# NSO Group

> As of 2026-07-28, NSO Group is a Israel-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, malware. Also known as Night Tsunami, NSO Group Technologies, Q Cyber Technologies, Pegasus operators. ATT&CK coverage spans 46 techniques across 16 tactics in 3 of 3 tracked threats. Most-observed techniques: T1409 (Stored Application Data), T1426 (System Information Discovery), T1429 (Audio Capture).

- **Nation:** Israel
- **Tracked threats:** 3
- **Categories:** THREAT_INTEL, MALWARE
- **Also known as:** Night Tsunami, NSO Group Technologies, Q Cyber Technologies, Pegasus operators
- **As of:** 2026-07-28

## ATT&CK techniques observed

46 techniques observed across 3 of 3 tracked threats. Tactics: Collection (Mobile) (12), Discovery (Mobile) (6), Defense Evasion (Mobile) (4), Command and Control (Mobile) (3), Initial Access (Mobile) (3), Persistence (Mobile) (3).

- [T1409](https://intel.threadlinqs.com/technique/T1409) Stored Application Data — Collection (Mobile) — observed in 3 of 3 tracked threats
- [T1426](https://intel.threadlinqs.com/technique/T1426) System Information Discovery — Discovery (Mobile) — observed in 3 of 3 tracked threats
- [T1429](https://intel.threadlinqs.com/technique/T1429) Audio Capture — Collection (Mobile) — observed in 3 of 3 tracked threats
- [T1430](https://intel.threadlinqs.com/technique/T1430) Location Tracking — Collection (Mobile) — observed in 3 of 3 tracked threats
- [T1456](https://intel.threadlinqs.com/technique/T1456) Drive-By Compromise — Initial Access (Mobile) — observed in 3 of 3 tracked threats
- [T1658](https://attack.mitre.org/techniques/T1658/) Exploitation for Client Execution — Execution (Mobile) — observed in 3 of 3 tracked threats
- [T1660](https://intel.threadlinqs.com/technique/T1660) Phishing — Initial Access (Mobile) — observed in 3 of 3 tracked threats
- [T1404](https://intel.threadlinqs.com/technique/T1404) Exploitation for Privilege Escalation — Privilege Escalation (Mobile) — observed in 2 of 3 tracked threats
- [T1417](https://intel.threadlinqs.com/technique/T1417) Input Capture — Collection (Mobile) — observed in 2 of 3 tracked threats
- [T1418](https://intel.threadlinqs.com/technique/T1418) Software Discovery — Discovery (Mobile) — observed in 2 of 3 tracked threats
- [T1437](https://intel.threadlinqs.com/technique/T1437) Application Layer Protocol — Command and Control (Mobile) — observed in 2 of 3 tracked threats
- [T1512](https://intel.threadlinqs.com/technique/T1512) Video Capture — Collection (Mobile) — observed in 2 of 3 tracked threats
- [T1628](https://intel.threadlinqs.com/technique/T1628) Hide Artifacts — Defense Evasion (Mobile) — observed in 2 of 3 tracked threats
- [T1630](https://intel.threadlinqs.com/technique/T1630) Indicator Removal on Host — Defense Evasion (Mobile) — observed in 2 of 3 tracked threats
- [T1636](https://intel.threadlinqs.com/technique/T1636) Protected User Data — Collection (Mobile) — observed in 2 of 3 tracked threats

## Tracked threats

- [NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor](https://intel.threadlinqs.com/threat/TL-2026-1748) — INFORMATIONAL
- [Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group)](https://intel.threadlinqs.com/threat/TL-2026-0751) — HIGH
- [NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)](https://intel.threadlinqs.com/threat/TL-2026-0728) — HIGH

## Related CVEs

7 CVEs referenced by tracked NSO Group activity.

- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2019-3568](https://intel.threadlinqs.com/cve/CVE-2019-3568)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/NSO%20Group
