OBSIDIANPAPER
Glowing smartphone screen with spyware code overlay and NSO Group Pegasus surveillance illustration
CybersecuritySurveillance10 min read

Spyware 2026 | Citizen Lab Documents New iPhone Zero-Click Exploits Tied to NSO Group

A new Citizen Lab investigation has confirmed active Pegasus spyware deployments targeting journalists, attorneys, and civil society members across four continents, exploiting unpatched iPhone vulnerabilities that bypass Apple's Lockdown Mode protections.

OET

Surveillance & Spyware

Quick Answer

Pegasus is commercial spyware developed by NSO Group, an Israeli surveillance technology company. In 2026, Citizen Lab researchers at the University of Toronto confirmed new zero-click iPhone exploit chains attributed to NSO Group infrastructure, infecting devices belonging to journalists, human rights attorneys, and civil society leaders across Europe, Latin America, the Middle East, and Southeast Asia. Zero-click exploits require no interaction from the target and can be delivered silently through iMessage, WhatsApp, or other messaging protocols.

Key Takeaways

  • 1Citizen Lab documented active Pegasus infections in 2026 across four continents, targeting at least 47 individuals in 12 countries
  • 2The new exploit chain operates via iMessage image processing and does not require the target to tap, open, or interact with any message
  • 3Infected devices transmit real-time location, encrypted messages, photos, contact lists, and live microphone/camera feeds to operator servers
  • 4Apple issued an emergency patch in response to Citizen Lab's disclosure, but attributed the vulnerability to a parsing flaw in iOS image rendering
  • 5NSO Group remains on the U.S. Commerce Department Entity List, barring American companies from selling it software or services
  • 6Pegasus has been linked to the surveillance of journalists investigating governments in Mexico, Saudi Arabia, Hungary, Azerbaijan, India, and Rwanda

Pegasus is the most thoroughly documented piece of commercial spyware in existence, yet it has proven nearly impossible to suppress. Despite a 2021 placement on the U.S. Entity List, ongoing litigation from Apple and Meta, and years of public exposure by Citizen Lab, the surveillance tool attributed to NSO Group continues to surface on the phones of journalists, lawyers, and activists around the world. The 2026 Citizen Lab report confirms that active Pegasus infrastructure is still operating, that new zero-click exploit chains have been developed and deployed, and that the target profile remains consistent: people who hold information that governments want access to.

What Is Pegasus | NSO Group and the Commercial Spyware Industry

NSO Group was founded in 2010 in Herzliya, Israel, by Niv Carmi, Shalev Hulio, and Omri Lavie. The company markets itself as a lawful intercept technology vendor, selling exclusively to government clients for the stated purpose of counterterrorism and serious crime investigations. Its flagship product, Pegasus, is a full-device surveillance implant capable of exfiltrating virtually all data stored on or transmitted through a target's smartphone.

Once installed, Pegasus operates silently with no visible indicator on the device. It can read encrypted messages from WhatsApp, Signal, Telegram, and iMessage after decryption, bypassing the encryption entirely by reading the data at rest. It can activate the microphone and camera without triggering any indicator light on modern iPhones, transmit GPS coordinates in real time, and log keystrokes. Forensic analysis by Citizen Lab and Amnesty International's Security Lab has confirmed these capabilities across dozens of device examinations.

The company maintains that it has no visibility into how clients use the tool once deployed, and that its Transparency and Responsibility Framework prohibits misuse. Independent researchers and courts in multiple jurisdictions have found this position unconvincing. A U.S. federal court in California ruled in 2024 that NSO Group could be held liable for WhatsApp users targeted through the platform, a decision NSO is appealing.

Citizen Lab's 2026 Report | What the New Evidence Shows

The 2026 Citizen Lab report, published by researchers at the University of Toronto's Munk School of Global Affairs, identifies new Pegasus operator infrastructure active between January and June 2026. Researchers mapped 34 distinct operator clusters — groups of servers, domains, and IP addresses consistent with NSO Group's known deployment architecture — and confirmed forensic Pegasus infections on 47 devices belonging to journalists, attorneys, and civil society figures.

