Skip to content
Practical · Non-exploit

Detection and Defense

Last updated 8 October 2026

Practical guidance for readers who may be at risk. No exploit content. The single most important action is keeping your phone fully updated; the rest reduces risk and helps confirm or rule out an infection.

Update — the non-negotiable baseline

Every named chain in this archive was patched on the date given. The Serbia case (Citizen Lab + SHARE, 2 September 2026) is a direct lesson: a high-confidence infection window of December 2025–January 2026 on a phone that was patched in iOS 18.4.1. An un-updated phone stays exposed to known, patched chains for as long as it stays un-updated.

Apple Lockdown Mode

Lockdown Mode reduces attack surface by blocking most message attachment types and complex web features. BLASTPASS (September 2023) showed it is not a guarantee — that chain affected Lockdown Mode targets — but it has blocked some later chains in Citizen Lab reporting. It is recommended for high-risk users: journalists, activists, lawyers, officials, and relatives of targets.

Apple threat notifications

Apple sends high-confidence mercenary-spyware warnings to accounts it assesses as targeted. These are not proof of infection by themselves. A recipient who needs forensic evidence should not factory-reset before a forensic image is made.

Forensic checks: MVT and iVerify

Amnesty's Mobile Verification Toolkit (MVT) parses a device backup for indicators of compromise and is the public method used by researchers. iVerify and similar commercial scanners are optional tools, not guarantees. A critical caveat: absence of indicators is not proof of cleanliness, because zero-click implants can self-delete and logs rotate.

If you are notified

  1. Update the device immediately.
  2. Enable Lockdown Mode.
  3. Contact a trusted digital-security lab (Access Now helpline; local groups such as SHARE).
  4. Preserve the device if legal evidence matters — do not wipe it.
Do
  • Keep iOS and Android fully updated. Historical chains died on the patch day; the Serbia case shows un-updated phones remain exposed months after a patch (iOS 18.4.1 patch vs December 2025 infection).
  • Enable Apple Lockdown Mode if you are a high-risk user. It reduces attack surface — blocks most message attachment types and complex web features. BLASTPASS showed it is not magic, but it has blocked some later chains in Citizen Lab reporting.
  • Take Apple threat notifications seriously. They are high-confidence mercenary-spyware warnings — but not proof of infection by themselves.
  • If you need forensic evidence, do not factory-reset before a forensic image is made.
  • Talk to a trusted digital-security lab. Citizen Lab does not take every case; Access Now helpline and local groups such as SHARE are public routes.
Do not
  • Do not rely on ordinary antivirus as a sole control.
  • Do not rely on 'click nothing' as a sole control — zero-click needs no click.
  • Do not assume Signal or WhatsApp encryption stops a post-decrypt implant.
  • Do not treat absence of indicators as proof of cleanliness — zero-click implants can self-delete and logs rotate.
  • Do not wipe a high-risk phone before consulting a forensic lab if the device may be evidence.
On Sale : Full Zero Click Pegasus Technology , Entire Source Codes & Technical Blueprints .
Complete Tech Stuck ₿ 0.50 BTC .
A spy in your pocket — what Pegasus spyware can secretly access: photos, calls, calendar, camera, microphone, messages, emails, contacts, WhatsApp chats, and GPS data
PEGASUS ZERO-CLICK ARCHIVE

The public record of NSO Group's Pegasus spyware — zero-click infection, documented victims, court cases, and defenses.

pegasus-zeroclick-spyware.shop · Updated 8 October 2026

What this site will not do
  • No exploit code or reproduction steps.
  • No target lists of private individuals beyond already-public cases.
  • No sale, licensing, or procurement guidance.
Evidence standard

Court judgment > forensic lab report > company document in a court filing > major investigative consortium > single secondary blog. Secondary blogs are not used for uncorroborated exploit claims.

Independent public-record archive. Not affiliated with NSO Group, Apple, WhatsApp, Citizen Lab, or Amnesty International. No exploit code is hosted or linked here.