Journal of Independent Cultural Commentary

DAWAT FREE MEDIA

Promoting independent discourse, regional literature, and historical research across borders.

Targeted Spyware Forensics

Pegasus and Commercial Spyware: Threat Modeling, MVT Forensic Toolkit, and Indicators of Compromise

How investigative journalists detect mercenary surveillance payloads: inspecting iOS and Android system dumps with Amnesty's Mobile Verification Toolkit (MVT) to uncover zero-click exploits.

Technical diagram of mercenary spyware zero-click exploit delivery, BlastDoor sandbox bypasses, and MVT forensic timeline analysis.
Auditing commercial spyware: parsing iOS sysdiagnose dumps, detecting malicious WebKit artifacts, and isolating NSO Group Pegasus Indicators of Compromise via MVT. (Illustration: Dawat Research Desk)

The proliferation of military-grade commercial spywareβ€”most notoriously NSO Group’s Pegasus, Candiru’s DevilsTongue, and Intellexa’s Predatorβ€”has permanently altered the threat model for investigative journalists, political dissidents, and human rights lawyers worldwide.

Sold to sovereign intelligence agencies and law enforcement bodies, these cyberweapons operate far beyond the capabilities of consumer malware. They do not require the target to click a suspicious link, open an attachment, or answer a phone call.

Instead, they deliver zero-click remote exploits that weaponize zero-day vulnerabilities in core mobile operating system daemons (such as Apple’s iMessage, WebKit, or Android’s stagefright graphics libraries). Within seconds of a silent invisible transmission, the spyware achieves complete root privileges: silently activating the phone’s microphone, turning on the camera, copying PGP keyrings, recording WhatsApp and Signal calls, and exfiltrating GPS location coordinates in real time.

This manual provides an operational technical guide for understanding mercenary spyware architectures, extracting raw mobile system forensics, and running Amnesty International’s open-source Mobile Verification Toolkit (MVT) to detect Indicators of Compromise (IOCs).


1. The Weaponization of the Zero-Click Exploit

The defining characteristic of state mercenary spyware is the zero-click infection vector:

                              THE ZERO-CLICK INFECTION CYCLE
                                             β”‚
      [ADVERSARY COMMAND CENTER] ────────────┼────────────► [TARGET SMARTPHONE]
                                             β”‚
             β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
             β–Ό                                                               β–Ό
      SILENT INGESTION                                                SANDBOX ESCAPE
   β€’ Malicious invisible iMessage                                  β€’ Exploits integer overflow in PDF
   β€’ No notification; no screen wake                               β€’ Bypasses Apple BlastDoor sandbox
   β€’ Device does not ring or buzz                                  β€’ Achieves kernel memory execution
             β”‚                                                               β”‚
             β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                             β–Ό
                                [TOTAL DEVICE COMPROMISE]
                             β€’ Root privilege attained
                             β€’ Live microphone tapping
                             β€’ Full Signal & WhatsApp exfiltration
                             β€’ Evidence tracks wiped from logs

Case in Point: FORCEDENTRY and Megalodon

Exploit chains such as FORCEDENTRY bypassed Apple’s hardened iMessage sandbox (BlastDoor) by transmitting a malicious 28-byte GIF file that was actually an encoded Adobe Photoshop PDF containing an emulation of an obsolete 1990s Xerox JBIG2 compression decompression algorithm. The decompression routine triggered an integer overflow that allowed arbitrary code execution, bootstrapping full system infection without any user interaction whatsoever.


