Chapter 1
The Digital Predator in Your Pocket
In 2021, the world discovered a terrifying truth: your smartphone, that intimate extension of your mind containing your most private thoughts and communications, could be weaponized against you without your knowledge. The Pegasus Project, a groundbreaking investigation by Forbidden Stories and Amnesty International, revealed that NSO Group's military-grade spyware had targeted over 50,000 phones worldwide-including those belonging to journalists, human rights defenders, business executives, and even heads of state like French President Emmanuel Macron. As Edward Snowden remarked upon learning of the investigation's findings: "Stop what you're doing and read this. This leak is just going to be the story of the year." The book "Pegasus" by Laurent Richard and Sandrine Rigaud takes readers behind the scenes of this momentous investigation that exposed what Rachel Maddow called a "worldwide Orwellian nightmare" and shook the foundations of the unregulated global surveillance industry.
Chapter 2
The Birth of an Invisible Weapon
NSO Group's journey began with two Israeli entrepreneurs, Shalev Hulio and Omri Lavie, who described themselves as "serial entrepreneurs" rather than cybersecurity experts. After military service (though not in the elite Unit 8200 as many assumed), they pursued various tech ventures together. Their first notable attempt was a platform allowing consumers to identify and purchase items seen in TV shows and movies, which failed during the 2008 financial crisis. They then joined CommuniTake, a company developing remote access software for tech support.
According to Hulio, a European intelligence service approached them about adapting this technology for surveillance, explaining they were "going dark" due to encryption advances. When CommuniTake's board rejected this direction, Hulio and Lavie left to establish NSO Group (named after the founders' initials plus a third partner, Niv Karmi, who quickly departed). With $1.6 million in venture capital, they set up shop in a renovated "chicken coop" outside Tel Aviv.
Their timing was perfect-focusing exclusively on mobile surveillance when most security researchers were still focused on desktop systems. By spring 2011, they had developed their flagship product, naming it Pegasus after the mythological flying horse: "a Trojan horse we sent flying through the air to devices."
Mexico proved to be the ideal first market. President Felipe Calderon was five years into a brutal war against drug cartels, with the US providing $1.5 billion through the Merida Initiative. NSO found the perfect guide in Jose Susumo Azano Matsura ("Mr. Lambo"), a wealthy businessman whose company had become a major middleman for foreign surveillance companies. Despite later serving prison time for illegal campaign contributions in the US, Azano was instrumental in NSO's early success, reportedly paying $500,000 for exclusive rights to resell Pegasus in Mexico and arranging demonstrations for Mexico's Secretary of Defense and President Calderon.
Within weeks, SEDENA (Mexico's Secretary of National Defense) closed a $15 million deal, launching NSO as a viable company. While Hulio later insisted NSO always vetted clients for human rights compliance, an NSO insider inadvertently revealed the truth: "If you're a small company struggling to pay salaries and you have ten million dollars coming from a state in Mexico, you don't really think about human rights."
Chapter 3
The Seductive Power of Total Surveillance
"Jose," a pseudonymous former Pegasus operator in Mexico, provided unprecedented insight into the sophisticated technical infrastructure required for modern surveillance operations. The command centers housed in temperature-controlled rooms contained an array of high-powered servers, specialized routers, and extensive storage systems capable of handling terabytes of intercepted data. Multiple redundant systems ensured 24/7 operation, with backup power supplies and cooling systems maintaining optimal conditions for the sensitive equipment.
The infection process was meticulously engineered. Operators crafted personalized SMS messages, often leveraging social engineering techniques and detailed intelligence about targets' interests and relationships. These messages contained specially designed links that, when clicked, would silently install the spyware through zero-day exploits - previously unknown software vulnerabilities. Once successfully deployed, operators gained god-like access to the target's digital life: real-time and historical messages (including those believed deleted), emails, photos, videos, call histories, precise GPS location, and perhaps most disturbingly, could remotely activate microphones and cameras without any indication to the user.
The system architecture comprised three primary capabilities: injection (utilizing a suite of zero-day exploits to penetrate device security), comprehensive monitoring (harvesting contacts, messages, system files, location data, and more), and sophisticated data retrieval and analysis tools. NSO Group provided turnkey solutions including custom hardware configurations, proprietary software suites, ongoing maintenance contracts, and extensive operator training programs. The platform offered multiple "infection vectors" optimized for different device types and operating systems, from iPhones to Android devices.
Security features were paramount, with built-in anonymizers, VPN networks, and encrypted communication channels protecting both operators and infrastructure. The base system could simultaneously monitor 400 phones for a full year, with modular expansion options available for larger operations. Regular updates from NSO kept the system effective against evolving security measures.
