Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group) — Threadlinqs Intelligence
As of 2026-06-10, Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group) is a high-severity malware threat attributed to NSO Group operated by Government of Azerbaijan customer (Azerbaijan), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0751 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: NSO Group operated by Government of Azerbaijan customer · Azerbaijan · ESPIONAGE
NSO Group's Pegasus zero-click mobile spyware was deployed by an Azerbaijani government operator to conduct covert state surveillance of journalists, activists, and human rights defenders. An amicus
Pegasus is a commercial (mercenary) mobile-surveillance implant developed and sold by Israeli vendor NSO Group exclusively to state customers. On 21 April 2026 the Committee to Protect Journalists (CPJ), Access Now, Data Rights, and Human Constanta filed a third-party intervention (amicus curiae brief) at the European Court of Human Rights (ECtHR) in support of a group of cases brought by Azerbaijani journalists, activists, and human rights defenders. The brief argues that the covert deployment of Pegasus against journalists violates the European Convention on Human Rights — in particular the right to private life and the protection of journalistic sources — and that European legislative safeguards and independent oversight are inadequate.
The underlying surveillance was first exposed through the 2021 Pegasus Project, a collaborative investigation coordinated by Forbidden Stories with the technical support of Amnesty International's Security Lab, based on a leak of more than 50,000 phone numbers selected for targeting by NSO Group clients. More than 1,000 Azerbaijani numbers appeared on the list selected by a single Azerbaijani government customer; the consortium named 74 of these targets and forensically confirmed Pegasus infection on the devices of at least five members of Azerbaijani civil society between 2019 and 2021. Confirmed victims include Khadija Ismayilova, a leading investigative journalist formerly with Radio Free Europe/Radio Liberty, whose iPhone was repeatedly re-infected with Pegasus over nearly three years, and Sevinj Vagifgizi, a reporter for the Berlin-based independent outlet Meydan TV.
Technically, Pegasus is delivered primarily through zero-click exploit chains that require no victim interaction. Documented chains include FORCEDENTRY (CVE-2021-30860), an integer-overflow flaw in Apple's CoreGraphics/JBIG2 image-rendering code delivered over iMessage that defeats the iOS BlastDoor sandbox, and BLASTPASS (CVE-2023-41064 with CVE-2023-41061), which abused a maliciously crafted image passed through the iOS PassKit / iMessage pipeline to compromise fully patched iPhones running iOS 16.6 without interaction. NSO's earlier 'Trident' one-click chain (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657) was the first captured Pegasus exploit, found on the phone of UAE activist Ahmed Mansoor in 2016. Once installed, Pegasus grants the operator full remote control of the device: exfiltration of messages (including end-to-end encrypted apps), photos, contacts, call logs, browsing history, and credentials; precise GPS location tracking; and the ability to silently activate the microphone and camera for real-time audio and video capture. Amnesty International's forensic methodology identifies Pegasus through disguised process names (notably 'bh'/'BridgeHead' and 'setframed'), iMessage account-lookup artifacts, and a large rotating set of Version 4 installation and command-and-control domains (Amnesty fingerprinted roughly 700 Pegasus domains). The Mobile Verification Toolkit (MVT), released by Amnesty alongside STIX2 indicators, lets defenders scan iOS and Android devices for these traces.
The Government of Azerbaijan has dismissed the Pegasus findings as a 'baseless fabrication.' This record is published for defensive and protective use by SOC analysts, incident responders, human-rights technologists, and at-risk civil-society defenders.
Weaknesses (CWE)
CWE-190, CWE-787, CWE-416, CWE-119
Target sectors: media, journalism, civil-society, human-rights, activism, political-opposition, ngo
Target regions: Azerbaijan, Caucasus, Eastern Europe, Central Asia, Europe
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2021-30860, CVE-2023-41064, CVE-2023-41061, CVE-2016-4655, CVE-2016-4656, CVE-2016-4657, T1456, T1660, T1658, T1575, T1398, T1404, T1407, T1630, T1628, T1406