Pegasus spyware is often seen as one of the most powerful cyberweapons ever developed. But it has caused global outrage because it’s been used to target politicians, journalists, and activists in ways many people believe are wrong or abusive. In this article, we’ll tell you more about this highly complex spyware for mobile devices and how to detect, remove, and protect yourself from it — even though, thankfully, average citizens are rarely affected. We’ll also explain how you can protect your Android device with Avira Antivirus Security from conventional spyware and other types of malware that pose a real threat to everyone.
What is Pegasus spyware?
Pegasus software isn’t a virus but an advanced form of spyware developed by Israeli cyberintelligence company NSO Group Technologies to spy on Android and iOS devices. Pegasus was designed originally to combat terrorism and serious crime, and is only sold to government agencies such as law enforcement bodies and intelligence services — which is why you’ll also hear it called a state Trojan. In practice, though, state actors also use the spyware illegally against politicians, journalists, whistleblowers, and activists — as well as other critical voices from civil society.
Pegasus spyware can access a wide range of data on a mobile device — such as emails, text messages, and location data — as well as the camera and microphone, and can transmit this information to the operator without the user’s knowledge. The sneaky thing about it is that this surveillance and spying software can even get onto a device without the user doing anything, disguise itself there, cover up everything it does, and then delete itself following the attack or in the event of imminent discovery.
What’s involved in a Pegasus attack?
The surveillance software usually gets onto a device via vulnerabilities, where it begins immediately collecting and transmitting data which can then be used by the attackers against the targeted individuals. Here’s a breakdown of what happens:
1. Mobile device infiltration
Pegasus spyware can infect devices in various ways:
Zero-click exploits: With this method, Pegasus exploits vulnerabilities in apps or the operating system, infecting the target device without any user interaction. The malicious code can, for example, enter the device via manipulated messaging-app messages, push notifications, or calls. The device gets infected during automatic processing of the received data — all without the message needing to be opened or the call answered. That’s why this method is the most widely used nowadays.
One-click exploits: In this scenario, targeted individuals are tricked into opening a personalized link through social engineering techniques like spear-phishing attacks (highly personalized messages). On doing so, an exploit is executed in the background that takes advantage of a vulnerability in the browser or an app, installing the spyware. Since this requires action on the user’s part, this method is used less frequently nowadays.
Network injections: With this method, attackers monitor unencrypted internet traffic (such as via fake cell phone towers, routers, or IMSI catchers — devices that mimic a real cell phone tower) and redirect the request to an infection server. This server sends an exploit to the device, taking advantage of a vulnerability in the browser or an app to install Pegasus spyware in the background. However, this method is rarely used because it requires access to the network infrastructure and is made more difficult by the increasing use of HTTPS encryption.
2. Data collection and exfiltration
Once Pegasus spyware has been successfully installed, it systematically starts exfiltrating data (meaning it steals and transfers data without permission). Almost all the information on the target device is encrypted and sent in real time to the attacker’s server. This allows them to build a detailed profile of the target, monitor their professional and personal life, and identify their contacts and networks.
- Data access: Pegasus can access any and all saved content such as contacts, text messages, emails, photos, videos, documents, calendar entries, notes, passwords, the browser history, and call logs.
- Eavesdropping: The spyware can bypass end-to-end encryption and read chat messages in WhatsApp, Telegram, and Signal — and eavesdrop on calls.
- Real-time remote spying: Through remote access, the camera and microphone can be turned on without the user noticing, allowing attackers to listen to conversations and watch what’s happening around the device.
- Location tracking: Pegasus spyware can determine the user’s GPS location in real time and create detailed movement profiles. By accessing Wi-Fi data, the user’s location can be pinpointed even when GPS is off.
- System control and concealment: Since it has admin rights, Pegasus malware can disable the operating system’s security features and delete itself as well as all traces of the attack (such as outbound data transfer logs).
