Pegasus is commercial spyware developed by NSO Group, an Israeli surveillance technology company. In 2026, Citizen Lab researchers at the University of Toronto confirmed new zero-click iPhone exploit chains attributed to NSO Group infrastructure, infecting devices belonging to journalists, human rights attorneys, and civil society leaders across Europe, Latin America, the Middle East, and Southeast Asia. Zero-click exploits require no interaction from the target and can be delivered silently through iMessage, WhatsApp, or other messaging protocols.
Key Takeaways
- 1Citizen Lab documented active Pegasus infections in 2026 across four continents, targeting at least 47 individuals in 12 countries
- 2The new exploit chain operates via iMessage image processing and does not require the target to tap, open, or interact with any message
- 3Infected devices transmit real-time location, encrypted messages, photos, contact lists, and live microphone/camera feeds to operator servers
- 4Apple issued an emergency patch in response to Citizen Lab's disclosure, but attributed the vulnerability to a parsing flaw in iOS image rendering
- 5NSO Group remains on the U.S. Commerce Department Entity List, barring American companies from selling it software or services
- 6Pegasus has been linked to the surveillance of journalists investigating governments in Mexico, Saudi Arabia, Hungary, Azerbaijan, India, and Rwanda
Pegasus is the most thoroughly documented piece of commercial spyware in existence, yet it has proven nearly impossible to suppress. Despite a 2021 placement on the U.S. Entity List, ongoing litigation from Apple and Meta, and years of public exposure by Citizen Lab, the surveillance tool attributed to NSO Group continues to surface on the phones of journalists, lawyers, and activists around the world. The 2026 Citizen Lab report confirms that active Pegasus infrastructure is still operating, that new zero-click exploit chains have been developed and deployed, and that the target profile remains consistent: people who hold information that governments want access to.
What Is Pegasus | NSO Group and the Commercial Spyware Industry
NSO Group was founded in 2010 in Herzliya, Israel, by Niv Carmi, Shalev Hulio, and Omri Lavie. The company markets itself as a lawful intercept technology vendor, selling exclusively to government clients for the stated purpose of counterterrorism and serious crime investigations. Its flagship product, Pegasus, is a full-device surveillance implant capable of exfiltrating virtually all data stored on or transmitted through a target's smartphone.
Once installed, Pegasus operates silently with no visible indicator on the device. It can read encrypted messages from WhatsApp, Signal, Telegram, and iMessage after decryption, bypassing the encryption entirely by reading the data at rest. It can activate the microphone and camera without triggering any indicator light on modern iPhones, transmit GPS coordinates in real time, and log keystrokes. Forensic analysis by Citizen Lab and Amnesty International's Security Lab has confirmed these capabilities across dozens of device examinations.
The company maintains that it has no visibility into how clients use the tool once deployed, and that its Transparency and Responsibility Framework prohibits misuse. Independent researchers and courts in multiple jurisdictions have found this position unconvincing. A U.S. federal court in California ruled in 2024 that NSO Group could be held liable for WhatsApp users targeted through the platform, a decision NSO is appealing.
Citizen Lab's 2026 Report | What the New Evidence Shows
The 2026 Citizen Lab report, published by researchers at the University of Toronto's Munk School of Global Affairs, identifies new Pegasus operator infrastructure active between January and June 2026. Researchers mapped 34 distinct operator clusters — groups of servers, domains, and IP addresses consistent with NSO Group's known deployment architecture — and confirmed forensic Pegasus infections on 47 devices belonging to journalists, attorneys, and civil society figures.
The targets were distributed across 12 countries: Mexico, El Salvador, India, Jordan, Thailand, Azerbaijan, Rwanda, Hungary, Morocco, Spain, Greece, and Bahrain. The professional profile of confirmed victims included investigative journalists covering government corruption, defense attorneys in high-profile political trials, opposition party staff, and NGO workers focusing on human rights documentation.
Citizen Lab confirmed the presence of Pegasus using its Mobile Verification Toolkit (MVT), an open-source forensic tool that looks for known Pegasus indicators of compromise (IOCs) including specific process names, domain lookup patterns, data exfiltration signatures, and binary artifacts left in iOS crash logs and system diagnostic data.
How Zero-Click Exploits Work | The Technical Mechanism
A zero-click exploit is a software vulnerability that can be triggered without any action from the targeted user. There is no link to click, no attachment to open, no prompt to accept. The exploit is delivered through a standard communication channel, the vulnerability executes silently in the background, and the payload installs itself before the user has any indication something happened.
NSO Group's most documented zero-click chains have targeted vulnerabilities in the components that process incoming data before it ever reaches the user's screen. The FORCEDENTRY exploit (documented by Citizen Lab in 2021) used a flaw in Apple's CoreGraphics PDF renderer, triggered by a specially crafted iMessage image. BlastPass (2023) exploited a PassKit vulnerability through Apple Wallet attachment processing. Both required zero interaction.