While Jose maintains his team operated within legal boundaries targeting organized crime, he offers a stark warning about the system's psychological impact: "These kinds of tools generate in [public servants] who have them within their reach a feeling of supremacy, of power, of control. And its use becomes perverse; it can become a means of personal satisfaction and not for the benefit of the public interest." This transformation from public servant to digital voyeur proved a common pattern.
This seductive power manifested clearly in Mexico. As President Enrique Pena Nieto's administration faced mounting crises - including the tragic disappearance of 43 student-teachers in Guerrero and the explosive "Casa Blanca" scandal revealing the president's questionable $7 million mansion acquisition - Pegasus became a weapon against truth-seekers. Carmen Aristegui, the journalist who exposed the Casa Blanca scandal, received carefully crafted text messages containing surveillance links. Journalist Jorge Carrasco faced similar targeting after investigating Panama Papers connections linking the scandal to elaborate offshore financial networks.
This pattern emerged as a global phenomenon: from Saudi Arabia to India, Hungary to Rwanda, whenever journalists, activists, or opposition figures posed challenges to powerful interests, Pegasus infections appeared in their devices - a sophisticated digital predator relentlessly stalking its prey across borders and jurisdictions.
Chapter 4
The Global Surveillance Marketplace
By 2013, NSO had secured a crucial sale to the UAE-a wealthy regime that could pay 5-10 times what Mexico could with fewer middlemen requiring cuts. This cash infusion challenged competitors like Italy's Hacking Team, which had previously dominated the market under CEO David Vincenzetti, who ran the company like a religion with followers rather than employees, adhering to the philosophy that "Business is not sport... It's war."
The cybersurveillance industry operated on a capitalist cycle of competition, innovation, sales, and investment-with questionable definitions of "better." When Francisco Partners purchased NSO for $120 million-triple Hacking Team's asking price-the balance of power shifted decisively.
Hacking Team's fortunes deteriorated further when Citizen Lab exposed its sales to authoritarian regimes who used the spyware against dissidents and journalists. The fatal blow came July 5, 2015, when hacker "Phineas Fisher" infiltrated Hacking Team's network, stealing and publicly releasing 400GB of internal documents that confirmed unethical sales practices and revealed their obsession with NSO. The hack effectively ended Hacking Team while making NSO the dominant player in the cybersurveillance market.
NSO's success stemmed partly from Israel's unique position in the cybersecurity world. The country's remarkable cybersecurity prowess emerged from its position of vulnerability, requiring constant vigilance against threats from neighboring countries hostile to its existence. Military intelligence became crucial to Israel's survival strategy, with Prime Minister Ben-Gurion establishing it as a pillar of defense doctrine. After the intelligence failure of the 1973 Yom Kippur War, Israel fed its best brainpower into Unit 8200, where innovation mattered above all and ideas trumped rank.
Unit 8200 created a pressure-cooker environment where young cyber specialists worked grueling shifts, sometimes 24-48 hours during special operations. "It's a hyper-stressed, hyper-worked technical environment where you have to make real choices," explained one veteran. "Nobody tells you exactly what to do. They tell you, 'This is the problem; go figure it out.'" This entrepreneurial approach created an elite cadre of cyber specialists who felt they were "part of this special ring" with access to information known only to top government officials.
Under Netanyahu's leadership, Israel's cybersecurity industry boomed-growing from 171 firms in 2013 to 420 in 2017, with private investments sextupling to over $800 million. His approach followed free market principles with one simple rule: "don't overregulate."
Chapter 5
The Human Cost of Digital Surveillance
The real-world consequences of Pegasus surveillance were devastating for those targeted. Moroccan journalist Omar Radi's journey embodied the transformation of technology from liberation tool to instrument of repression. Beginning in 2008 with pranking surveillance authorities, Omar became central to Morocco's February 20 Movement in 2011, advocating for democratic reforms.
His investigative journalism exposed how public resources enriched the monarchy's allies. When investigating a land deal giving Qatari royalty public land, he was followed by government agents and his phone conversations leaked to pro-government media. After tweeting criticism of a judge in 2019, Omar was arrested twice, eventually receiving a suspended four-month sentence.
On June 22, 2020, Forbidden Stories published their investigation revealing Omar had been targeted with Pegasus spyware. Two days later, he was summoned by police and interrogated for six hours. Pro-government media was tipped off to film his "perp walk," while prosecutors accused him of "working with foreign intelligence agencies." Despite maintaining his defiance-"I'm not afraid of anything. I'm going with my head held high"-Omar faced escalating harassment.
