Pegasus and Commercial Spyware: Threat Modeling, MVT Forensic Toolkit, and Indicators of Compromise
How investigative journalists detect mercenary surveillance payloads: inspecting iOS and Android system dumps with Amnesty's Mobile Verification Toolkit (MVT) to uncover zero-click exploits.
The proliferation of military-grade commercial spywareβmost notoriously NSO Groupβs Pegasus, Candiruβs DevilsTongue, and Intellexaβs Predatorβhas permanently altered the threat model for investigative journalists, political dissidents, and human rights lawyers worldwide.
Sold to sovereign intelligence agencies and law enforcement bodies, these cyberweapons operate far beyond the capabilities of consumer malware. They do not require the target to click a suspicious link, open an attachment, or answer a phone call.
Instead, they deliver zero-click remote exploits that weaponize zero-day vulnerabilities in core mobile operating system daemons (such as Appleβs iMessage, WebKit, or Androidβs stagefright graphics libraries). Within seconds of a silent invisible transmission, the spyware achieves complete root privileges: silently activating the phoneβs microphone, turning on the camera, copying PGP keyrings, recording WhatsApp and Signal calls, and exfiltrating GPS location coordinates in real time.
This manual provides an operational technical guide for understanding mercenary spyware architectures, extracting raw mobile system forensics, and running Amnesty Internationalβs open-source Mobile Verification Toolkit (MVT) to detect Indicators of Compromise (IOCs).
1. The Weaponization of the Zero-Click Exploit
The defining characteristic of state mercenary spyware is the zero-click infection vector:
THE ZERO-CLICK INFECTION CYCLE
β
[ADVERSARY COMMAND CENTER] βββββββββββββΌβββββββββββββΊ [TARGET SMARTPHONE]
β
βββββββββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββββββββ
βΌ βΌ
SILENT INGESTION SANDBOX ESCAPE
β’ Malicious invisible iMessage β’ Exploits integer overflow in PDF
β’ No notification; no screen wake β’ Bypasses Apple BlastDoor sandbox
β’ Device does not ring or buzz β’ Achieves kernel memory execution
β β
βββββββββββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββ
βΌ
[TOTAL DEVICE COMPROMISE]
β’ Root privilege attained
β’ Live microphone tapping
β’ Full Signal & WhatsApp exfiltration
β’ Evidence tracks wiped from logs
Case in Point: FORCEDENTRY and Megalodon
Exploit chains such as FORCEDENTRY bypassed Appleβs hardened iMessage sandbox (BlastDoor) by transmitting a malicious 28-byte GIF file that was actually an encoded Adobe Photoshop PDF containing an emulation of an obsolete 1990s Xerox JBIG2 compression decompression algorithm. The decompression routine triggered an integer overflow that allowed arbitrary code execution, bootstrapping full system infection without any user interaction whatsoever.
2. Threat Modeling: Are You a High-Value Target?
Mercenary spyware is astronomically expensive. A single zero-click exploit chain typically costs between \$1.5 million and \$3 million on the gray cyber-arms market, and vendor service contracts routinely exceed \$10 million annually.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β MERCENARY SPYWARE TARGETING TIERS β
ββββββββββββββββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββ€
β HIGH-RISK PROFILES β STANDARD INVESTIGATIVE RISK β
β β’ Cross-border corruption reportersβ β’ Local municipal reporting β
β β’ State defense & arms monitors β β’ Standard public records queries β
β β’ Political dissidents in exile β β’ Phishing & credential harvestingβ
β β’ Lawyers defending high-profile β β’ Device seizure at protests β
β political prisoners β β’ Commercial data brokers β
ββββββββββββββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββββββββββββ
If your reporting investigates state intelligence misconduct, cross-border arms smuggling, sovereign financial corruption, or authoritarian leadership circles, you must assume your smartphone is an active target for zero-click surveillance.
3. Forensic Detection: Deploying Mobile Verification Toolkit (MVT)
Because mercenary spyware is designed to erase its temporary installation files, detecting infection requires deep inspection of historical system diagnostic databases, SMS caches, and safari WebKit records.
The global standard tool for this analysis is MVT (Mobile Verification Toolkit), an open-source forensic Python framework developed by Amnesty International Security Lab.
[TARGET IPHONE] βββΊ [ENCRYPTED ITUNES BACKUP] βββΊ [MVT BACKUP DECRYPT] βββΊ [IOC SIGNATURE SCAN] βββΊ [EVIDENTIARY REPORT]
Step 1: Generate an Encrypted Full Backup (iOS)
Forensic extraction requires an encrypted backup, because unencrypted backups omit sensitive system health logs, Wi-Fi history, and diagnostic SQLite databases:
# On a hardened Linux or macOS workstation, create a local backup via libimobiledevice:
idevicebackup2 backup --full /path/to/backup_folder/
Step 2: Install and Configure MVT
# Install MVT via Python pip
pip3 install mvt
# Download the latest open-source Indicators of Compromise (STIX 2.0 format)
git clone https://github.com/AmnestyTech/investigations.git
Step 3: Run the Forensic Analysis Pipeline
# Decrypt the encrypted iOS backup for processing
mvt-ios decrypt-backup -p "YOUR_BACKUP_PASSWORD" -d /path/to/decrypted_output/ /path/to/backup_folder/
# Execute MVT forensic extraction and match against Amnesty's Pegasus IOCs
mvt-ios check-backup --iocs investigations/2021-07-18_pegasus/pegasus.stix2 \
--output /path/to/forensic_results/ \
/path/to/decrypted_output/
4. Reading the Artifacts: What MVT Flags
When MVT scans an iOS backup, it parses dozens of internal system SQLite databases, flagging anomalies that indicate zero-click compromise:
SAMPLE MVT DETECTION MANIFEST:
[!] MATCH DETECTED in DataUsage.sqlite:
Process: "/private/var/mobile/Containers/Data/Application/..."