2. Threat Modeling: Are You a High-Value Target?

Mercenary spyware is astronomically expensive. A single zero-click exploit chain typically costs between \$1.5 million and \$3 million on the gray cyber-arms market, and vendor service contracts routinely exceed \$10 million annually.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                   MERCENARY SPYWARE TARGETING TIERS                    β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ HIGH-RISK PROFILES                 β”‚ STANDARD INVESTIGATIVE RISK       β”‚
β”‚ β€’ Cross-border corruption reportersβ”‚ β€’ Local municipal reporting       β”‚
β”‚ β€’ State defense & arms monitors    β”‚ β€’ Standard public records queries β”‚
β”‚ β€’ Political dissidents in exile    β”‚ β€’ Phishing & credential harvestingβ”‚
β”‚ β€’ Lawyers defending high-profile   β”‚ β€’ Device seizure at protests      β”‚
β”‚   political prisoners              β”‚ β€’ Commercial data brokers         β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

If your reporting investigates state intelligence misconduct, cross-border arms smuggling, sovereign financial corruption, or authoritarian leadership circles, you must assume your smartphone is an active target for zero-click surveillance.


3. Forensic Detection: Deploying Mobile Verification Toolkit (MVT)

Because mercenary spyware is designed to erase its temporary installation files, detecting infection requires deep inspection of historical system diagnostic databases, SMS caches, and safari WebKit records.

The global standard tool for this analysis is MVT (Mobile Verification Toolkit), an open-source forensic Python framework developed by Amnesty International Security Lab.

[TARGET IPHONE] ──► [ENCRYPTED ITUNES BACKUP] ──► [MVT BACKUP DECRYPT] ──► [IOC SIGNATURE SCAN] ──► [EVIDENTIARY REPORT]

Step 1: Generate an Encrypted Full Backup (iOS)

Forensic extraction requires an encrypted backup, because unencrypted backups omit sensitive system health logs, Wi-Fi history, and diagnostic SQLite databases:

# On a hardened Linux or macOS workstation, create a local backup via libimobiledevice:
idevicebackup2 backup --full /path/to/backup_folder/

Step 2: Install and Configure MVT

# Install MVT via Python pip
pip3 install mvt

# Download the latest open-source Indicators of Compromise (STIX 2.0 format)
git clone https://github.com/AmnestyTech/investigations.git

Step 3: Run the Forensic Analysis Pipeline

# Decrypt the encrypted iOS backup for processing
mvt-ios decrypt-backup -p "YOUR_BACKUP_PASSWORD" -d /path/to/decrypted_output/ /path/to/backup_folder/

# Execute MVT forensic extraction and match against Amnesty's Pegasus IOCs
mvt-ios check-backup --iocs investigations/2021-07-18_pegasus/pegasus.stix2 \
  --output /path/to/forensic_results/ \
  /path/to/decrypted_output/

4. Reading the Artifacts: What MVT Flags

When MVT scans an iOS backup, it parses dozens of internal system SQLite databases, flagging anomalies that indicate zero-click compromise:

SAMPLE MVT DETECTION MANIFEST:
[!] MATCH DETECTED in DataUsage.sqlite:
    Process: "/private/var/mobile/Containers/Data/Application/..."
    Suspicious Daemon: "com.apple.imfoundation.IMRemoteURLConnectionAgent"
    Domain: "142.93.18.24" (Known NSO Group Command & Control Domain)
    First Seen: 2026-09-14 03:22:18 UTC

[!] ANOMALOUS SAFARI ARTIFACT in Safari/History.db:
    Redirect Chain: "whatsapp://..." -> "https://free-updates-service.net/install"
    Suspicious User-Agent: "CFNetwork/1126"

Key Artifacts Inspected:

  1. DataUsage.sqlite: Logs every background daemon and network process that transmitted bytes over cellular or Wi-Fi networks. Spyware processes (often masquerading as fake Apple daemons like launchd or mediaanalysisd) appear transmitting hundreds of megabytes during early morning hours.
  2. InteractionC.sqlite: Records every contact interaction and notification. If an incoming message record exists without an associated audio chime or visual banner notification, an invisible zero-click payload was ingested.
  3. Safari/History.db and WebKit LocalStorage: Uncovers malicious browser redirects triggered silently by network-injection attacks or rogue cell-site simulators.

