Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group)

Pegasus Mercenary Spyware Used for State Surveillance of (TL-2026-0751), also tracked as Pegasus Project, is a high-severity malware campaign, first published 2026-06-10. It is attributed to NSO Group operated by Government of Azerbaijan customer (Azerbaijan) with high confidence, affects Apple iOS / iPadOS (iPhone, iPad), references 6 CVEs (CVE-2021-30860, CVE-2023-41064, CVE-2023-41061), maps to 24 MITRE ATT&CK techniques (T1398, T1404, T1406), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-0751

Threat ID
TL-2026-0751
Also known as
Pegasus Project, FORCEDENTRY, BLASTPASS, Trident
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-06-10
Last reviewed
2026-06-10
Attribution
NSO Group operated by Government of Azerbaijan customer
Attribution confidence
HIGH
Nation-state nexus
Azerbaijan
Motivation
ESPIONAGE
Target sectors
media, journalism, civil-society, human-rights, activism, political-opposition, ngo
Target regions
Azerbaijan, Caucasus, Eastern Europe, Central Asia, Europe
Detection rules
9
Indicators of compromise
22

Malware and tooling in Pegasus Mercenary Spyware Used for State Surveillance of

Malware and tooling: Chrysaor, BLASTPASS, FORCEDENTRY, NSO Group Pegasus Version 4 attack infrastructure

NSO Group's Pegasus zero-click mobile spyware was deployed by an Azerbaijani government operator to conduct covert state surveillance of journalists, activists, and human rights defenders. An amicus brief filed at the European Court of Human Rights on 21 April 2026 documents how Pegasus turns a target's phone into a 24-hour surveillance device with full remote access to its contents and real-time audio/video capture; Amnesty International's Security Lab forensically confirmed infections of Azerbaijani journalists including Khadija Ismayilova and Sevinj Vagifgizi between 2019 and 2021.

How Pegasus Mercenary Spyware Used for State Surveillance of works

Pegasus is a commercial (mercenary) mobile-surveillance implant developed and sold by Israeli vendor NSO Group exclusively to state customers. On 21 April 2026 the Committee to Protect Journalists (CPJ), Access Now, Data Rights, and Human Constanta filed a third-party intervention (amicus curiae brief) at the European Court of Human Rights (ECtHR) in support of a group of cases brought by Azerbaijani journalists, activists, and human rights defenders. The brief argues that the covert deployment of Pegasus against journalists violates the European Convention on Human Rights — in particular the right to private life and the protection of journalistic sources — and that European legislative safeguards and independent oversight are inadequate.

The underlying surveillance was first exposed through the 2021 Pegasus Project, a collaborative investigation coordinated by Forbidden Stories with the technical support of Amnesty International's Security Lab, based on a leak of more than 50,000 phone numbers selected for targeting by NSO Group clients. More than 1,000 Azerbaijani numbers appeared on the list selected by a single Azerbaijani government customer; the consortium named 74 of these targets and forensically confirmed Pegasus infection on the devices of at least five members of Azerbaijani civil society between 2019 and 2021. Confirmed victims include Khadija Ismayilova, a leading investigative journalist formerly with Radio Free Europe/Radio Liberty, whose iPhone was repeatedly re-infected with Pegasus over nearly three years, and Sevinj Vagifgizi, a reporter for the Berlin-based independent outlet Meydan TV.

Technically, Pegasus is delivered primarily through zero-click exploit chains that require no victim interaction. Documented chains include FORCEDENTRY (CVE-2021-30860), an integer-overflow flaw in Apple's CoreGraphics/JBIG2 image-rendering code delivered over iMessage that defeats the iOS BlastDoor sandbox, and BLASTPASS (CVE-2023-41064 with CVE-2023-41061), which abused a maliciously crafted image passed through the iOS PassKit / iMessage pipeline to compromise fully patched iPhones running iOS 16.6 without interaction. NSO's earlier 'Trident' one-click chain (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657) was the first captured Pegasus exploit, found on the phone of UAE activist Ahmed Mansoor in 2016. Once installed, Pegasus grants the operator full remote control of the device: exfiltration of messages (including end-to-end encrypted apps), photos, contacts, call logs, browsing history, and credentials; precise GPS location tracking; and the ability to silently activate the microphone and camera for real-time audio and video capture. Amnesty International's forensic methodology identifies Pegasus through disguised process names (notably 'bh'/'BridgeHead' and 'setframed'), iMessage account-lookup artifacts, and a large rotating set of Version 4 installation and command-and-control domains (Amnesty fingerprinted roughly 700 Pegasus domains). The Mobile Verification Toolkit (MVT), released by Amnesty alongside STIX2 indicators, lets defenders scan iOS and Android devices for these traces.

The Government of Azerbaijan has dismissed the Pegasus findings as a 'baseless fabrication.' This record is published for defensive and protective use by SOC analysts, incident responders, human-rights technologists, and at-risk civil-society defenders.

