The Times Australia
The Times World News

.
Beatbot

.

What is Pegasus? A cybersecurity expert explains how the spyware invades phones and what it does when it gets in

  • Written by Bhanukiran Gurijala, Assistant Professor of Computer Science & Information Systems, West Virginia University

End-to-end encryption is technology that scrambles messages on your phone and unscrambles them only on the recipients’ phones, which means anyone who intercepts the messages in between can’t read them. Dropbox, Facebook, Google, Microsoft, Twitter and Yahoo are among the companies whose apps and services use end-to-end encryption[1].

This kind of encryption is good for protecting your privacy, but governments don’t like it[2] because it makes it difficult for them to spy on people, whether tracking criminals and terrorists or, as some governments have been known to do, snooping on dissidents, protesters and journalists. Enter an Israeli technology firm, NSO Group[3].

The company’s flagship product is Pegasus, spyware[4] that can stealthily enter a smartphone and gain access to everything on it, including its camera and microphone. Pegasus is designed to infiltrate devices running Android, Blackberry, iOS and Symbian operating systems[5] and turn them into surveillance devices. The company says it sells Pegasus only to governments[6] and only for the purposes of tracking criminals and terrorists.

How it works

Earlier version of Pegasus[7] were installed on smartphones through vulnerabilities[8] in commonly used apps or by spear-phishing[9], which involves tricking a targeted user into clicking a link or opening a document that secretly installs the software. It can also be installed over a wireless transceiver[10] located near a target, or manually if an agent can steal the target’s phone.

Close-up of an icon on a smartphone screen Pegasus can infiltrate a smartphone via the widely used messaging app WhatsApp without the phone’s user noticing. Christoph Scholz/Flickr, CC BY-SA[11][12]

Since 2019, Pegasus users have been able to install the software on smartphones with a missed call on WhatsApp[13], and can even delete the record of the missed call, making it impossible for the the phone’s owner to know anything is amiss. Another way is by simply sending a message to a user’s phone that produces no notification.

This means the latest version of this spyware does not require the smartphone user to do anything. All that is required for a successful spyware attack and installation is having a particular vulnerable app or operating system installed on the device. This is known as a zero-click exploit[14].

Once installed, Pegasus can theoretically harvest any data[15] from the device and transmit it back to the attacker. It can steal photos and videos, recordings, location records, communications, web searches, passwords, call logs and social media posts. It also has the capability to activate cameras and microphones for real-time surveillance without the permission or knowledge of the user.

Who has been using Pegasus and why

NSO Group says it builds Pegasus solely for governments to use in counterterrorism and law enforcement work. The company markets it as a targeted spying tool to track criminals and terrorists and not for mass surveillance. The company does not disclose its clients.

The earliest reported use[16] of Pegasus was by the Mexican government in 2011 to track notorious drug baron Joaquín “El Chapo” Guzmán. The tool was also reportedly used to track people[17] close to murdered Saudi journalist Jamal Khashoggi.

It is unclear who or what types of people are being targeted and why. However, much of the recent reporting[18] about Pegasus centers around a list of 50,000 phone numbers. The list has been attributed to NSO Group, but the list’s origins are unclear. A statement from Amnesty International in Israel stated that the list contains phone numbers[19] that were marked as “of interest” to NSO’s various clients, though it’s not known if any of the phones associated with numbers have actually been tracked.

A media consortium, the Pegasus Project[20], analyzed the phone numbers on the list and identified over 1,000 people in over 50 countries. The findings included people who appear to fall outside of the NSO Group’s restriction to investigations of criminal and terrorist activity. These include politicians, government workers, journalists, human rights activists, business executives and Arab royal family members.

Other ways your phone can be tracked

Pegasus is breathtaking in its stealth and its seeming ability to take complete control of someone’s phone, but it’s not the only way people can be spied on through their phones. Some of the ways phones can aid surveillance and undermine privacy[21] include location tracking, eavesdropping, malware[22] and collecting data from sensors.

What is Pegasus? A cybersecurity expert explains how the spyware invades phones and what it does when it gets in Law enforcement agencies use cell site simulators like this StingRay to intercept calls from phones in the vicinity of the device. U.S. Patent and Trademark Office via AP[23]

Governments and phone companies can track a phone’s location by tracking cell signals from cell tower transceivers and cell transceiver simulators[24] like the StingRay[25] device. Wi-Fi and Bluetooth signals can also be used to track phones[26]. In some cases, apps and web browsers can determine a phone’s location.

Eavesdropping on communications is harder to accomplish than tracking, but it is possible in situations in which encryption is weak or lacking. Some types of malware can compromise privacy by accessing data.

The National Security Agency has sought agreements with technology companies under which the companies would give the agency special access into their products via backdoors[27], and has reportedly built backdoors on its own[28]. The companies say that backdoors defeat the purpose of end-to-end encryption[29].

The good news is, depending on who you are, you’re unlikely to be targeted by a government wielding Pegasus. The bad news is, that fact alone does not guarantee your privacy.

