How can you check if your phone has been infected with Pegasus?

Pegasus: software designed to monitor iOS and Android phones

Pegasus is software developed by the NSO Group that allows for the extraction of information from iOS and Android phones. The data retrieved can include sent or received messages, contacts, microphone and camera access, GPS data, and even calls. This article explains how to check if your phone has been infected by Pegasus.

How does Pegasus infect a phone?

Pegasus is installed on a phone via cyberattacks, relying on:

  • a "spear-phishing" attack (or " targeted phishing "), which involves sending a trap that prompts the target to perform an action such as clicking a link, which then triggers the installation of Pegasus;
  • exploiting a vulnerability affecting the targeted system (iOS or Android) by sending a message containing an exploit, which is a toolkit used to leverage the vulnerability.

When the installation relies on exploiting a vulnerability, it may involve vulnerabilities not yet known to the international community, also known as "Zero-Day vulnerabilities." These vulnerabilities, kept secret, are formidable: because they are unknown to the international community, there are no measures in place to identify them. Consequently, they are also extremely expensive.

The value of a Zero-Day vulnerability lies in maintaining that secrecy: as soon as these vulnerabilities are spotted, they are published internationally and a security patch is released to neutralize them. Once discovered, the vulnerability joins the family of "known" or "One-Day" vulnerabilities referenced in the CVE (Common Vulnerabilities and Exposures) database.

Is Pegasus installed on your phone and has it infected it?

Acquisition of the Pegasus software is restricted to specific organizations, partly due to the significant financial investment required and partly due to the NSO Group's client selection process.

Given these conditions, it is statistically unlikely that Pegasus is installed on your phone.

How to check if your phone has been infected by Pegasus?

Amnesty International provides a tool called MVT (Mobile Verification Toolkit), under a license derived from the Mozilla Public License v2.0. Use of MVT is subject to the explicit prior consent of the owner of the phone being analyzed.

This tool allows you to analyze files extracted from a phone and search them for Indicators of Compromise (IoCs).

In addition to MVT, Amnesty International also provides a dataset in STIX2 (Structured Threat Information Expression) format on GitHub.

Using MVT with the STIX2 dataset requires some technical skills, and Cyberwatch provides this tutorial to help you check whether your phone has been infected with Pegasus.

Time required: 4 hours.

1. Download and install the MVT project

MVT installation is described in detail on the project's Git repository.

To install MVT on a Linux system:
Install the prerequisites with the command: sudo apt install python3 python3-pip libusb-1.0-0
Then install MVT with the command: pip3 install mvt

To install MVT on a macOS system:
Install Brew using the command:

/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"

Install the prerequisites using the command: brew install python3 libusb
Then install MVT using the command: pip3 install mvt

To install MVT on a Windows system:
Install WSL (Windows Subsystem for Linux) using the official Microsoft documentation.
Then install a Linux distribution on your Windows system and follow the procedure for Linux.

2. Download the Pegasus indicators of compromise file

Download the pegasus.stix2 file from the following GitHub link and note its location on your computer.

3. Identify the phone type

The process for checking a phone with MVT depends on the target operating system. You must therefore verify whether the phone to be analyzed is running Android or iOS.

If the phone to be analyzed is running iOS, proceed to step 4. If the phone to be analyzed is running Android, skip directly to step 7.

4. For iOS phones: preparing data for analysis

The easiest way to analyze an iOS phone is to create a backup and then analyze that backup using MVT.

Warning: to get the most data, the backup must be password-protected! Otherwise, it will contain less information for security reasons.

To back up your phone, connect your iPhone to your computer using a USB cable.

If you have iTunes, launch it and create a local backup of your phone, making sure it is encrypted.

On macOS, you can also perform the backup from the Finder via the following procedure.

Your backup can then be found in:

  • on Windows, in %USERPROFILE%\Apple\MobileSync\ or %USERPROFILE%\AppData\Roaming\Apple Computer\MobileSync\ ;
  • on macOS, in ~/Library/Application Support/MobileSync/.

5. iOS phone: converting the backup to an easy-to-use format

Since the backup is initially encrypted, you must use MVT to decrypt the data and make it easier to work with.

