Pegasus for iOS

MITRE ATT&CK: S0289 View on attack.mitre.org

Aliases: Pegasus for iOS

Malware type
spyware, trojan
Family
Malware family
Operating systems
ios
Profile updated
2026-07-07 15:28:04

Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications financial-services healthcare-and-pharmaceutical

Context

Pegasus for iOS is the iOS version of malware that has reportedly been linked to the NSO Group. It has been advertised and sold to target high-value victims. The Android version is tracked separately under Pegasus for Android.

Malware & tools used

  • Call Log (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Out of Band Data (attack-pattern)
  • Drive-By Compromise (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Compromise Client Software Binary (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Contact List (attack-pattern)
  • SMS Messages (attack-pattern)
  • Phishing (attack-pattern)
  • Location Tracking (attack-pattern)
  • Exploitation for Initial Access (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Audio Capture (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)

Related threat objects

Reports & references

  • MITRE ATT&CK — S0289 (report)
  • citizenlab.ca — Million Dollar Dissident Iphone Zero Day Nso Group Uae (report)
  • info.lookout.com — Lookout Pegasus Technical Analysis (report)

External references