Pegasus Flashcards
what is pegasus
trojan horse computer virus
The 2021 Project Pegasus revelations suggest that the current Pegasus software can exploit all recent iOS versions up to iOS 14.6. As of 2016, Pegasus was capable of reading text messages, tracking calls, collecting passwords, location tracking, accessing the target device’s microphone and camera, and harvesting information from apps. The spyware is named after Pegasus, the winged horse of Greek mythology. It is a Trojan horse computer virus that can be sent “flying through the air” to infect cell phones.
who is the developer of pegasus
nso group technologies - The company states that it provides “authorized governments with technology that helps them combat terror and crime.
can only be used to criminal and national security investogations
Pegasus was discovered in ______ during a failed attempt to infect Arab human rights defender Ahmed Mansoor’s phone who sent the link sent to him to citizen lab
August 2016
it was the first time that a malicious remote exploit used _________ to gain unrestricted access to an iPhone.
jailbreaking
On Apple devices running iOS and iPadOS-based operating systems, jailbreaking is a privilege escalation exploit executed to remove software restrictions imposed by the manufacturer. Typically it is done through a series of kernel patches. A jailbroken device permits root access within the operating system and provides the opportunity to install software not available through the App Store.
what does pegasus do if it is ubale to communicate with its command and control server for over 60 days
Pegasus hides itself as far as is possible and self-destructs in an attempt to eliminate evidence after 60 days. It will do the same if the software has been downloaded on the wrong mobile.
it can also self-destruct on command
what is citizen lab
a multi-disciplinary laboratory based in at the Munk School of Global Affairs at the University of Toronto, Canada. and founded in 2001
how many countries is pegasus reported to have been used in
45 countries including india, bahrain, uae, palestine and us
when was it discovered that pegasus could also infect android
at the 2017 Security Analyst Summit held by Kaspersky Lab, researchers revealed that Pegasus was available for Android in addition to iOS; Google refers to the Android version as Chrysaor, the brother of the winged horse Pegasus. Its functionality is similar to the iOS version, but the mode of attack is different. The Android version tries to gain root access (similar to jailbreaking in iOS); if it fails, it asks the user for permissions that enable it to harvest at least some data. At the time Google said that only a few Android devices had been infected.
what is pegasus for android called and who named it so
chrysaor
what kind of exploit is pegasus and what are its infection vectors
Rather than being a specific exploit, Pegasus is a suite of exploits that uses many vulnerabilities in the system. Infection vectors include clicking links, the Photos app, the Apple Music app, and iMessage. Some of the exploits Pegasus uses are zero-click—that is, they can run without any interaction from the victim.
what has been dubbes as the Pegasus Anonymizing Transmission Network (PATN) by NSO group
Human rights group Amnesty International reported in the 2021 Project Pegasus revelations that Pegasus employs a sophisticated command-and-control (C&C) infrastructure to deliver exploit payloads and send commands to Pegasus targets. There are at least four known iterations of the C&C infrastructure, dubbed the Pegasus Anonymizing Transmission Network (PATN) by NSO group, each encompassing up to 500 domain names, DNS servers, and other network infrastructure. The PATN reportedly utilizes techniques such as registering high port numbers for their online infrastructure as to avoid conventional Internet scanning. PATN also uses up to three randomised subdomains unique per exploit attempt as well as randomised URL paths
what kind of infrastructure does pegasus use
command and control
what is pegasus project (2021 july)
an international investigative journalism initiative to look into nso group’s espionage software - pegasus
how did the pegasus project come to be
In 2020, a list of over 50,000 phone numbers believed to belong to individuals identified as “people of interest” by clients of the Israeli cyberarms firm NSO Group was leaked to Amnesty International and Forbidden Stories, a media nonprofit organisation based in Paris, France. This information was passed along to 17 media organisations under the umbrella name “The Pegasus Project”.
what were these journalistic agencies and how many journalists worked on the pegasus project
over 80 journalists from The Guardian (United Kingdom), Le Monde and Radio France (France), Die Zeit, Süddeutsche Zeitung, WDR and NDR (Germany), The Washington Post and Frontline (United States),[7] Haaretz (Israel), Aristegui Noticias and Proceso (Mexico), Knack and Le Soir (Belgium), The Wire (India), Daraj (Syria),[8] Direkt36 (Hungary),[9] and OCCRP investigated the spying abuses