To do this, run the following command:

mvt-ios decrypt-backup -p <YOUR_PASSWORD> -d <DESTINATION_PATH> <ENCRYPTED_BACKUP_PATH>

replacing YOUR_PASSWORD with your backup encryption password, DESTINATION_PATH with the directory where your decrypted backup will be saved, and ENCRYPTED_BACKUP_PATH with the directory of your backup (see step 4).

Wait for the operation to complete, which may take several minutes.

6. iOS phone: analyzing the decrypted backup

You can now start the analysis process.

To do this, run the following command:

mvt-ios check-backup --output <ANALYSIS_DESTINATION> --iocs <IOCS_LOCATION>/pegasus.stix2 <DECRYPTED_BACKUP_LOCATION>

replacing ANALYSIS_DESTINATION with the directory that will contain the MVT results, IOCS_LOCATION with the location of the pegasus.stix2 file (see step 2), and DECRYPTED_BACKUP_LOCATION with the directory of your decrypted backup (obtained in step 5).

MVT will highlight suspicious activities related to Pegasus. You can then proceed to step 10.

7. Android phone: preparing your computer

For Android, data preparation involves:

  • extracting the phone's applications in APK format to analyze them on VirusTotal and Koodous;
  • extracting messages to analyze them with Pegasus IOCs.

This procedure requires:

  • installing MVT (see step 1);
  • installing ADB (Android Debug Bridge, via the official procedure);
  • enabling developer mode on your phone using this procedure ;
  • Java installed on your computer ;
  • downloading ABE (Android Backup Extractor) via the following GitHub repository (simply take the abe.jar file and note its location on your computer).

8. Android phone: analyzing applications

Connect your phone to your computer using a USB cable.

Then, open a shell and run the command:

mvt-android download-apks --output <DESTINATION_DIRECTORY> --all-checks

replacing <DESTINATION_DIRECTORY> with the location of a folder on your computer where the APKs will be downloaded.

9. Android phone: analyzing SMS

Connect your phone to your computer using a USB cable.

Start the extraction with the command: adb backup com.android.providers.telephony

You will get a file named backup.ab.

This file cannot be used as is and must be converted into a format that is easier to handle.

To do this, run ABE using the command:

java -jar <ABE_LOCATION>/abe.jar unpack <BACKUP_LOCATION>/backup.ab <DESTINATION>/backup.tar

replacing EMPLACEMENT_ABE / EMPLACEMENT_BACKUP / DESTINATION each time with the ABE location, the backup location, and the destination of the converted file.

Next, decompress the backup.tar file using the program of your choice (7Zip, tar, etc.) into a directory named android-backup-decompresse.

Finally, run the command:

mvt-android check-backup --iocs <EMPLACEMENT_IOCS>/pegasus.stix2 --output sms <EMPLACEMENT_TAR_DECOMPRESSE>/android-backup-decompresse

replacing EMPLACEMENT_IOCS with the directory containing pegasus.stix2 (file from step 2), and EMPLACEMENT_TAR_DECOMPRESSE with the directory containing android-backup-decompresse.

MVT will then run an analysis of your SMS messages using the indicators of compromise file and highlight any identified anomalies. You can proceed to step 10.

10. Analyze the results

If suspicious items are present, it is highly likely that your phone has been targeted by Pegasus.

Otherwise, it means that no evidence from the work of Amnesty International and Forbidden Stories allows us to conclude that your phone has been targeted by Pegasus.

What should you do if your phone has been compromised by Pegasus?

Cyberwatch recommends that you contact the authorities using the contact details provided on the website of the National Cybersecurity Agency of France (ANSSI).

How can you limit the risk of attacks on your phone?

A phone relies on technologies developed by humans, who occasionally make mistakes. These errors can lead to security issues known as "vulnerabilities." These vulnerabilities vary in severity and are sometimes dangerous enough to be exploited by operations such as a Pegasus infection.

Cyberwatch recommends consistently following the guidelines in the ANSSI cybersecurity guide, and specifically, regularly installing security updates on your phone.

For any further questions, please contact our experts via this form.

Thanks for submitting the form.