NSO Group Says It Sells Pegasus Spyware Only to Vetted Governments to Fight Terrorism and Crime. Citizen Lab Found the Software on the Phone of Jamal Khashoggi's Wife Months Before His Murder.

Share
NSO Group Says It Sells Pegasus Spyware Only to Vetted Governments to Fight Terrorism and Crime. Citizen Lab Found the Software on the Phone of Jamal Khashoggi's Wife Months Before His Murder.
Photo by Rohan / Unsplash

In March 2021, researchers examining the iPhone of a Saudi activist found a file disguised as a GIF sitting in the device's iMessage data. It was not a GIF. It was a PDF containing a compressed image format called JBIG2, engineered so precisely that the individual pixels of the fake image could be used as logic gates — AND, OR, XOR — wired together into a small computer built entirely out of image-decompression instructions, running inside Apple's own code, for the sole purpose of taking over the phone. The activist had not clicked anything. He had not opened anything. He did not know it had happened.

The exploit was called FORCEDENTRY, and Google's Project Zero, which took it apart afterward, called it "one of the most technically sophisticated exploits we've ever seen." It was built by NSO Group, an Israeli company that says it sells its Pegasus spyware exclusively to vetted government agencies for the purpose of fighting terrorism and serious crime. In the years since NSO Group was founded in a Herzliya office in 2010, that same software has also been found on the phones of New York Times and Al Jazeera reporters, human rights lawyers, opposition politicians in Spain, the wife of a murdered Washington Post columnist, and — according to a forensic report commissioned after the fact — Amazon's founder.

A Text Message That Does Not Need to Be Opened

Pegasus's defining feature is that it requires nothing from its target. Earlier spyware needed a victim to click a malicious link — NSO Group's first documented case, in 2016, worked exactly that way, sending UAE activist Ahmed Mansoor a text message promising "new secrets" about torture in Emirati prisons. Mansoor, trained by then to be suspicious, forwarded the message to Citizen Lab instead of tapping it. Researchers there traced it to three unpatched iPhone vulnerabilities and named the resulting report "The Million Dollar Dissident."

By the time of FORCEDENTRY five years later, NSO Group no longer needed the target to do anything at all. The exploit abused the fact that iMessage automatically ran any file ending in ".gif" through Apple's CoreGraphics rendering engine — a step that happened outside the "BlastDoor" sandbox Apple had built specifically to contain this class of attack. Apple assigned the flaw CVE-2021-30860 and patched it on September 13, 2021, after Citizen Lab disclosed it. Apple's own advisory described the bug in three words: a maliciously crafted PDF.

The Company's Own Rules

NSO Group's public position has been consistent for over a decade: it sells Pegasus only to "vetted" government law enforcement and intelligence agencies, only for preventing crime and terrorism, and it does not operate the systems itself once they are sold. The company has said it has turned down more than $300 million in potential sales over human rights concerns.

  • NSO Group states it "sells its technologies solely to law enforcement and intelligence agencies of vetted governments for the sole purpose of saving lives through preventing crime and terror acts."
  • The company says it does not have access to the data its government customers collect using Pegasus.
  • Citizen Lab's first published Pegasus case — Ahmed Mansoor, a human rights defender with no terrorism or criminal record — predates the company's public defenses of its vetting process by years.

The Circle Around a Murdered Journalist

In April 2018, Hanan Elatr — married to Washington Post columnist Jamal Khashoggi — was detained and questioned by security agents at Dubai International Airport. Forensic analysis by Citizen Lab's Bill Marczak, later reported by The Washington Post, found that Pegasus had been manually installed on her phone during that detention, attributed with high confidence to a UAE government operator. Around the same period, Citizen Lab concluded with high confidence that the Saudi government had used Pegasus to target the phone of Omar Abdulaziz, a Montreal-based activist and one of Khashoggi's closest collaborators, who was in frequent contact with Khashoggi in the months before his death. Khashoggi was killed by Saudi agents inside the Saudi consulate in Istanbul on October 2, 2018.

Separately, a forensic report commissioned by Amazon founder Jeff Bezos's security team found it "highly probable" that his phone was compromised by a video file sent on May 1, 2018 from the personal WhatsApp account of Saudi Crown Prince Mohammed bin Salman — after which data leaving Bezos's phone increased by an estimated 29,156 percent. Two United Nations special rapporteurs, Agnès Callamard and David Kaye, called the incident consistent with the tools NSO Group's spyware provides and urged an investigation.

Fifty Thousand Numbers

In July 2021, Forbidden Stories, a Paris-based journalism nonprofit, and Amnesty International's Security Lab published the Pegasus Project — an investigation by more than 80 journalists at 17 media organizations built around a leaked list of over 50,000 phone numbers selected by NSO Group government clients across more than 50 countries since 2016. The list included close to 200 journalists in 24 countries, along with human rights defenders, lawyers, and heads of state.

  • Forensic testing confirmed Pegasus infections on the phones of New York Times reporter Ben Hubbard and exiled Russian journalist Galina Timchenko.
  • Citizen Lab found at least 36 personal phones belonging to Al Jazeera journalists and executives, including reporter Rania Dridi, had been compromised.
  • Citizen Lab identified 65 phones belonging to Catalan activists, politicians, and civil society figures in Spain that had been targeted or infected with Pegasus.
  • Mexican human rights organizations representing victims of military abuses were also found among those targeted with iOS zero-click exploits.