The 2026 chain appears to target the ImageIO framework, which handles image decoding across multiple Apple system apps. Because ImageIO runs at a high privilege level and processes data from untrusted external sources by default, a parsing vulnerability in the library can be exploited to achieve remote code execution and then privilege escalation, ultimately allowing the attacker to install a persistent implant that survives a device reboot.
Apple's Lockdown Mode, introduced in iOS 16 as a hardened security setting for high-risk users, was specifically designed to reduce attack surface by disabling many of the message attachment features exploited by Pegasus. Citizen Lab's 2026 findings indicate at least three confirmed infections on devices with Lockdown Mode enabled, suggesting the new exploit chain targets a code path that Lockdown Mode does not currently restrict.
Who Was Targeted | The 2026 Victim Profile
The pattern of targeting in Citizen Lab's 2026 report is consistent with every prior NSO Group investigation: the victims are almost exclusively people whose professional work creates friction with government interests. They are not criminals, terrorists, or subjects of ordinary law enforcement attention. They are reporters, lawyers, and activists.
Among the confirmed 2026 victims, Citizen Lab identified a journalist working on a corruption investigation involving a sitting head of state, a defense attorney in a political detention case, three staff members of an opposition party in an EU member state, and a regional director for an international human rights NGO. Citizen Lab does not name individual victims without consent; all 47 confirmed cases were verified with the device owners before publication.
The geographic distribution of operator clusters in the 2026 report is notable for including two EU member states. Previous NSO investigations had documented Pegasus use by Hungary and Greece, both NATO members, against EU citizens. The continued presence of EU-based operators after the European Parliament's PEGA Committee investigation and subsequent recommendations has drawn sharp criticism from MEPs and digital rights groups including Access Now and the European Digital Rights initiative (EDRi).
Apple's Response | Emergency Patches and Lockdown Mode Limits
Apple received Citizen Lab's technical findings under coordinated disclosure prior to the report's publication and issued an emergency security update patching the ImageIO vulnerability. The patch was released as a Rapid Security Response, Apple's mechanism for delivering critical security fixes outside the normal iOS update cycle, and was pushed to all supported devices automatically for users with automatic updates enabled.
Apple's threat notification system, which alerts users who may have been targeted by mercenary spyware, sent notifications to the 47 confirmed victims and an additional 116 individuals in 23 countries who matched behavioral indicators consistent with Pegasus targeting. The company stated that it sent these notifications based on internal threat intelligence and that being notified does not constitute confirmed infection.
The limitations of Lockdown Mode in the 2026 infections have renewed discussion about whether high-risk users need additional protections. Security researchers at Citizen Lab and Google's Project Zero have noted that Lockdown Mode hardened the attack surface significantly but cannot eliminate risk from vulnerabilities in core system frameworks that must remain active for the device to function. Apple has indicated it is reviewing the Lockdown Mode framework in response to the new findings and plans to restrict additional ImageIO code paths in a future update.
NSO Group's Legal Status | Sanctions, Lawsuits, and the Spyware Industry in 2026
NSO Group's position in 2026 is legally precarious but operationally intact. The company remains on the U.S. Commerce Department Entity List, where it was placed in November 2021, barring American firms from supplying it with software, hardware, or services without a license. The Entity List designation has not prevented NSO from continuing to develop and sell Pegasus, as the company sources its technology infrastructure primarily from non-U.S. vendors.
Apple's lawsuit against NSO Group, filed in November 2021, is ongoing in the Northern District of California. Apple is seeking a permanent injunction barring NSO from using Apple products or services and unspecified damages. NSO has argued that it is immune from suit as an agent of sovereign governments; the court has repeatedly rejected this argument at the motion stage.
Meta's WhatsApp lawsuit, filed in 2019, reached a significant milestone in 2024 when the Ninth Circuit Court of Appeals ruled that NSO Group was not immune from civil suit under the Foreign Sovereign Immunities Act. The case is proceeding to discovery. If WhatsApp prevails, NSO Group could face substantial financial liability and be compelled to disclose client lists, which the company has strongly resisted.
The broader commercial spyware industry of which NSO Group is the most prominent member continues to operate. Competitors including Intellexa (maker of Predator spyware), Paragon Solutions, and Cy4Gate remain active. The European Union's proposed Spyware Regulation, which would require member states to disclose commercial spyware procurements and create an independent oversight mechanism, remains in committee as of June 2026.
Frequently Asked Questions
Frequently Asked Questions
Sources & References
- [1] Citizen Lab: Pegasus Spyware and Predatory Surveillance Research
- [2] Apple Threat Notifications and Protecting Against Mercenary Spyware
- [3] NSO Group Entity List Designation
- [4] Apple Inc. v. NSO Group Technologies Limited
- [5] FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild
- [6] BlastPass: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild
- [7] Lockdown Mode Overview