Suspicious Daemon: "com.apple.imfoundation.IMRemoteURLConnectionAgent"
Domain: "142.93.18.24" (Known NSO Group Command & Control Domain)
First Seen: 2026-09-14 03:22:18 UTC
[!] ANOMALOUS SAFARI ARTIFACT in Safari/History.db:
Redirect Chain: "whatsapp://..." -> "https://free-updates-service.net/install"
Suspicious User-Agent: "CFNetwork/1126"
Key Artifacts Inspected:
DataUsage.sqlite: Logs every background daemon and network process that transmitted bytes over cellular or Wi-Fi networks. Spyware processes (often masquerading as fake Apple daemons likelaunchdormediaanalysisd) appear transmitting hundreds of megabytes during early morning hours.InteractionC.sqlite: Records every contact interaction and notification. If an incoming message record exists without an associated audio chime or visual banner notification, an invisible zero-click payload was ingested.Safari/History.dband WebKit LocalStorage: Uncovers malicious browser redirects triggered silently by network-injection attacks or rogue cell-site simulators.
5. Defensive Countermeasures: Mitigating Advanced Spyware
Defeating state-sponsored zero-click attacks is technically challenging, but specific operational protocols drastically reduce your attack surface:
DEFENSIVE HYGIENE PYRAMID:
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 1. ACTIVATE APPLE LOCKDOWN MODE β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β 2. SCHEDULE DAILY SMARTPHONE REBOOTS (08:00 & 20:00) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β 3. DISABLE IMESSAGE & FACETIME ON SENSITIVE DEVICES β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β 4. ISOLATE LAPTOP REPORTING FROM MOBILE MESSAGING β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
1. Apple Lockdown Mode
Introduced in iOS 16, Lockdown Mode is the most effective commercial defense against mercenary spyware: * It completely disables complex font parsing, blocks incoming message attachments (except images), strips JIT (Just-In-Time) JavaScript compilation in Safari, and blocks incoming FaceTime calls from unknown numbers. * Citizen Lab testing confirms that Lockdown Mode successfully blocked multiple live Pegasus and Predator zero-click exploit attempts.
2. The Daily Reboot Defense
Because modern mobile operating systems enforce hardened read-only root filesystems, commercial spyware often avoids writing persistent binaries to disk to escape detection. Instead, it runs entirely in volatile RAM. * The Routine: Reboot your smartphone every morning and every evening. * A reboot flushes system memory, terminating the active spyware process. The adversary is forced to expend another high-risk zero-click exploit to re-infect your device.
By understanding the technical anatomy of targeted spyware and regularly auditing devices with MVT, investigative newsrooms maintain the cryptographic sovereignty necessary to protect their most vulnerable sources.
How to Detect Mercenary Spyware Using Mobile Verification Toolkit (MVT)
Forensic procedure for extracting iOS and Android system dumps and scanning for zero-click exploit indicators of compromise.
- Create an Encrypted Full Device Backup: Use libimobiledevice to generate a full encrypted backup capturing diagnostic system databases.
- Install and Configure MVT with Latest STIX2 IOCs: Download Amnesty International's latest Pegasus and Predator threat indicators.
- Decrypt and Parse System SQLite Databases: Run mvt-ios to inspect DataUsage.sqlite, InteractionC.sqlite, and Safari local storage.
- Activate Lockdown Mode and Daily Reboot Cadence: Harden mobile devices against incoming zero-click payloads by turning on Apple Lockdown Mode and scheduling twice-daily reboots.
Frequently Asked Verification Questions
Key technical principles, error traps, and diagnostic standards for investigative researchers.
What makes Pegasus spyware different from standard phone malware?
How does Apple Lockdown Mode protect journalists from zero-click exploits?
Inspect Diagnostic Metadata & Hash File Dumps
Audit binary file headers, calculate SHA-256 evidence digests in local memory, and verify system log timestamps without uploading data.
About the Contributor
The Dawat Forensic Research Desk specializes in open-source investigative intelligence, conflict zone media verification, and digital human rights documentation.
Related Research & Dispatches
Physical Surveillance Countermeasures: Surveillance Detection Routes and Dead-Drop Hygiene for Field Reporters
Operational tradecraft for high-threat reporting: executing Surveillance Detection Routes (SDR), managing phys...
Commercial Satellite Resolution Guide: Maxar, PlanetScope, Sentinel-2, and Synthetic Aperture Radar
A comparative buyer and investigative handbook for procuring orbital imagery: evaluating ground sample distanc...
Air-Gapped Cold Storage: Architecting Isolated Workstations for High-Risk Whistleblower Dossiers
How to engineer physically isolated, air-gapped computers: removing internal wireless modems, defeating acoust...