Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group)
Pegasus Mercenary Spyware Used for State Surveillance of (TL-2026-0751), also tracked as Pegasus Project, is a high-severity malware campaign, first published 2026-06-10. It is attributed to NSO Group operated by Government of Azerbaijan customer (Azerbaijan) with high confidence, affects Apple iOS / iPadOS (iPhone, iPad), references 6 CVEs (CVE-2021-30860, CVE-2023-41064, CVE-2023-41061), maps to 24 MITRE ATT&CK techniques (T1398, T1404, T1406), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0751
- Threat ID
- TL-2026-0751
- Also known as
- Pegasus Project, FORCEDENTRY, BLASTPASS, Trident
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-06-10
- Last reviewed
- 2026-06-10
- Attribution
- NSO Group operated by Government of Azerbaijan customer
- Attribution confidence
- HIGH
- Nation-state nexus
- Azerbaijan
- Motivation
- ESPIONAGE
- Target sectors
- media, journalism, civil-society, human-rights, activism, political-opposition, ngo
- Target regions
- Azerbaijan, Caucasus, Eastern Europe, Central Asia, Europe
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Pegasus Mercenary Spyware Used for State Surveillance of
Malware and tooling: Chrysaor, BLASTPASS, FORCEDENTRY, NSO Group Pegasus Version 4 attack infrastructure
NSO Group's Pegasus zero-click mobile spyware was deployed by an Azerbaijani government operator to conduct covert state surveillance of journalists, activists, and human rights defenders. An amicus brief filed at the European Court of Human Rights on 21 April 2026 documents how Pegasus turns a target's phone into a 24-hour surveillance device with full remote access to its contents and real-time audio/video capture; Amnesty International's Security Lab forensically confirmed infections of Azerbaijani journalists including Khadija Ismayilova and Sevinj Vagifgizi between 2019 and 2021.
How Pegasus Mercenary Spyware Used for State Surveillance of works
Pegasus is a commercial (mercenary) mobile-surveillance implant developed and sold by Israeli vendor NSO Group exclusively to state customers. On 21 April 2026 the Committee to Protect Journalists (CPJ), Access Now, Data Rights, and Human Constanta filed a third-party intervention (amicus curiae brief) at the European Court of Human Rights (ECtHR) in support of a group of cases brought by Azerbaijani journalists, activists, and human rights defenders. The brief argues that the covert deployment of Pegasus against journalists violates the European Convention on Human Rights — in particular the right to private life and the protection of journalistic sources — and that European legislative safeguards and independent oversight are inadequate.
The underlying surveillance was first exposed through the 2021 Pegasus Project, a collaborative investigation coordinated by Forbidden Stories with the technical support of Amnesty International's Security Lab, based on a leak of more than 50,000 phone numbers selected for targeting by NSO Group clients. More than 1,000 Azerbaijani numbers appeared on the list selected by a single Azerbaijani government customer; the consortium named 74 of these targets and forensically confirmed Pegasus infection on the devices of at least five members of Azerbaijani civil society between 2019 and 2021. Confirmed victims include Khadija Ismayilova, a leading investigative journalist formerly with Radio Free Europe/Radio Liberty, whose iPhone was repeatedly re-infected with Pegasus over nearly three years, and Sevinj Vagifgizi, a reporter for the Berlin-based independent outlet Meydan TV.
Technically, Pegasus is delivered primarily through zero-click exploit chains that require no victim interaction. Documented chains include FORCEDENTRY (CVE-2021-30860), an integer-overflow flaw in Apple's CoreGraphics/JBIG2 image-rendering code delivered over iMessage that defeats the iOS BlastDoor sandbox, and BLASTPASS (CVE-2023-41064 with CVE-2023-41061), which abused a maliciously crafted image passed through the iOS PassKit / iMessage pipeline to compromise fully patched iPhones running iOS 16.6 without interaction. NSO's earlier 'Trident' one-click chain (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657) was the first captured Pegasus exploit, found on the phone of UAE activist Ahmed Mansoor in 2016. Once installed, Pegasus grants the operator full remote control of the device: exfiltration of messages (including end-to-end encrypted apps), photos, contacts, call logs, browsing history, and credentials; precise GPS location tracking; and the ability to silently activate the microphone and camera for real-time audio and video capture. Amnesty International's forensic methodology identifies Pegasus through disguised process names (notably 'bh'/'BridgeHead' and 'setframed'), iMessage account-lookup artifacts, and a large rotating set of Version 4 installation and command-and-control domains (Amnesty fingerprinted roughly 700 Pegasus domains). The Mobile Verification Toolkit (MVT), released by Amnesty alongside STIX2 indicators, lets defenders scan iOS and Android devices for these traces.
The Government of Azerbaijan has dismissed the Pegasus findings as a 'baseless fabrication.' This record is published for defensive and protective use by SOC analysts, incident responders, human-rights technologists, and at-risk civil-society defenders.