3. Manipulation and discrediting
The extracted data can be used to support targeted efforts to influence or damage someone’s reputation. By closely monitoring a person’s social environment and personal life, attackers can harvest material for blackmail and apply psychological pressure. They can also use confidential information to publicly discredit the target or disrupt their planned activities. The aim of these actions is usually to intimidate and strategically weaken political opponents, journalists, or activists.
Revelations and controversies surrounding Pegasus
In 2021, over 80 journalists from ten countries — working with Amnesty International and the NGO Forbidden Stories — revealed the systematic abuse of Pegasus spyware as part of the Pegasus Project. Their analysis of 50,000 leaked phone numbers of suspected targets showed that Pegasus spyware had been used globally to systematically monitor heads of state, diplomats, opposition figures, activists, lawyers, and journalists. The NSO Group categorically denied all allegations, stating that the list of telephone numbers had nothing to do with Pegasus.
It also emerged that Pegasus licenses had not only been sold to “vetted and approved customers”, as NSO claimed, but also to questionable government actors. As a result, the US added the company to a blacklist over concerns about national security. At the end of 2025, an American investment group acquired NSO Group and is now trying to have the company removed from the blacklist and the sanctions lifted.
The revelations of the Pegasus Project also sparked a global debate about the need to regulate cyberweapons. UN experts called on all states to impose a global moratorium on the sale and transfer of surveillance technology until there are robust regulations that guarantee its use in compliance with international human rights standards. Given the continued lack of such a global regulatory framework, regulation remains largely dependent on the individual decisions of nation states.
WhatsApp and Apple lawsuits
In 2019, WhatsApp sued the NSO Group over Pegasus attacks that targeted its messaging infrastructure. The attacks were uncovered by WhatsApp together with the research group Citizen Lab. In 2025, the NSO Group was ordered to pay $167 million to WhatsApp after being found guilty of hacking 1,400 users via the platform. On appeal, the NSO Group managed to reduce the amount to around $4 million.
In 2021, Apple also filed a lawsuit after it became known that Pegasus had used zero‑click exploits to break into the iOS operating system. However, Apple withdrew the case in 2024 to avoid having to reveal sensitive internal security details in court. Both Apple and WhatsApp have said they will continue to warn users — even under the Trump administration — if they detect spyware attacks such as Pegasus or Graphite (from Paragon Solutions) on civilian phones.
Known Pegasus-attack victims
Government critic Jamal Khashoggi: In 2021 it was revealed that phones belonging to people close to journalist Jamal Khashoggi — who was murdered by Saudi agents in 2018 — had been infected with Pegasus, most likely by the Saudi government.
French government: According to the Pegasus Project, the French president Emmanuel Macron along with other members of the French government, was among the 50,000 potential targets of the spyware. In this case, the trail led to Morocco, causing a diplomatic crisis between the two countries.
Polish opposition: In January 2025, the former Polish minister of justice Zbigniew Ziobro was arrested on charges of authorizing the illegal surveillance of opposition politicians using Pegasus software during his term in office.
Mexican activist: In 2020, the cell phone of Mexican human rights defender Raymundo Ramos was infected with Pegasus to monitor his investigations into extra-judicial killings by the military. In 2023, leaked internal documents (the Guacamaya Leaks) indicated that the army deliberately used the data obtained to discredit Ramos.
Serbian journalists: In 2025, Amnesty International reported that two female journalists from the investigative network BIRN in Serbia were specifically targeted with Pegasus spyware to monitor their investigations into corruption and state abuse.
How to spot Pegasus on iPhones and Android devices
Pegasus burrows deep into the operating system, leaving hardly any digital traces. That’s because the surveillance software primarily operates in volatile memory, uses legitimate system processes, and deletes or manipulates log entries that might give away its presence. Temporary files are usually deleted, and communication with the control servers is encrypted and disguised, so even experienced users or common security programs find it very difficult to detect Pegasus.
Mobile devices belonging to ordinary individuals are rarely affected by the spyware, especially since governments have to pay huge sums for each Pegasus license. That said, there are a few telltale signs that might point to a Pegasus infection, including rapid battery discharge, high data consumption, and an unusual heating of your cell phone.