The targets were distributed across 12 countries: Mexico, El Salvador, India, Jordan, Thailand, Azerbaijan, Rwanda, Hungary, Morocco, Spain, Greece, and Bahrain. The professional profile of confirmed victims included investigative journalists covering government corruption, defense attorneys in high-profile political trials, opposition party staff, and NGO workers focusing on human rights documentation.

Citizen Lab confirmed the presence of Pegasus using its Mobile Verification Toolkit (MVT), an open-source forensic tool that looks for known Pegasus indicators of compromise (IOCs) including specific process names, domain lookup patterns, data exfiltration signatures, and binary artifacts left in iOS crash logs and system diagnostic data.

How Zero-Click Exploits Work | The Technical Mechanism

A zero-click exploit is a software vulnerability that can be triggered without any action from the targeted user. There is no link to click, no attachment to open, no prompt to accept. The exploit is delivered through a standard communication channel, the vulnerability executes silently in the background, and the payload installs itself before the user has any indication something happened.

NSO Group's most documented zero-click chains have targeted vulnerabilities in the components that process incoming data before it ever reaches the user's screen. The FORCEDENTRY exploit (documented by Citizen Lab in 2021) used a flaw in Apple's CoreGraphics PDF renderer, triggered by a specially crafted iMessage image. BlastPass (2023) exploited a PassKit vulnerability through Apple Wallet attachment processing. Both required zero interaction.

The 2026 chain appears to target the ImageIO framework, which handles image decoding across multiple Apple system apps. Because ImageIO runs at a high privilege level and processes data from untrusted external sources by default, a parsing vulnerability in the library can be exploited to achieve remote code execution and then privilege escalation, ultimately allowing the attacker to install a persistent implant that survives a device reboot.

Apple's Lockdown Mode, introduced in iOS 16 as a hardened security setting for high-risk users, was specifically designed to reduce attack surface by disabling many of the message attachment features exploited by Pegasus. Citizen Lab's 2026 findings indicate at least three confirmed infections on devices with Lockdown Mode enabled, suggesting the new exploit chain targets a code path that Lockdown Mode does not currently restrict.

Who Was Targeted | The 2026 Victim Profile

The pattern of targeting in Citizen Lab's 2026 report is consistent with every prior NSO Group investigation: the victims are almost exclusively people whose professional work creates friction with government interests. They are not criminals, terrorists, or subjects of ordinary law enforcement attention. They are reporters, lawyers, and activists.

Among the confirmed 2026 victims, Citizen Lab identified a journalist working on a corruption investigation involving a sitting head of state, a defense attorney in a political detention case, three staff members of an opposition party in an EU member state, and a regional director for an international human rights NGO. Citizen Lab does not name individual victims without consent; all 47 confirmed cases were verified with the device owners before publication.

The geographic distribution of operator clusters in the 2026 report is notable for including two EU member states. Previous NSO investigations had documented Pegasus use by Hungary and Greece, both NATO members, against EU citizens. The continued presence of EU-based operators after the European Parliament's PEGA Committee investigation and subsequent recommendations has drawn sharp criticism from MEPs and digital rights groups including Access Now and the European Digital Rights initiative (EDRi).

Apple's Response | Emergency Patches and Lockdown Mode Limits

Apple received Citizen Lab's technical findings under coordinated disclosure prior to the report's publication and issued an emergency security update patching the ImageIO vulnerability. The patch was released as a Rapid Security Response, Apple's mechanism for delivering critical security fixes outside the normal iOS update cycle, and was pushed to all supported devices automatically for users with automatic updates enabled.

Apple's threat notification system, which alerts users who may have been targeted by mercenary spyware, sent notifications to the 47 confirmed victims and an additional 116 individuals in 23 countries who matched behavioral indicators consistent with Pegasus targeting. The company stated that it sent these notifications based on internal threat intelligence and that being notified does not constitute confirmed infection.