MITRE ATT&CK techniques used in TL-2026-0751
Persistence
T1398 Boot or Logon Initialization Scripts
Privilege Escalation
T1404 Exploitation for Privilege Escalation
Defense Evasion
T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1628 Hide Artifacts; T1630 Indicator Removal on Host
collection
Collection
T1417 Input Capture; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1513 Screen Capture; T1532 Archive Collected Data; T1636 Protected User Data
Discovery
T1418 Software Discovery; T1426 System Information Discovery
Command and Control
T1437 Application Layer Protocol; T1481 Web Service
Initial Access
T1456 Drive-By Compromise; T1660 Phishing
Credential Access
Execution
T1575 Native API; T1658 Exploitation for Client Execution
Exfiltration
Affected products and versions in Pegasus Mercenary Spyware Used for State Surveillance of
- Apple — iOS / iPadOS (iPhone, iPad)
Vulnerable versions: <= 14.7 (FORCEDENTRY); <= 16.6 (BLASTPASS); <= 9.3.4 (Trident)
Fixed in: 14.8; 16.6.1; 9.3.5 - Apple — macOS
Vulnerable versions: Big Sur < 11.6; Ventura < 13.5.2
Fixed in: 11.6; 13.5.2 - Google — Android
Vulnerable versions: multiple (Pegasus Android variant Chrysaor)
Fixed in: vendor security updates / Google Play Protect detection
Remediation for Pegasus Mercenary Spyware Used for State Surveillance of
Patches
- Apple iOS 14.8 / macOS 11.6 (FORCEDENTRY, CVE-2021-30860)
- Apple iOS 16.6.1 (BLASTPASS, CVE-2023-41064 and CVE-2023-41061)
- Apple iOS 9.3.5 (Trident, CVE-2016-4655/4656/4657)
Immediate actions
- Update iOS/iPadOS and macOS to the latest version to close FORCEDENTRY (CVE-2021-30860), BLASTPASS (CVE-2023-41064/41061) and other patched zero-click chains
- Enable Apple Lockdown Mode on at-risk devices (journalists, activists, HRDs) — confirmed by Apple to block the BLASTPASS attack vector
- Run Amnesty International's Mobile Verification Toolkit (MVT) with the published Pegasus STIX2 indicators against iOS backups and Android dumps to detect existing infection
Workarounds
- Enable Lockdown Mode
- Disable iMessage and FaceTime on highest-risk devices
- Block known Pegasus installation/C2 domains at DNS and perimeter
Longer-term hardening
- Adopt a high-risk mobile security posture for journalists, activists, and human rights defenders: minimal app footprint, frequent reboots, disabling iMessage/FaceTime where feasible
- Establish civil-society incident-response partnerships (Access Now Digital Security Helpline, Amnesty Security Lab, Citizen Lab) for forensic triage
- Push for legal and policy safeguards on commercial spyware exports and use, independent oversight, and effective remedies as argued in the ECtHR brief
CVEs associated with Pegasus Mercenary Spyware Used for State Surveillance of
CVE-2021-30860, CVE-2023-41064, CVE-2023-41061, CVE-2016-4655, CVE-2016-4656, CVE-2016-4657
Weaknesses (CWE) in Pegasus Mercenary Spyware Used for State Surveillance of
CWE-190, CWE-787, CWE-416, CWE-119
Timeline of Pegasus Mercenary Spyware Used for State Surveillance of
- Citizen Lab and Lookout disclose Pegasus 'Trident' one-click iOS exploit chain (CVE-2016-4655/4656/4657) found on UAE activist Ahmed Mansoor's iPhone; Apple patches in iOS 9.3.5.
- Forensic analysis later dates the start of repeated Pegasus infections of Azerbaijani journalists and civil-society figures, including Khadija Ismayilova and Sevinj Vagifgizi, to around 2019.
- Amnesty International publishes its Forensic Methodology Report, the Mobile Verification Toolkit (MVT), and Pegasus STIX2 indicators (process names, ~700 domains, iMessage artifacts).
- The Pegasus Project (Forbidden Stories, Amnesty Security Lab, OCCRP and 80+ journalists) publishes; over 1,000 Azerbaijani numbers appear on the target list and forensic infection of at least five Azerbaijani civil-society members (2019-2021) is confirmed.
- Citizen Lab discloses FORCEDENTRY (CVE-2021-30860), a zero-click iMessage/CoreGraphics JBIG2 integer-overflow exploit that bypasses the iOS BlastDoor sandbox; Apple patches in iOS 14.8.
- Citizen Lab discloses BLASTPASS (CVE-2023-41064 + CVE-2023-41061), a zero-click PassKit/iMessage chain compromising fully patched iPhones on iOS 16.6; Apple patches in iOS 16.6.1 and confirms Lockdown Mode blocks it.
- CPJ, Access Now, Data Rights, and Human Constanta file a third-party intervention (amicus brief) at the European Court of Human Rights supporting Azerbaijani journalists, activists, and HRDs targeted with Pegasus.
- CPJ publicly reports the ECtHR amicus filing, emphasizing risks to journalists' source protection in Eastern Europe and Central Asia and inadequate European safeguards.
Sources cited for Pegasus Mercenary Spyware Used for State Surveillance of
- Amicus brief on spyware and surveillance in Azerbaijan
- CPJ, partners file ECtHR amicus brief on spyware use against journalists in Azerbaijan
- Forensic Methodology Report: How to catch NSO Group's Pegasus
- Amnesty Tech NSO investigation indicators (MVT / STIX2)
- FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild
- BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild
- Sevinj Vaqifqizi, Azerbaijani Reporter (Pegasus Project)
- Life in Azerbaijan's Digital Autocracy: They Want to be in Control of Everything
- Azerbaijani journalist Sevinj Vagifgizi was 'astonished' to learn of Pegasus spyware on phone
- Journalist Targeted With Pegasus Spyware Speaks Out (Khadija Ismayilova) - PBS FRONTLINE
- The Pegasus Project - Amnesty International Security Lab
- Apple addresses zero-day, zero-click NSO Group BLASTPASS exploit
Threats related to Pegasus Mercenary Spyware Used for State Surveillance of
- NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor
- Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets
- Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member Stelios Kouloglou
- BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student Protesters
Detection coverage for TL-2026-0751
As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0751 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.