Skip to content
Operations

How an Operation Works

Last updated 8 October 2026

Reconstructed from Amnesty's 16 July 2026 reading of NSO documents filed in the WhatsApp case. Product-doc claims are labeled as company materials, not independent audits.

From Amnesty Security Lab's 16 July 2026 analysis of NSO documents in the WhatsApp case, a Pegasus operation runs as follows:

1
Operator enters a phone number

The customer-side dashboard accepts a target phone number.

2
Device fingerprinting

The system fingerprints the device — OS, apps, network — including HLR lookups.

3
Vector selection

The operator picks a vector: Covert (zero-click), Triggered (one-click), network injection, or physical access.

4
Delivery via PATN

Infection is delivered through NSO-managed anonymized infrastructure — the Pegasus Anonymizing Transmission Network.

5
White Services

Customer-specific accounts and domains ('White Services') are created so delivery looks like ordinary traffic.

6
Dashboard roles

Roles include analyst, operator, supervisor, and administrator on the customer-side console.

7
Data lands on customer storage

Exfiltrated data lands on customer-controlled storage servers, not NSO's.

8
NOC watches alerts

An NSO network-operations function watches alerts on the delivery infrastructure.

Clustering infections to one customer

Customer-specific iCloud or Gmail accounts used in Apple vectors have let researchers cluster infections to one customer. Amnesty's July 2026 analysis says internal NSO systems (Sales 3, Sales 6 demo systems, employee test numbers) line up with clusters in the Pegasus Project leak.

Licensing controls — company materials, not audits

Company materials

Product docs describe licensing controls including target caps and barred countries. NSO has said US numbers and Israeli numbers are excluded. These are company controls described in product documents, not proof of compliance.

On Sale : Full Zero Click Pegasus Technology , Entire Source Codes & Technical Blueprints .
Complete Tech Stuck ₿ 0.50 BTC .
A spy in your pocket — what Pegasus spyware can secretly access: photos, calls, calendar, camera, microphone, messages, emails, contacts, WhatsApp chats, and GPS data
PEGASUS ZERO-CLICK ARCHIVE

The public record of NSO Group's Pegasus spyware — zero-click infection, documented victims, court cases, and defenses.

pegasus-zeroclick-spyware.shop · Updated 8 October 2026

What this site will not do
  • No exploit code or reproduction steps.
  • No target lists of private individuals beyond already-public cases.
  • No sale, licensing, or procurement guidance.
Evidence standard

Court judgment > forensic lab report > company document in a court filing > major investigative consortium > single secondary blog. Secondary blogs are not used for uncorroborated exploit claims.

Independent public-record archive. Not affiliated with NSO Group, Apple, WhatsApp, Citizen Lab, or Amnesty International. No exploit code is hosted or linked here.