Washington Adds NSO to a List

On November 3, 2021, the U.S. Commerce Department's Bureau of Industry and Security added NSO Group and fellow Israeli firm Candiru to its Entity List, restricting their access to U.S. technology. The agency's stated basis was that the companies had "developed and supplied spyware to foreign governments that used these tools to maliciously target" government officials, journalists, businesspeople, activists, academics, and embassy workers — enabling what the department called transnational repression. Within weeks, credit analysts were describing NSO Group as at risk of defaulting on roughly $400 million in debt.

Two Lawsuits, Two Different Endings

Apple sued NSO Group and its parent, Q Cyber Technologies, in federal court on November 23, 2021, seeking a permanent injunction barring the company from using any Apple product or service, and pledging $10 million plus any damages awarded toward organizations researching cyber-surveillance abuses. Nearly three years later, in September 2024, Apple abruptly withdrew the suit, telling the court that continuing to litigate risked exposing its own threat-intelligence methods to "the very adversaries" it was suing, and that increasing government and industry pressure had already "substantially weakened" companies like NSO Group.

Meta's WhatsApp had sued separately in 2019, alleging NSO Group exploited a vulnerability in WhatsApp's servers between April and May of that year to install Pegasus on more than 1,400 devices belonging to journalists, human rights activists, and dissidents. In May 2025, a jury in the Northern District of California returned the first verdict of its kind against a commercial spyware company, awarding WhatsApp $444,719 in compensatory damages and $167,254,000 in punitive damages. In October 2025, Judge Phyllis Hamilton reduced the punitive award to $4 million, citing legal limits on the ratio between punitive and compensatory damages — but she also issued a permanent injunction barring NSO Group from ever targeting WhatsApp again.

Who Owns Pegasus Now

NSO Group's co-founder and chief executive, Shalev Hulio, stepped down in 2022 amid layoffs of roughly 100 employees as the company's finances deteriorated under the weight of its blacklisting and mounting legal bills. In October 2025, NSO Group confirmed it had been acquired by a group of U.S. investors, led by Hollywood producer Robert Simonds, who pledged roughly $300 million to rebuild the company. The new ownership group named David Friedman — the former U.S. ambassador to Israel under President Trump, and previously Trump's personal bankruptcy attorney — as chairman. As of May 2025, NSO Group had also retained a lobbying firm with ties to the Trump administration in an effort to be removed from the Commerce Department's Entity List.

NSO Group's spyware remains, as of publication, on that Entity List. Its new chairman spent his prior career keeping his clients' companies out of bankruptcy court; his newest client's product was found, in April 2018, on the phone of a woman being interrogated by the security services of one of the governments it was licensed to serve, months before her husband was killed by agents of a different one.


Filed from public reporting:

Read more

A Hand-Tightened Blind Flange and a Botched Shift Handover Killed 167 Men on Occidental Petroleum's Piper Alpha Platform in 22 Minutes. No One at the Company Was Ever Criminally Charged.

A Hand-Tightened Blind Flange and a Botched Shift Handover Killed 167 Men on Occidental Petroleum's Piper Alpha Platform in 22 Minutes. No One at the Company Was Ever Criminally Charged.

At around 10 p.m. on July 6, 1988, a pressure safety valve that had been pulled for maintenance that morning let gas condensate leak past a blind flange that had only been hand-tightened. Within 22 minutes, the Piper Alpha platform, 120 miles northeast of Aberdeen in the North

By The Complaints Department
Netflix Spent Six Years Telling Customers Love Is Sharing a Password. Once It Started Charging $7.99 a Month Per Shared Password Instead, Subscriber Growth Hit Its Best Year Since the Pandemic.

Netflix Spent Six Years Telling Customers Love Is Sharing a Password. Once It Started Charging $7.99 a Month Per Shared Password Instead, Subscriber Growth Hit Its Best Year Since the Pandemic.

On March 10, 2017, Netflix's official Twitter account posted four words that would follow the company around for the next six years: "Love is sharing a password." It was a promo tweet for a show called Love, but it was also, unmistakably, a policy statement — an

By The Complaints Department
New York Paused Congestion Pricing for 'Affordability' Weeks Before a 2024 Election, Then Relaunched It at a Lower Price Once Voting Was Over. A Year Later, Traffic Was Down 11 Percent and the Federal Government Was Still in Court Trying to Kill It.

New York Paused Congestion Pricing for 'Affordability' Weeks Before a 2024 Election, Then Relaunched It at a Lower Price Once Voting Was Over. A Year Later, Traffic Was Down 11 Percent and the Federal Government Was Still in Court Trying to Kill It.

On June 5, 2024, Governor Kathy Hochul stood before reporters and "indefinitely paused" New York's Central Business District Tolling Program, the long-planned congestion charge for driving into Manhattan below 60th Street. The launch was three weeks away. Hochul cited affordability concerns for working- and middle-

By The Complaints Department
Twitter Cut Off the Third-Party Apps That Built Its Developer Ecosystem in January 2023 With No Warning. One of Those Apps Coined the Word Tweet and Designed Twitter's Bird Logo Before Twitter Had Either.

Twitter Cut Off the Third-Party Apps That Built Its Developer Ecosystem in January 2023 With No Warning. One of Those Apps Coined the Word Tweet and Designed Twitter's Bird Logo Before Twitter Had Either.

On January 13, 2023, Twitter's API went dark for third-party client apps with no announcement and no explanation. Tweetbot, Twitterrific, Fenix, and others simply stopped working, all at once, for everyone. Developers spent days guessing whether it was a bug, an outage, or deliberate. Four days later,

By The Complaints Department