Capabilities After Infection
Once resident, public analyses describe broad access to the device. This is why wiping a phone is not a complete answer, and why a trusted forensic lab should be consulted before a wipe if the user is high-risk.
What the implant can reach
Calls, SMS, email, and app data — including WhatsApp, Signal, and iMessage content after it is decrypted on the device.
Photos, files, contacts, calendar, and browsing history.
Location reporting from the device.
Stored credentials on the device.
Microphone activation described in product documents and forensic reports.
Camera activation and photo capture described in product documents.
The implant is designed to hide and, in some versions, to remove itself.
Some versions remove themselves, leaving little forensic trace.
Why wiping is not a complete answer
Cloud tokens taken from the device can keep yielding data after the implant is gone. NSO's own 2018 product description said cloud access can last months. So a factory reset removes the implant from the device but does not revoke access already granted to cloud accounts. A high-risk user should consult a trusted forensic lab before a wipe if the device may be evidence, and should rotate credentials and revoke device tokens for cloud accounts.
The capabilities above come from product documents and forensic reports. The product-document descriptions are company materials, not independent audits.

