Search

CloudSEK Report Highlights the Surge of the Fake Pegasus Spyware Following Apple’s Threat Notifications

In its report, CloudSEK says it investigated the incidents involving fake Pegasus spyware in dark and deep web sources.

Advertisement
Highlights
  • In its advisory, Apple mentioned Pegasus spyware as an example
  • CloudSEK found six unique samples of Pegasus HVNC between 2022-24
  • CloudSEK checked 15 spyware samples, none of which belonged to Pegasus
CloudSEK Report Highlights the Surge of the Fake Pegasus Spyware Following Apple’s Threat Notifications

CloudSEK examined 25,000 Telegram posts and found a large portion claimed to sell Pegasus source code

Photo Credit: Unsplash/Clément Hélardot

CloudSEK, a cybersecurity firm, led an investigation after Apple's threat notifications were sent out to iPhone users in 92 countries last month, and found that soon after the advisory was released, the deep and dark web saw a rise of fake Pegasus spyware. Notably, Apple did not name any threat actors in association with its warning, but it did mention Pegasus spyware from the NSO group as an example. CloudSEK believes this could have led to scammers selling fraudulent malware as Pegasus source code.

Details of CloudSEK's investigation

After Apple's warning in April, CloudSEK researchers began delving into the deep and dark web, as well as the surface web to see whether authentic Pegasus spyware was available to purchase or if fraudsters were using its name to swindle potential buyers.

In a report titled “Behind the Advisory: Decoding Apple's Alert and Spyware Dilemma”, the cybersecurity firm stated that it frequented Internet Relay Chat (IRC) platforms. After analysing approximately 25,000 posts on Telegram, researchers found that a major portion of the posts claimed to sell authentic Pegasus source code.

cloudsek telegram pegasus CloudSEK investigation

CloudSEK's investigation in Telegram
Photo Credit: CloudSEK

These sale alert posts followed the same pattern. It used words such as NSO Tools and Pegasus to entice buyers. Interacting with more than 150 potential sellers of such “Pegasus” spyware, the report found that the samples included source code, live video demonstrations of using the malware, and snapshots of the source code. These were all done with names suggesting Pegasus.

Researchers also found six unique samples named Pegasus HNVC (Hidden Virtual Network Computing) posted on the deep web between May 2022 and January 2024, suggesting the proliferation of these samples among threat actors. Similar instances were also found on the surface web.

CloudSEK's findings

The cybersecurity group eventually obtained 15 samples and more than 30 indicators from various sources. However, it found that “nearly all of them have been creating their own fraudulent, ineffective tools and scripts, attempting to distribute them under Pegasus' name to capitalise on Pegasus and NSO Group's name for substantial financial gain.”

It is believed that groups of bad actors have used the sensationalism created by Apple's advisory and multiple news reports mentioning the Pegasus name and used it to sell self-created random samples labelled Pegasus. While these spyware can still be nefarious and harm the victims, they are likely not associated with the NSO Group or Pegasus.

The report has urged critical examination after an incident of a threat attack to correctly attribute the threat actors as it can both help cybersecurity firms in identifying and suggesting reinforcements and will ensure no panic is spread among people.


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Apple iPhone 16e Review: When You Just Need an iPhone
  2. Motorola Edge 60 Pro May Reportedly Come With a Mystery New Button
  3. Poco F7 Ultra, Poco F7 Pro Launched With Snapdragon Chipsets
  4. iQOO Z10 Charging Speed Revealed; India Pricing Tipped
  5. Airtel Launches IPTV Services With Bundled OTT Apps in India
  6. Why Google Is Reportedly Preparing to Develop Its Android OS in Private
  7. Infinix Note 50X 5G With Dimensity 7300 Ultimate SoC Launched in India
  8. Nothing's Essential Space Feature Might Soon Require a Subcription
  9. Motorola Razr 60 Spotted Online; Design, Key Specifications Leaked
  10. Apple iPhone 17 Series Said to Offer 8K Video Recording
  1. Study Finds grey Seals Can Track Blood Oxygen to Prevent Drowning
  2. Robinhood OTT Release Date: When and Where to Watch Nithiin’s Heist Comedy
  3. Ring Ring Ring Now Streaming: Where to Watch Praveen Raj’s Tamil Comedy-Drama Online
  4. Den of Thieves 2: Pantera OTT Release Date: When and Where to Watch it Online?
  5. Japan’s Universal Memory Breakthrough Reduces Energy, Boosts Speed
  6. China’s ‘Kill Mesh’ Threatens US Satellites, Space Force Warns
  7. New Study Challenges Claims of Vast Underground Water on Mars
  8. Asgard Archaea May Hold the Key to the Origins of Eukaryotic Life, New Study Suggests
  9. SpaceX Sets Falcon 9 Reuse Record with NROL-57 Launch from Vandenberg
  10. Tomb Raider Developer Crystal Dynamics Announces Layoffs
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »