Pegasus Flashcards

1
Q

what is pegasus

A

trojan horse computer virus

The 2021 Project Pegasus revelations suggest that the current Pegasus software can exploit all recent iOS versions up to iOS 14.6. As of 2016, Pegasus was capable of reading text messages, tracking calls, collecting passwords, location tracking, accessing the target device’s microphone and camera, and harvesting information from apps. The spyware is named after Pegasus, the winged horse of Greek mythology. It is a Trojan horse computer virus that can be sent “flying through the air” to infect cell phones.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

who is the developer of pegasus

A

nso group technologies - The company states that it provides “authorized governments with technology that helps them combat terror and crime.

can only be used to criminal and national security investogations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Pegasus was discovered in ______ during a failed attempt to infect Arab human rights defender Ahmed Mansoor’s phone who sent the link sent to him to citizen lab

A

August 2016

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

it was the first time that a malicious remote exploit used _________ to gain unrestricted access to an iPhone.

A

jailbreaking

On Apple devices running iOS and iPadOS-based operating systems, jailbreaking is a privilege escalation exploit executed to remove software restrictions imposed by the manufacturer. Typically it is done through a series of kernel patches. A jailbroken device permits root access within the operating system and provides the opportunity to install software not available through the App Store.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what does pegasus do if it is ubale to communicate with its command and control server for over 60 days

A

Pegasus hides itself as far as is possible and self-destructs in an attempt to eliminate evidence after 60 days. It will do the same if the software has been downloaded on the wrong mobile.

it can also self-destruct on command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what is citizen lab

A

a multi-disciplinary laboratory based in at the Munk School of Global Affairs at the University of Toronto, Canada. and founded in 2001

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

how many countries is pegasus reported to have been used in

A

45 countries including india, bahrain, uae, palestine and us

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

when was it discovered that pegasus could also infect android

A

at the 2017 Security Analyst Summit held by Kaspersky Lab, researchers revealed that Pegasus was available for Android in addition to iOS; Google refers to the Android version as Chrysaor, the brother of the winged horse Pegasus. Its functionality is similar to the iOS version, but the mode of attack is different. The Android version tries to gain root access (similar to jailbreaking in iOS); if it fails, it asks the user for permissions that enable it to harvest at least some data. At the time Google said that only a few Android devices had been infected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what is pegasus for android called and who named it so

A

chrysaor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what kind of exploit is pegasus and what are its infection vectors

A

Rather than being a specific exploit, Pegasus is a suite of exploits that uses many vulnerabilities in the system. Infection vectors include clicking links, the Photos app, the Apple Music app, and iMessage. Some of the exploits Pegasus uses are zero-click—that is, they can run without any interaction from the victim.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what has been dubbes as the Pegasus Anonymizing Transmission Network (PATN) by NSO group

A

Human rights group Amnesty International reported in the 2021 Project Pegasus revelations that Pegasus employs a sophisticated command-and-control (C&C) infrastructure to deliver exploit payloads and send commands to Pegasus targets. There are at least four known iterations of the C&C infrastructure, dubbed the Pegasus Anonymizing Transmission Network (PATN) by NSO group, each encompassing up to 500 domain names, DNS servers, and other network infrastructure. The PATN reportedly utilizes techniques such as registering high port numbers for their online infrastructure as to avoid conventional Internet scanning. PATN also uses up to three randomised subdomains unique per exploit attempt as well as randomised URL paths

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what kind of infrastructure does pegasus use

A

command and control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is pegasus project (2021 july)

A

an international investigative journalism initiative to look into nso group’s espionage software - pegasus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

how did the pegasus project come to be

A

In 2020, a list of over 50,000 phone numbers believed to belong to individuals identified as “people of interest” by clients of the Israeli cyberarms firm NSO Group was leaked to Amnesty International and Forbidden Stories, a media nonprofit organisation based in Paris, France. This information was passed along to 17 media organisations under the umbrella name “The Pegasus Project”.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what were these journalistic agencies and how many journalists worked on the pegasus project

A

over 80 journalists from The Guardian (United Kingdom), Le Monde and Radio France (France), Die Zeit, Süddeutsche Zeitung, WDR and NDR (Germany), The Washington Post and Frontline (United States),[7] Haaretz (Israel), Aristegui Noticias and Proceso (Mexico), Knack and Le Soir (Belgium), The Wire (India), Daraj (Syria),[8] Direkt36 (Hungary),[9] and OCCRP investigated the spying abuses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

pegasus attacks have been launched against _______ in india

A

https://en.wikipedia.org/wiki/Pegasus_Project_(investigation)#Origins_and_members

17
Q

what kind of survelliance does pegasus use

A

remote zero-click surveillance of smartphones.

18
Q

when was nso founded and by whom

A

NSO Group Technologies was founded by Omri Lavie; Shalev Hulio; Niv Karmi; (Left the company one month after its inception)

in 2010

19
Q

who own nso group

A

Novalpina Capital; Omri Lavie; Shalev Hulio

20
Q

where is nso group headquartered

A

Herzliya, Israel

21
Q

who is the founder ceo of nso group technologies

A

shalev hulio

22
Q

the nso group is a subsidiary of

A

Q Cyber Technologies group of companies.

(Q Cyber Technologies is the name the NSO Group uses in Israel, OSY Technologies in Luxembourg, and in North America it has a subsidiary formerly known as Westbridge. It has operated through other companies around the world)

23
Q

pegasus has been classified as a weapon by which country making it neccesary to seek permission for its export

A

israel

24
Q

what is us’s position on pegasus

A

On 3 November 2021 the United States added the NSO Group to its Entity List, for acting “contrary to the foreign policy and national security interests of the US” and it effectively bans the sale of hardware and software to the company.

25
Q

who sued pegasus in november 2021

A

On 23 November 2021, NSO Group were sued by Apple, Inc. for their activities in relation to Apple products.[

26
Q

which surveillance firm did nso merge with in 2014

A

circles

Circles is capable of identifying the location of a phone in seconds, anywhere in the world. It was identified that 25 countries across the world were customers of Circles

27
Q

who venture capital funded nso as a start up for 30% stake

A

a group of investors headed by Eddy Shalev, a partner in venture capital fund Genesis Partners.

invested $1.8 million

28
Q

which american private equity firm bought nso in 2014 and for how much

A

American private equity firm Francisco Partners bought the company for $130 million.

29
Q

who bought 60% majority stake from fransico partners in 2019

A

On February 14, 2019, Francisco Partners sold a 60% majority stake of NSO back to co-founders Shalev Hulio and Omri Lavie, who were supported in the purchase by Novalpina Capital LLP (a european private equity firm).