Special tools are also available, like the Mobile Verification Toolkit (MVT) developed by Amnesty International for Android and iOS devices. Forensic analysis of smartphones can reveal evidence of a Pegasus break in, although this is more difficult on Android smartphones than on iPhones and iPads. However, you need considerable technical knowledge to use the tool. If you suspect your device is infected with Pegasus, consult an IT forensics expert.
Pegasus email scam
If you receive an email claiming that your cell phone is infected with Pegasus spyware, you can safely ignore it and report it as spam. The scammers will claim to have sensitive material, like embarrassing recordings, and use this to blackmail you.
Should your device actually be infected (which, as mentioned, is very unlikely), WhatsApp and Apple will do the following: If WhatsApp believes your device has come under threat, it will notify you directly via a WhatsApp chat. This chat displays a system message at the top verifying that it is an official WhatsApp support account. If Apple detects activity consistent with a mercenary spyware attack, it will notify you via a threat notification message in your Apple account and via email and iMessage.
How can you remove Pegasus spyware?
Since a regular virus scanner for smartphones can’t detect or remove such sophisticated spyware as Pegasus, if you’re affected you should completely reset your device to factory settings. To prevent possible reinfection, avoid restoring your device via a local or cloud backup. However, since Pegasus malware can even survive in the boot loader (the phone’s startup program), experts recommend physically destroying the infected device and replacing it with a new smartphone with a new SIM card and creating a new Apple ID or Google account.
How can you protect iPhones and Android devices from Pegasus?
Apple, Google, and Samsung have introduced special high-security modes for particularly vulnerable users in response to increasingly complex spyware attacks such as those carried out by Pegasus software. These can be turned on in the device settings under the privacy and security settings, significantly reducing the attack surface for zero-click exploits and other threats. However, this will result in some features being severely restricted or not available at all in these enhanced protection modes.
iPhone: Lockdown Mode
Lockdown Mode was introduced in 2022 with iOS 16. It blocks most message attachments, disables links and link previews, and blocks complex web technologies. FaceTime calls from unknown contacts are also blocked, and your phone won’t automatically join and will disconnect from non-secure Wi-Fi networks. 2G and 3G mobile support is also turned off. In addition, it automatically restricts device connections and configuration profiles.
Google Pixel: Advanced Protection
Introduced with Android 16, this protection mode turns on a range of security features. For example, your device will no longer connect to 2G networks, reducing the attack surface for remote exploits. For supported apps, the hardware and software feature Memory Tagging Extension (MTE) is automatically turned on, preventing spyware such as Pegasus from exploiting vulnerabilities in the RAM.
Samsung Galaxy: Auto Blocker (“Maximum restrictions” feature)
Among other things, this feature blocks the auto-downloading of attachments. It also blocks hyperlinks and previews in the messaging app. On top of that, it prevents the activation of device admin apps that could be misused to remotely control your phone.
How to protect your smartphone from spyware and other malware
Mobile device security isn’t just relevant for high-risk users. For ordinary individuals, there are simpler, less drastic measures than those described above.
Fix security flaws
Since Pegasus as well as other spyware and malware often ends up getting installed on a device as a result of vulnerabilities in apps or the operating system, you should fix these flaws as soon as possible. Thankfully, this is taken care of for you with the security patches that come with regular updates — so it’s a good idea to turn on automatic app and system updates in the app store settings and in your device’s system settings.
Use a virus scanner
In addition to the above, use a cyberprotection solution like Avira Antivirus Security for Android to prevent malware infections. Its virus scanner also helps you detect and remove conventional spyware. In addition, with Smart Scan you can identify and fix not only security risks but also privacy and performance issues on your cell phone.
WhatsApp is a registered trademark of Meta Platforms, Inc.
iOS, iPad, iPhone, and FaceTime are registered trademarks of Apple Inc.
Samsung and Galaxy are registered trademarks of Samsung Electronics Co., Ltd.
Google, Android, and Pixel are registered trademarks of Google LLC.
