Skip to content
Reference

Glossary

Last updated 8 October 2026

Key terms used across this archive, with anchor-friendly entries. Use the filter to narrow.

Zero-click
An exploit that infects the target without any action by the target — no tap, no open, no answered call. The phone's own automatic parsing of incoming data is abused.
One-click
An exploit that requires the target to interact — typically tapping a link or opening a document.
Network injection
Traffic redirected en route, sometimes with carrier cooperation, to deliver an exploit or implant.
Mercenary spyware
Commercial spyware sold to government customers by private companies, as distinct from intelligence-agency-built tools. Pegasus, Predator, and Graphite are examples.
Implant
The malicious code that runs on the target device after a successful exploit, granting the operator access to data and device functions.
Exploit chain
A sequence of vulnerabilities chained together to get from initial access to a running implant.
Zero-day
A vulnerability that is unknown to the vendor and for which no patch exists at the time of exploitation.
CVE
Common Vulnerabilities and Exposurations — a public identifier for a specific disclosed vulnerability.
BlastDoor
An Apple iOS sandboxed service that parses untrusted data from iMessage to limit the reach of message-borne exploits.
Lockdown Mode
An optional Apple iOS setting that reduces attack surface by blocking most message attachment types and complex web features. Not a guarantee.
HLR lookup
A Home Location Register query used to fingerprint a phone number's network and device status.
PATN
Pegasus Anonymizing Transmission Network — NSO-managed infrastructure used to deliver infections and relay operator commands.
IoC
Indicator of Compromise — a forensic artifact (file, domain, behavior) used to detect prior infection.
Forensic artifact
A trace left on a device or in its backups that indicates a past infection or operation.
Entity List
The US Commerce Department's list of entities restricted from receiving US items; NSO was added 3 November 2021.
E2EE vs endpoint compromise
End-to-end encryption protects data in transit; a device-level implant reads data after it is decrypted on the device, so E2EE alone does not stop it.
Phantom
A name used beside Pegasus in some NSO documents for a related configuration — define cautiously as it appears in case filings.
On Sale : Full Zero Click Pegasus Technology , Entire Source Codes & Technical Blueprints .
Complete Tech Stuck ₿ 0.50 BTC .
A spy in your pocket — what Pegasus spyware can secretly access: photos, calls, calendar, camera, microphone, messages, emails, contacts, WhatsApp chats, and GPS data
PEGASUS ZERO-CLICK ARCHIVE

The public record of NSO Group's Pegasus spyware — zero-click infection, documented victims, court cases, and defenses.

pegasus-zeroclick-spyware.shop · Updated 8 October 2026

What this site will not do
  • No exploit code or reproduction steps.
  • No target lists of private individuals beyond already-public cases.
  • No sale, licensing, or procurement guidance.
Evidence standard

Court judgment > forensic lab report > company document in a court filing > major investigative consortium > single secondary blog. Secondary blogs are not used for uncorroborated exploit claims.

Independent public-record archive. Not affiliated with NSO Group, Apple, WhatsApp, Citizen Lab, or Amnesty International. No exploit code is hosted or linked here.