5. Defensive Countermeasures: Mitigating Advanced Spyware

Defeating state-sponsored zero-click attacks is technically challenging, but specific operational protocols drastically reduce your attack surface:

DEFENSIVE HYGIENE PYRAMID:
  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
  β”‚  1. ACTIVATE APPLE LOCKDOWN MODE                       β”‚
  β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
  β”‚  2. SCHEDULE DAILY SMARTPHONE REBOOTS (08:00 & 20:00)  β”‚
  β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
  β”‚  3. DISABLE IMESSAGE & FACETIME ON SENSITIVE DEVICES   β”‚
  β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
  β”‚  4. ISOLATE LAPTOP REPORTING FROM MOBILE MESSAGING     β”‚
  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

1. Apple Lockdown Mode

Introduced in iOS 16, Lockdown Mode is the most effective commercial defense against mercenary spyware: * It completely disables complex font parsing, blocks incoming message attachments (except images), strips JIT (Just-In-Time) JavaScript compilation in Safari, and blocks incoming FaceTime calls from unknown numbers. * Citizen Lab testing confirms that Lockdown Mode successfully blocked multiple live Pegasus and Predator zero-click exploit attempts.

2. The Daily Reboot Defense

Because modern mobile operating systems enforce hardened read-only root filesystems, commercial spyware often avoids writing persistent binaries to disk to escape detection. Instead, it runs entirely in volatile RAM. * The Routine: Reboot your smartphone every morning and every evening. * A reboot flushes system memory, terminating the active spyware process. The adversary is forced to expend another high-risk zero-click exploit to re-infect your device.

By understanding the technical anatomy of targeted spyware and regularly auditing devices with MVT, investigative newsrooms maintain the cryptographic sovereignty necessary to protect their most vulnerable sources.

Standard Operating Procedure Step-by-Step Field Protocol

How to Detect Mercenary Spyware Using Mobile Verification Toolkit (MVT)

Forensic procedure for extracting iOS and Android system dumps and scanning for zero-click exploit indicators of compromise.

  1. Create an Encrypted Full Device Backup: Use libimobiledevice to generate a full encrypted backup capturing diagnostic system databases.
  2. Install and Configure MVT with Latest STIX2 IOCs: Download Amnesty International's latest Pegasus and Predator threat indicators.
  3. Decrypt and Parse System SQLite Databases: Run mvt-ios to inspect DataUsage.sqlite, InteractionC.sqlite, and Safari local storage.
  4. Activate Lockdown Mode and Daily Reboot Cadence: Harden mobile devices against incoming zero-click payloads by turning on Apple Lockdown Mode and scheduling twice-daily reboots.
Forensic Q&A

Frequently Asked Verification Questions

Key technical principles, error traps, and diagnostic standards for investigative researchers.

What makes Pegasus spyware different from standard phone malware?
Pegasus uses zero-click exploits that require no link clicking or interaction. It silently infects the phone via core background processes (like iMessage or WebKit) and gains root privileges without triggering visual alerts.
How does Apple Lockdown Mode protect journalists from zero-click exploits?
Lockdown Mode dramatically reduces the smartphone's attack surface by blocking incoming message attachments, disabling complex WebKit font parsing, turning off JIT JavaScript compilers, and blocking unsaved FaceTime invitations.
Binary Forensics & Evidence Integrity Zero Server Uploads β€’ 100% Private RAM

Inspect Diagnostic Metadata & Hash File Dumps

Audit binary file headers, calculate SHA-256 evidence digests in local memory, and verify system log timestamps without uploading data.

Launch Deep Metadata Inspector β†’ Verification Navigator β†’

About the Contributor

The Dawat Forensic Research Desk specializes in open-source investigative intelligence, conflict zone media verification, and digital human rights documentation.

Curated Intelligence

Related Research & Dispatches

View Complete Investigative Archive β†’