a broken app or legitimate background work. Sophisticated spyware is designed to avoid obvious signs, and a clean-looking phone is not proof that no compromise occurred.
| Observation | What it can justify | What it cannot prove |
|---|---|---|
| Battery or heat change | Check battery health and per-app usage | Attribution to Pegasus |
| Unexpected account login | Secure the account and preserve the alert | That the phone operating system was infected |
| Suspicious tailored link | Do not open; preserve and request expert triage | That successful infection occurred |
| Official threat notification | Take the warning seriously and seek specialized help | The exact exploit without further analysis |
| Unknown app | Verify publisher, install source and permissions | That it is Pegasus rather than another app or system component |
| Forensic indicator match | Requires expert interpretation and corroboration | A final conclusion by itself |
Reliable conclusions come from multiple artifacts, validated indicators, timestamps and an understood collection method. A consumer antivirus result alone is not a complete forensic examination.
Practical protection for Android users
Install operating-system and security updates
Google’s Android help documentation shows where to check the Android version, security update and Google Play system update. Install updates available for the device. Update schedules vary by manufacturer and carrier; if a phone no longer receives security patches, move sensitive work to a supported device.
Reduce message and account exposure
- Do not open unexpected links, even when the message uses real names or current events.
- Confirm unusual requests through a separate, known channel.
- Use a password manager and unique passwords so one stolen credential does not unlock other accounts.
- Use passkeys or hardware-backed security keys where suitable.
- Review active account sessions and recovery details.
- Limit sensitive information in notifications visible on the lock screen.
Keep the device in its supported security model
Avoid unknown app stores, untrusted APK files and unnecessary rooting. Google warns that modified Android versions can lose built-in protections and automatic security updates. Review apps with accessibility, device-administrator, VPN, notification and install-unknown-apps privileges.
Consider Advanced Protection if you are high risk
Google recommends its Advanced Protection Program for people at elevated risk of targeted online attacks, including journalists, activists, campaign staff, business leaders and IT administrators. It strengthens account sign-in and applies additional controls, but it does not make a phone invulnerable or replace timely device patches and expert incident response.
What to do if you may be a targeted person
- Move the conversation. Contact a trusted security specialist from another known-clean device. Do not discuss the suspected compromise only through the phone in question.
- Preserve the trigger. Keep suspicious messages, links, sender details, warning emails and timestamps. Do not forward an active link casually to colleagues.
- Avoid destructive changes before advice. A factory reset, app cleanup or operating-system reinstall may destroy forensic evidence. Ask the investigator what to preserve first.
- Reduce immediate exposure. Follow the responder’s guidance about powering down, isolating or replacing the device. The correct choice depends on safety needs and evidence collection.
- Protect related accounts. From a clean device, review sessions and recovery settings and change credentials where the incident responder recommends it.
- Document impact. List sensitive accounts, sources, contacts, locations and organizational systems that the phone could access.
- Plan communications. Coordinate legal, security and public statements. An early unsupported accusation can harm an investigation or expose other targets.
If you face immediate physical danger, prioritize personal safety and contact an appropriate trusted organization. Technical evidence collection should not put a person at greater risk.
What Mobile Verification Toolkit can and cannot do
Mobile Verification Toolkit (MVT) is an open-source project created by Amnesty International’s Security Lab for consensual forensic analysis of Android and iOS devices. Its documentation explains how analysts collect supported artifacts and compare them with indicators of compromise.
MVT is not a one-click “Pegasus scanner.” The current Android methodology notes that Android forensic sources can be limited and inconsistent across versions and manufacturers. The project has removed its older direct ADB analysis workflow and documents collection through supported artifacts such as AndroidQF output and bug reports.
Important limitations include:
- a lack of findings does not prove a device was never compromised;
- an indicator match needs context and corroboration;
- public indicators may not cover a new or private campaign;
- collection itself can change device state;
- results may expose sensitive contacts, messages and browsing data;
- chain of custody matters if evidence may be used in legal or organizational proceedings.
Do not ask a random online service to analyze a full phone backup. That backup may contain more sensitive information than the suspected attacker already obtained.
Where high-risk civil-society users can seek help
Amnesty International’s Security Lab publishes targeted-surveillance research and provides access to digital-forensics resources. Access Now’s Digital Security Helpline offers free, 24/7 technical support for eligible civil-society users, including activists, journalists, bloggers, human-rights defenders and media organizations.
Contact an organization through the address on its official domain and do so from a device you reasonably trust. Explain your risk context and evidence without sending confidential archives until the responder establishes a secure process.
A safe organizational readiness exercise
Organizations supporting high-risk staff can prepare without collecting exploit details:
- identify who receives a targeted-threat report;
- maintain a second secure contact channel;
- keep an inventory of devices and patch-support dates;
- define when a replacement device is issued;
- name an approved digital-forensics partner;
- write evidence-preservation and data-minimization rules;
- practice a tabletop scenario involving one suspected phone;
- record lessons and update the plan.
Continue with MetaCyberGuru’s free cybersecurity course for structured lessons on identity, networks, monitoring, vulnerability management and incident response.
Frequently asked questions
Can Pegasus infect Android without a click?
Zero-click mobile-spyware chains have been documented. Whether a specific device and version were vulnerable depends on the campaign, software and patch state. “No click” is not proof of infection, and “I clicked nothing” does not rule it out.
Can antivirus detect Pegasus?
A security product may detect some known artifacts, but sophisticated targeted spyware requires careful forensic analysis. No single consumer scan can prove a phone is clean.
Should I factory-reset immediately?
If evidence or legal accountability matters, obtain expert advice first because a reset can destroy artifacts. If you cannot obtain help and face immediate safety risk, prioritize safety and secure critical accounts from another trusted device.
Does end-to-end encryption stop Pegasus?
Encryption protects content in transit between endpoints. If an endpoint is compromised, spyware may access content where it is displayed or stored.
Is unusual battery drain evidence?
No. It is a reason to investigate battery health and app use, not a diagnosis of Pegasus. Forensic evidence and context are required.
Authoritative resources
- Mobile Verification Toolkit documentation
- MVT Android forensic methodology and limitations
- Citizen Lab: independently confirmed Pegasus cases and methodology
- Google: check Android and security updates
- Google Advanced Protection Program
- Access Now Digital Security Helpline
Safety note: This is defensive information for device owners and authorized responders. It deliberately omits exploit instructions and does not claim to diagnose any device.