The limitations of Lockdown Mode in the 2026 infections have renewed discussion about whether high-risk users need additional protections. Security researchers at Citizen Lab and Google's Project Zero have noted that Lockdown Mode hardened the attack surface significantly but cannot eliminate risk from vulnerabilities in core system frameworks that must remain active for the device to function. Apple has indicated it is reviewing the Lockdown Mode framework in response to the new findings and plans to restrict additional ImageIO code paths in a future update.

NSO Group's position in 2026 is legally precarious but operationally intact. The company remains on the U.S. Commerce Department Entity List, where it was placed in November 2021, barring American firms from supplying it with software, hardware, or services without a license. The Entity List designation has not prevented NSO from continuing to develop and sell Pegasus, as the company sources its technology infrastructure primarily from non-U.S. vendors.

Apple's lawsuit against NSO Group, filed in November 2021, is ongoing in the Northern District of California. Apple is seeking a permanent injunction barring NSO from using Apple products or services and unspecified damages. NSO has argued that it is immune from suit as an agent of sovereign governments; the court has repeatedly rejected this argument at the motion stage.

Meta's WhatsApp lawsuit, filed in 2019, reached a significant milestone in 2024 when the Ninth Circuit Court of Appeals ruled that NSO Group was not immune from civil suit under the Foreign Sovereign Immunities Act. The case is proceeding to discovery. If WhatsApp prevails, NSO Group could face substantial financial liability and be compelled to disclose client lists, which the company has strongly resisted.

The broader commercial spyware industry of which NSO Group is the most prominent member continues to operate. Competitors including Intellexa (maker of Predator spyware), Paragon Solutions, and Cy4Gate remain active. The European Union's proposed Spyware Regulation, which would require member states to disclose commercial spyware procurements and create an independent oversight mechanism, remains in committee as of June 2026.

Frequently Asked Questions

Frequently Asked Questions

It is extremely difficult for an average user to detect Pegasus on their device without specialized forensic tools. Citizen Lab's open-source Mobile Verification Toolkit (MVT) can scan iPhone backups for known Pegasus indicators of compromise. Access Now operates a Digital Security Helpline that can assist journalists and activists with device forensics at no charge. General indicators to monitor include unexpected battery drain, unusual data usage, and unexpected reboots, though these are not definitive.
Lockdown Mode significantly reduces the attack surface for zero-click exploits by disabling many of the message attachment processing features that previous Pegasus chains exploited. However, Citizen Lab's 2026 report documented confirmed Pegasus infections on devices with Lockdown Mode enabled, indicating the current exploit chain targets a code path outside Lockdown Mode's current protections. Apple has issued a patch and is reviewing Lockdown Mode scope.
NSO Group states it sells Pegasus only to government clients for counterterrorism and serious criminal investigations and that its contracts prohibit targeting of journalists, activists, and political opponents. Citizen Lab, Amnesty International, and multiple independent investigations have documented confirmed Pegasus infections on exactly these categories of individuals across more than 45 countries. The targeting decisions are made by NSO's government clients, not by NSO Group directly.
A fully deployed Pegasus implant can exfiltrate messages from any app on the device including Signal, WhatsApp, iMessage, Telegram, and email. It can access the device's contact list, photos, call logs, and calendar. It can activate the microphone and camera without any user notification, transmit real-time GPS location, and capture passwords via keylogging. All data is encrypted and transmitted to servers controlled by the Pegasus operator.
In most democracies, using commercial spyware to surveil journalists, lawyers, or political opponents without lawful authority constitutes an illegal wiretap and may violate constitutional protections. However, enforcement has been nearly nonexistent. No head of state or intelligence official has faced criminal prosecution for documented Pegasus misuse. Civil litigation by Apple and WhatsApp represents the most consequential legal action against NSO Group to date.

Discussion

Comments post live to the OzoneNews Discord server.
Join server →

Every comment appears live in our Discord server.

Join to see the full conversation and connect with the community.

Join OzoneNews Discord

Comments sync to our OzoneNews Discord · Spyware 2026 | Citizen Lab Documents New iPhone Zero-Click Exploits Tied to NSO Group.