Pegasus for Android

MITRE ATT&CK: S0316 View on attack.mitre.org

Aliases: Chrysaor, Pegasus for Android

First seen
2017-04-01 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:05:10

Targeted industries: government-and-public-sector media-and-entertainment

Context

Pegasus for Android is the Android version of malware that has reportedly been linked to the NSO Group. The iOS version is tracked separately under Pegasus for iOS.

Malware & tools used

  • Audio Capture (attack-pattern)
  • Broadcast Receivers (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Call Log (attack-pattern)
  • Calendar Entries (attack-pattern)
  • Video Capture (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Compromise Client Software Binary (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Contact List (attack-pattern)
  • Software Discovery (attack-pattern)
  • Out of Band Data (attack-pattern)

Related threat objects

Reports & references

  • android-developers.googleblog.com — An Investigation Of Chrysaor Malware On (report)
  • MITRE ATT&CK — S0316 (report)
  • blog.lookout.com — Pegasus Android (report)

External references