Threadlinqs IntelligenceStart free

Threat actorIsraelTracked since 2026-06

NSO Group

Also known as:Night TsunamiNSO Group TechnologiesQ Cyber TechnologiesPegasus operators

As of 2026-07-28, NSO Group is a Israel-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, malware. Also known as Night Tsunami, NSO Group Technologies, Q Cyber Technologies, Pegasus operators. ATT&CK coverage spans 46 techniques across 16 tactics in 3 of 3 tracked threats. Most-observed techniques: T1409 (Stored Application Data), T1426 (System Information Discovery), T1429 (Audio Capture).

Tracked threats
32 high
First seen
2026-06-09
Last seen
2026-07-28
ATT&CK techniques
46across 3 of 3 threats
Related CVEs
7Referenced by its activity
Attribution
IsraelNation or origin
Nation: Israel · 3 tracked threat(s) · Categories: THREAT_INTEL, MALWARE

Activity timeline

NSO Group appears in 3 tracked threats between and ; the busiest month was 2026-06 with 2 reports.

ATT&CK techniques observed

46 techniques observed across 3 of 3 tracked threats · Collection (Mobile) (12), Discovery (Mobile) (6), Defense Evasion (Mobile) (4), Command and Control (Mobile) (3), Initial Access (Mobile) (3), Persistence (Mobile) (3)
  • T1409 Stored Application Data — Collection (Mobile)observed in 3 of 3 tracked threats
  • T1426 System Information Discovery — Discovery (Mobile)observed in 3 of 3 tracked threats
  • T1429 Audio Capture — Collection (Mobile)observed in 3 of 3 tracked threats
  • T1430 Location Tracking — Collection (Mobile)observed in 3 of 3 tracked threats
  • T1456 Drive-By Compromise — Initial Access (Mobile)observed in 3 of 3 tracked threats
  • T1658 Exploitation for Client Execution — Execution (Mobile)observed in 3 of 3 tracked threats
  • T1660 Phishing — Initial Access (Mobile)observed in 3 of 3 tracked threats
  • T1404 Exploitation for Privilege Escalation — Privilege Escalation (Mobile)observed in 2 of 3 tracked threats
  • T1417 Input Capture — Collection (Mobile)observed in 2 of 3 tracked threats
  • T1418 Software Discovery — Discovery (Mobile)observed in 2 of 3 tracked threats
  • T1437 Application Layer Protocol — Command and Control (Mobile)observed in 2 of 3 tracked threats
  • T1512 Video Capture — Collection (Mobile)observed in 2 of 3 tracked threats
  • T1628 Hide Artifacts — Defense Evasion (Mobile)observed in 2 of 3 tracked threats
  • T1630 Indicator Removal on Host — Defense Evasion (Mobile)observed in 2 of 3 tracked threats
  • T1636 Protected User Data — Collection (Mobile)observed in 2 of 3 tracked threats

Tracked threats

Related CVEs

7 CVEs referenced by tracked NSO Group activity