Just enter the phone number and read other people's correspondence. How NSO Group turned total surveillance into a convenient web service

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
345
Reaction score
508
Deposit
0$
To hack a smartphone with Pegasus, the operator often needs to know the victim’s phone number. The rest of the work is taken by the complex infrastructure of the NSO Group, which determines the model of the device, selects a way of infection, hides the source of the attack and delivers stolen data to the customer. The new technical research for the first time reveals in detail the whole process through the eyes of a person sitting behind the control panel of the spy system.






The authors of the analysis studied internal presentations, instructions and marketing materials of the NSO Group, which became public during the long-term trial of the company with WhatsApp and Meta. The documents confirm many of the conclusions of previous investigations, but at the same time reveal the Pegasus device much deeper. The spy platform looks not like a separate malware, but as a full-fledged surveillance service with operators, analysts, servers, anonymization networks and round-the-clock technical support.





The main servers with the control panel and the archive of the stolen information are usually installed directly in the customer's country, for example, in a secure server state department. However, the key elements of the system remain under the control of the NSO Group. The company develops exploits, serves delivery channels, deploys intermediate nodes and monitors the technical condition of client complexes. Without the constant help of the developer, Pegasus quickly loses its health performance, as iOS, Android and popular apps regularly close the vulnerabilities used.





The traces of the customer are hidden by a special network Pegasus Anonymizing Transmission Network, reminiscent of a closed VPN. Malicious code and stolen information pass through the server chain in different countries, so the victim or researcher does not see the real location of the control system. A separate NSO Group division called White Services registers domains, email addresses, messenger accounts, and servers for each client. Part of the infrastructure, judging by the court materials, was paid for by cryptocurrency to make it difficult to find owners.







Each customer receives an isolated set of technical resources. This approach was supposed to protect customers from exposure, but in the end helped the researchers to link different attacks with each other. The same iCloud account, domain or server found on multiple infected devices, indicates one Pegasus operator. The authors of the analysis found no cases when the same attacking account simultaneously served several NSO Group customers.





The work of the operator begins with the creation of a case in the Pegasus browser. Within the case, you can combine several goals related to one organization, investigation or intelligence task. The system supports different roles and access levels. Administrators manage the platform, operators launch infections, and analysts are studying the information collected. Each employee sees only the cases assigned to him, so the average user may not know the general scale of surveillance.





After adding the phone number, Pegasus conducts preliminary reconnaissance. The platform is trying to find out whether the number belongs to the smartphone, which operating system is installed, whether the device is included, which mobile network is connected to the victim, whether the phone is in roaming and which applications are available for attack. The materials mention WhatsApp and iMessage. Some checks require sending hidden requests to the device or network services, so even an unsuccessful hacking attempt can leave traces in magazines.





The information obtained helps the system to choose the appropriate “vector”, that is, an exploit or a method of delivering malicious code. The operator may not see a specific vulnerability. The interface offers only general variants like a hidden attack on iOS, a hidden attack on Android or infection after the user’s actions.





Priority receive attacks without a click, when the phone owner does not need to open a link or confirm the installation. If there is no suitable exploit, Pegasus offers to prepare a message with a malicious link. The panel helps create a plausible bait, disguised as the news, notification or a page of a familiar service. After clicking, the link starts the exploits chain, hacks the browser and installs the spy module.





Internal documents mention several code names of such tools. Vector Heaven, which appeared around January 2018, allowed to imperceptibly infect a wide range of Android smartphones through WhatsApp. Other variants of the Hummingbird family were called Eden and Erised, and the latter, judging by the materials, worked only on Samsung devices. For the iPhone used vectors Diablo and Dragonfly, which attacked the components of iOS and iMessage. After closure of vulnerabilities, NSO Group released new options.





Pegasus also supported infection through a mobile network. In cooperation with the operator, the victim’s Internet traffic could be imperceptibly redirected to the server with a exploit during the usual browsing of sites. The documentation also encounters attacks when physically accessing a smartphone, and one partially hidden partition probably describes infection through wireless interfaces at a short distance from the target.





If direct hacking is impossible, NSO Group offered the “close circle” tactics. Instead of the main goal, the operator infects the smartphones of colleagues, friends or family members to collect the necessary information through their correspondence, meetings and contacts. Similar attacks were previously recorded against relatives of journalists and representatives of the political opposition, including minors.





After successfully installing, Pegasus turns the smartphone into a universal surveillance tool. The panel sorts the received information by category, including calls, messages, email, calendar, contacts, browser history, documents, applications and photos. A separate section stores passwords, authorization tokens and other accounts. Such access allows you to continue surveillance through cloud accounts even after deleting the spy module from the phone. The internal description of the product promised a continuous stream of data from the cloud for several months.





The operator can not only read the information already collected, but also send the commands to the smartphone. Among the available functions are called the inclusion of a microphone, location determination, creating a camera image and capturing the screen. Sound recording can be planned in advance, for example, for the duration of an important meeting found in the victim’s calendar.





The work of client complexes is monitored around the clock by the NSO Group network center. The company claimed that support employees see technical warnings, but did not access the content of the stolen data. Nevertheless, the system must transmit to the developer at least part of the telemetry, otherwise specialists would not be able to notice crashes, exposed servers and unsuccessful attempts to infect.





The published documents also confirm the authenticity of the phone number database, which formed the basis of the Pegasus Project investigation in 2021. The courtroom found the numbers of employees of the NSO Group and the test devices that the company used to demonstrate Pegasus to potential buyers. The same numbers appeared in the leaked database on the coincident dates. Two sets of recordings were associated with internal demonstration systems Sales 3 and Sales 6. Earlier, NSO Group stated that the leak is not related to its technology.





The new materials show how little technical knowledge the finite operator Pegasus is required. The state employee works with a familiar web panel, enters the phone number and selects the proposed attack option, while the search for vulnerabilities, the preparation of infrastructure and hidden delivery takes the NSO Group. Behind the externally simple interface works a constantly updated system that is able to penetrate the smartphone without a single action of the owner and save access to its digital life even after the disappearance of the infection.
 
Top Bottom