[Understand new developments in science, health and technology, each week. Subscribe to The Conversation’s science newsletter[30].]

References

  1. ^ use end-to-end encryption (www.eff.org)
  2. ^ governments don’t like it (www.washingtonpost.com)
  3. ^ NSO Group (www.nsogroup.com)
  4. ^ spyware (techterms.com)
  5. ^ operating systems (techterms.com)
  6. ^ only to governments (www.nsogroup.com)
  7. ^ Earlier version of Pegasus (economictimes.indiatimes.com)
  8. ^ vulnerabilities (nvd.nist.gov)
  9. ^ spear-phishing (www.trendmicro.com)
  10. ^ transceiver (www.pcmag.com)
  11. ^ Christoph Scholz/Flickr (flickr.com)
  12. ^ CC BY-SA (creativecommons.org)
  13. ^ missed call on WhatsApp (economictimes.indiatimes.com)
  14. ^ zero-click exploit (www.news18.com)
  15. ^ harvest any data (www.documentcloud.org)
  16. ^ earliest reported use (www.ynetnews.com)
  17. ^ track people (www.washingtonpost.com)
  18. ^ much of the recent reporting (www.bbc.com)
  19. ^ the list contains phone numbers (twitter.com)
  20. ^ the Pegasus Project (forbiddenstories.org)
  21. ^ can aid surveillance and undermine privacy (ssd.eff.org)
  22. ^ malware (techterms.com)
  23. ^ U.S. Patent and Trademark Office via AP (newsroom.ap.org)
  24. ^ cell transceiver simulators (www.eff.org)
  25. ^ StingRay (www.engadget.com)
  26. ^ used to track phones (arstechnica.com)
  27. ^ backdoors (techterms.com)
  28. ^ reportedly built backdoors on its own (www.reuters.com)
  29. ^ defeat the purpose of end-to-end encryption (www.zdnet.com)
  30. ^ Subscribe to The Conversation’s science newsletter (theconversation.com)

Read more https://theconversation.com/what-is-pegasus-a-cybersecurity-expert-explains-how-the-spyware-invades-phones-and-what-it-does-when-it-gets-in-165382

The Times Features

Evaluating Costs and Benefits of DIY Plumbing vs. Professional Services in Newcastle

Plumbing is an essential service for homes and businesses in Newcastle, ensuring the smooth flow of water and sanitation facilities. As residents and businesses strive to maintai...

Tasting Australia welcomes Journey Beyond as new presenting partner

One of the country’s longest running food and beverage festivals, Tasting Australia has announced Journey Beyond as the festival’s new presenting partner for 2025 and beyond. Th...

There are 2 main ways to stretch – the one you should choose depends on what you want your body to do

Picture this: you’ve just woken up and rolled out of bed. Your feet hit the floor, and your legs buckle. They are in absolute agony – that run yesterday has really come back to...

Chef Tom Walton shares three top tips to create budget-friendly meals without compromising on flavour

Feeding the family on a budget doesn’t need to mean sacrificing flavour. Chef Tom Walton shares his top three tips for creating delicious and cost-effective meals. Here’s how y...

Mosquito-borne diseases are on the rise. Here’s how collecting mozzies in your backyard can help science

Warm weather is here and mosquitoes are on the rise in Australia. Unseasonably large swarms are causing problems in some parts of Sydney already[1]. Health authorities track m...

HOYTS Gift Cards are coming in hot this festive season

With a hot selection of blockbuster movies coming to the big screen this summer, avoid the crowds and enjoy some movie magic at HOYTS with discounted gift cards—perfect for stuff...

Times Magazine

Full Accident History Is Now Available on VinFocs

Buying a car is an important and responsible step to which you need to find an approach. It's always possible to buy a new car from the showroom, but used cars are in excellent condition. But did you know that a car after an accident is usually c...

An Introductory Guide to Electrical Sub Boards

Advantages of Installing an Electrical SubBoard Installing an electrical subboard is a great way to keep your home or business safe and properly wired. By adding a subboard to your existing wiring system, you can increase the safety and efficien...

The Top 10 Highest-Scoring Matches in the Champions League

The 7:0 victory of Olympique Marseille over MŠK Žilina was the biggest away win in the history of the Champions League. But far from being the highest-scoring match in this prestigious competition. Here's our top ten. Feyenoord Rotterdam – KR Reykja...

Consumer Warning: Read Your Warranty

When buying a new hot water system, you enter the tricky world of warranties – the fine print, the pitfalls, the foggy areas and the rarer warranties that actually make sense. How do you navigate it? Too many people get attracted to the word ‘wa...

Providing comprehensive water management solutions for rural areas at its finest.

Are you looking for the ultimate water management solutions to help rural areas? Water is increasingly becoming a precious resource, and the stranglehold of drought and scarcity is impacting communities on a global scale. For remote or rural areas...

Truck Dealers Sales and Service: Get the Best Deals on Trucks Here

Looking for the best deals on trucks near you? Truck repair shops in Australia offer a range of services and sales options that can help you get the perfect truck for your needs.  Whether you're looking for a new or used one, these professional ...