MITRE ATT&CK techniques used in TL-2026-0751

Persistence

T1398 Boot or Logon Initialization Scripts

Privilege Escalation

T1404 Exploitation for Privilege Escalation

Defense Evasion

T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1628 Hide Artifacts; T1630 Indicator Removal on Host

collection

T1409 Stored Application Data

Collection

T1417 Input Capture; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1513 Screen Capture; T1532 Archive Collected Data; T1636 Protected User Data

Discovery

T1418 Software Discovery; T1426 System Information Discovery

Command and Control

T1437 Application Layer Protocol; T1481 Web Service

Initial Access

T1456 Drive-By Compromise; T1660 Phishing

Credential Access

T1517 Access Notifications

Execution

T1575 Native API; T1658 Exploitation for Client Execution

Exfiltration

T1646 Exfiltration Over C2 Channel

Affected products and versions in Pegasus Mercenary Spyware Used for State Surveillance of

  • Apple — iOS / iPadOS (iPhone, iPad)
    Vulnerable versions: <= 14.7 (FORCEDENTRY); <= 16.6 (BLASTPASS); <= 9.3.4 (Trident)
    Fixed in: 14.8; 16.6.1; 9.3.5
  • Apple — macOS
    Vulnerable versions: Big Sur < 11.6; Ventura < 13.5.2
    Fixed in: 11.6; 13.5.2
  • Google — Android
    Vulnerable versions: multiple (Pegasus Android variant Chrysaor)
    Fixed in: vendor security updates / Google Play Protect detection

Remediation for Pegasus Mercenary Spyware Used for State Surveillance of

Patches

  • Apple iOS 14.8 / macOS 11.6 (FORCEDENTRY, CVE-2021-30860)
  • Apple iOS 16.6.1 (BLASTPASS, CVE-2023-41064 and CVE-2023-41061)
  • Apple iOS 9.3.5 (Trident, CVE-2016-4655/4656/4657)

Immediate actions

  • Update iOS/iPadOS and macOS to the latest version to close FORCEDENTRY (CVE-2021-30860), BLASTPASS (CVE-2023-41064/41061) and other patched zero-click chains
  • Enable Apple Lockdown Mode on at-risk devices (journalists, activists, HRDs) — confirmed by Apple to block the BLASTPASS attack vector
  • Run Amnesty International's Mobile Verification Toolkit (MVT) with the published Pegasus STIX2 indicators against iOS backups and Android dumps to detect existing infection

Workarounds

  • Enable Lockdown Mode
  • Disable iMessage and FaceTime on highest-risk devices
  • Block known Pegasus installation/C2 domains at DNS and perimeter

Longer-term hardening

  • Adopt a high-risk mobile security posture for journalists, activists, and human rights defenders: minimal app footprint, frequent reboots, disabling iMessage/FaceTime where feasible
  • Establish civil-society incident-response partnerships (Access Now Digital Security Helpline, Amnesty Security Lab, Citizen Lab) for forensic triage
  • Push for legal and policy safeguards on commercial spyware exports and use, independent oversight, and effective remedies as argued in the ECtHR brief

CVEs associated with Pegasus Mercenary Spyware Used for State Surveillance of

CVE-2021-30860, CVE-2023-41064, CVE-2023-41061, CVE-2016-4655, CVE-2016-4656, CVE-2016-4657

Weaknesses (CWE) in Pegasus Mercenary Spyware Used for State Surveillance of

CWE-190, CWE-787, CWE-416, CWE-119

Timeline of Pegasus Mercenary Spyware Used for State Surveillance of

  • Citizen Lab and Lookout disclose Pegasus 'Trident' one-click iOS exploit chain (CVE-2016-4655/4656/4657) found on UAE activist Ahmed Mansoor's iPhone; Apple patches in iOS 9.3.5.
  • Forensic analysis later dates the start of repeated Pegasus infections of Azerbaijani journalists and civil-society figures, including Khadija Ismayilova and Sevinj Vagifgizi, to around 2019.
  • Amnesty International publishes its Forensic Methodology Report, the Mobile Verification Toolkit (MVT), and Pegasus STIX2 indicators (process names, ~700 domains, iMessage artifacts).
  • The Pegasus Project (Forbidden Stories, Amnesty Security Lab, OCCRP and 80+ journalists) publishes; over 1,000 Azerbaijani numbers appear on the target list and forensic infection of at least five Azerbaijani civil-society members (2019-2021) is confirmed.
  • Citizen Lab discloses FORCEDENTRY (CVE-2021-30860), a zero-click iMessage/CoreGraphics JBIG2 integer-overflow exploit that bypasses the iOS BlastDoor sandbox; Apple patches in iOS 14.8.
  • Citizen Lab discloses BLASTPASS (CVE-2023-41064 + CVE-2023-41061), a zero-click PassKit/iMessage chain compromising fully patched iPhones on iOS 16.6; Apple patches in iOS 16.6.1 and confirms Lockdown Mode blocks it.
  • CPJ, Access Now, Data Rights, and Human Constanta file a third-party intervention (amicus brief) at the European Court of Human Rights supporting Azerbaijani journalists, activists, and HRDs targeted with Pegasus.
  • CPJ publicly reports the ECtHR amicus filing, emphasizing risks to journalists' source protection in Eastern Europe and Central Asia and inadequate European safeguards.

Sources cited for Pegasus Mercenary Spyware Used for State Surveillance of

Threats related to Pegasus Mercenary Spyware Used for State Surveillance of

Detection coverage for TL-2026-0751

As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0751 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats