Pegasus vs Predator vs Graphite: Mercenary Spyware Compared in 2026
Pegasus, Predator, and Graphite are three different mercenary spyware products from three different companies. This comparison clarifies the differences between NSO Group, Intellexa, and Paragon.

Pegasus, Predator, and Graphite are frequently mentioned together in spyware reporting, but they are not the same product. They are made by different companies, have different capabilities, and have been documented in different contexts. Confusing them leads to inaccurate threat assessment and inaccurate reporting. This post provides a clear comparison.
Pegasus: NSO Group
Manufacturer: NSO Group Technologies, founded 2010 in Herzliya, Israel.
Product: Pegasus is the most extensively documented mercenary spyware in the public record. It has been confirmed on both iOS and Android, with zero-click delivery documented since at least 2017 (iOS) and early 2018 (Android, via the "Heaven" vector in Pegasus 2.50).
Known vectors: iMessage zero-click (KISMET, FORCEDENTRY, BLASTPASS, PWNYOURHOME, LATENTIMAGE, FINDMYPWN, and the Serbia 2025-2026 chain), WhatsApp calling zero-click (CVE-2019-3568), SMS one-click (the 2016 Mansoor case), and others.
Known customers: Multiple governments across multiple continents, including documented or alleged use in Mexico, Saudi Arabia, UAE, India, Hungary, Morocco, Spain, El Salvador, Thailand, Greece, Serbia, and others.
Legal status: NSO was added to the US Commerce Entity List on 3 November 2021. The WhatsApp v. NSO case resulted in a final judgment of $4,447,190 and a permanent injunction (November 2025). NSO underwent a change in controlling ownership in October 2025.
Capabilities: Full device access after infection — messages, calls, camera, microphone, photos, location, emails, contacts, and app data including Signal and WhatsApp content (read after decryption on the device).
Predator: Intellexa / Cytrox
Manufacturer: Intellexa Alliance (formerly Cytrox), a mercenary spyware vendor with operations spanning Greece and other jurisdictions. Intellexa is a different company from NSO Group — they are competitors, not collaborators.
Product: Predator is a separate spyware product with its own exploit chains and infrastructure. It has been documented on both Android and iOS, though the public record on Predator is less extensive than for Pegasus.
Known cases: Predator has been documented in Greece (the case of Thanasis Koukakis and others), in Serbia (prior to the September 2026 Pegasus confirmation, Serbia's documented spyware threat was primarily Predator), and in other countries. The Intellexa consortium has been the subject of export control scrutiny, and Intellexa was added to the US Commerce Entity List.
Key difference from Pegasus: Predator is a different product from a different company. The targeting patterns overlap (civil society, journalists, politicians) because the customer base is similar, but the technical infrastructure, exploit chains, and vendor are distinct. When reporting on spyware in Serbia, for example, it matters whether the confirmed tool was Pegasus (NSO) or Predator (Intellexa) — they are different products with different vendors and different legal contexts.
Graphite: Paragon
Manufacturer: Paragon Solutions, a newer entrant in the mercenary spyware market. Paragon is an Israeli-founded company that has reportedly marketed its Graphite product to government customers.
Product: Graphite is a third distinct product. Less is known about Graphite in the public record than about Pegasus or Predator, but it has been reported in connection with targeting of journalists and activists, including reporting on Italian government use.
Key difference: Graphite is the newest of the three in the public record. Its capabilities, exploit chains, and customer list are less extensively documented. It should not be assumed to be equivalent to Pegasus — it is a different product from a different company.
Why the Distinction Matters
For researchers, journalists, and defenders, conflating these products leads to errors:
- Attribution errors. If a device is infected with Predator, attributing the infection to NSO Group is incorrect. The vendor is Intellexa, not NSO. The legal context is different (different Entity List entries, different litigation).
- Threat assessment errors. Different products have different capabilities, different patch statuses, and different detection indicators. MVT's IoC database is primarily oriented toward Pegasus; detecting Predator or Graphite may require different indicators.
- Policy errors. Regulatory and export control measures are company-specific. The Entity List addition for NSO does not apply to Intellexa or Paragon. Policy responses need to be calibrated to the specific vendor.
How to Tell Them Apart
In practice, the distinction is made through forensic analysis:
- Different indicators of compromise. Pegasus, Predator, and Graphite use different infrastructure (domains, servers, network signatures) and leave different artifacts. Forensic labs like Citizen Lab and Amnesty can distinguish them through IoC analysis.
- Different exploit chains. The documented exploit chains for each product are different. Pegasus has the most extensively cataloged chain list (KISMET, FORCEDENTRY, etc.); Predator and Graphite have their own chains.
- Different operational patterns. The targeting infrastructure and delivery methods differ between products.
When you read reporting about "spyware" infections, check which product is named. If the report says Pegasus, it is NSO Group. If it says Predator, it is Intellexa. If it says Graphite, it is Paragon. If the report does not specify, the product is unidentified — and the analysis should be treated accordingly.
Sources
This comparison draws on: Citizen Lab reports on Pegasus (multiple), Predator (including the Greece and Serbia investigations), and reporting on Graphite; the US Commerce Entity List entries for NSO Group and Intellexa; and court filings in WhatsApp v. NSO. The public record on Predator and Graphite is less extensive than on Pegasus; this comparison reflects the available evidence as of October 2026.







