Monday, April 28, 2025
HomeAndroidHackers using Android & iOS Spyware "Pegasus" to Conducting Massive Surveillance...

Hackers using Android & iOS Spyware “Pegasus” to Conducting Massive Surveillance Operations in 45 Countries

Published on

SIEM as a Service

Follow Us on Google News

New research reveals that Israel based NSO Group using powerful mobile based Pegasus Spyware to conducting massive surveillance in 45 countries across the globe.

NSO Group is operating from Israel where they produce and sells a mobile phone spyware named as Pegasus to governments and private entities to perform massive Surveillance operation in order to gain sensitive information from the targeted victims.

Pegasus spyware previous operation launched against UAE activist Ahmed Mansoor in Aug 2016 which contains a Zero-day exploit for the Apple iPhone along with Spyware that targets his iPhone 6 to spying his Phone activities.

- Advertisement - Google News

NSO Group basically operating as a “cyber war” company that sells Pegasus spyware to government agencies and private firms as a “lawful intercept” software.

Researchers believe that at least 10 Pegasus operators appear to be actively engaged behind this Surveillance operation across the 45 countries.

Pegasus spyware is one of the most sophisticated and powerful spyware that perform various malicious activities in both android and iPhone such as stealing private data, including passwords, contact lists, calendar events, text messages, and live voice calls from popular mobile messaging apps.

As of now, researchers discovered 36 distinct Pegasus systems and each one perhaps run by a separate operator and they suspect the Pegasus infections associated with 33 of the 36 Pegasus operators and they Surveillance 45 Following Countries.

Algeria, Bahrain, Bangladesh, Brazil, Canada, Cote d’Ivoire, Egypt, France, Greece, India, Iraq, Israel, Jordan, Kazakhstan, Kenya, Kuwait, Kyrgyzstan, Latvia, Lebanon, Libya, Mexico, Morocco, the Netherlands, Oman, Pakistan, Palestine, Poland, Qatar, Rwanda, Saudi Arabia, Singapore, South Africa, Switzerland, Tajikistan, Thailand, Togo, Tunisia, Turkey, the UAE, Uganda, the United Kingdom, the United States, Uzbekistan, Yemen, and Zambia

Pegasus Spyware Surveillance Operation

Researchers developed a new technique called Athena found 1,091 IP addresses matched with the fingerprint and 1,014 domain names are pointed to the  NSO Group.

Later on, the countries that are under Surveillance was identified by conducting a global DNS Cache Probing study on the matching domain names which helps to find in which countries each operator was spying.

According to citizen lab research, To monitor a target, a government operator of Pegasus must convince the target to click on a specially crafted exploit link, which, when clicked, delivers a chain of zero-day exploits to penetrate security features on the phone and installs Pegasus without the user’s knowledge or permission.

After the successful exploitation of the phone, it starts communicating with the operator via command & controls sever in order to receive further operation command.

Communication is established to the Pegasus spyware via HTTPS request and it requires operators to register and maintain domain names.

Domain names that used to exploit links mimic as mobile providers, online services, banks, and government services

An operator may have several domain names that they use in exploit links they send, and also have several domain names they use for C&C. The domain names often resolve to cloud-based virtual private servers (we call these front-end servers) rented either by NSO Group or the operator. Researchers said.

NSO Group Denied

In this case, NSO Group Denied the citizen lab findings and said, “There are multiple problems with Citizen Lab’s latest report. Most significantly, the list of countries  in which NSO is alleged to operate is simply inaccurate.”

“NSO does not operate in many of the countries listed. The product is only licensed to operate in countries approved under our Business Ethics Framework and the product will not operate outside of approved countries”

Also Read:

Spyware Company Got Hacked – Attackers Stole Login Credentials, Audio Recordings, Pictures, and Text Messages

Sophisticated Spyware Attack on Military Mobile Devices to Record Phone Calls & Take a Picture

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

North Korean APT Hackers Pose as Companies to Spread Malware to Job Seekers

Silent Push Threat Analysts have uncovered a chilling new cyberattack campaign orchestrated by the...

Russian VPS Servers With RDP and Proxy Servers Enable North Korean Cybercrime Operations

Trend Research has uncovered a sophisticated network of cybercrime operations linked to North Korea,...

Hackers Exploit Ivanti Connect Secure 0-Day to Deploy DslogdRAT and Web Shell

Threat actors exploited a zero-day vulnerability in Ivanti Connect Secure, identified as CVE-2025-0282, to...