By July 29, Omar was arrested on new charges of accepting money from foreign intelligence, "undermining state security," and rape. Nine months later, with the Pegasus Project gaining traction elsewhere, Omar remained in jail with little hope of mounting a real defense. He would eventually be sentenced to six years in prison on dubious charges, his health declining after a year in jail-exactly what King Mohammed VI intended as a warning to other journalists.
In Azerbaijan, award-winning investigative journalist Khadija Ismayilova faced similar persecution after exposing the Aliyev family's vast corruption. Despite blackmail attempts with hidden camera sex videos in 2012 and later imprisonment on fabricated charges, she continued her work. Forensic examination revealed relentless Pegasus attacks on her phone starting March 28, 2019-just days after NSO Group announced a new corporate governance regime supposedly aligned with UN human rights principles.
When finally informed about the Pegasus targeting in 2021, Khadija was overwhelmed with guilt-not just for herself, but for everyone she'd inadvertently compromised: "It's not just me," she lamented, angry at both the Aliyev regime and the companies selling such tools to repressive governments.
Hungarian journalist Szabolcs Panyi discovered his phone had been compromised in 2019, allowing the government to access everything he saw, spoke, and wrote-including encrypted Signal messages. The infection occurred while he was meeting an arms dealer investigating the Trump-Orban relationship. When forensic analysis revealed half of his small news organization's editorial staff had been targeted, the journalists realized they were facing a massive story that would require extensive investigation.
Chapter 6
The Technical Marvel Behind the Menace
The Security Lab's analysis revealed that while the actual Pegasus malware was relatively ordinary, the exploit system used to inject it was extraordinarily sophisticated. NSO was deploying "zero-day exploits"-attacks exploiting vulnerabilities unknown to companies like Apple, giving them zero days to fix the problem before an attack. These zero-days were particularly valuable because they targeted previously undiscovered weaknesses in operating systems, making them virtually impossible to defend against until discovered.
Modern devices typically require chains of three or more exploits to break through security protections, with each exploit chain potentially worth millions of dollars on the black market. A single comprehensive exploit chain could fetch upwards of $2-3 million from government buyers. Claudio Guarnieri of Amnesty International believed NSO was spending considerable resources on in-house research to develop proprietary zero-day weapons, maintaining a team of elite researchers and developers. This investment made economic sense given their dozens of paying customers, each potentially paying hundreds of thousands of dollars per target.
The researchers observed NSO engaging in a constant cat-and-mouse game with Apple, needing to compromise multiple security layers simultaneously to gain complete control of an iPhone. These layers included the initial entry point (often iMessage), privilege escalation to gain system access, and kernel exploitation to disable security features. When Apple patched one vulnerability, NSO would need to find alternatives within days or weeks, making the entire process extremely complex but highly profitable given their reported $1 million per-target fees.
By June 2021, Claudio and his colleague Donncha O Cearbhaill had pieced together the sophisticated zero-day, zero-click iMessage exploit chain that Pegasus had been using throughout the year. They named it "Megalodon" after history's largest shark species, reflecting its unprecedented power and sophistication. Their analysis revealed how NSO cleverly disguised malicious processes by slightly altering legitimate Apple process names-changing "ckkeyrolld" to "ckkeyrollfd" or "fseventsd" to "eventsfssd." This technique made the malware nearly invisible to casual inspection and allowed it to persist even through system reboots.
Their evolving forensic tool became increasingly sophisticated, allowing them to identify patterns connecting different NSO clients through specific fabricated iCloud accounts used to launch attacks. Hungarian targets were contacted by fake accounts like "jessicadavies1345@outlook.com" while Moroccan targets received messages from accounts like "bergers.o79@gmail.com." This pattern recognition helped them track NSO's operations across different countries and identify new victims more quickly.
In one particularly striking case, when examining Carine Kanimba's phone (daughter of "Hotel Rwanda" hero Paul Rusesabagina), they discovered Pegasus was actively infecting her device at that very moment. The malware was attempting to establish persistence and communicate with its command servers. This marked a significant development-they were now finding live infections rather than historical cases, putting them "head-to-head" with NSO's operations and allowing them to observe the attack methodology in real-time. This breakthrough provided unprecedented insight into how Pegasus operated and helped develop better detection methods.
Chapter 7
The Pegasus Project: Exposing the Invisible
The Pegasus Project began when Laurent Richard and Sandrine Rigaud of Forbidden Stories traveled to Berlin to meet with Claudio Guarnieri and Donncha O Cearbhaill from Amnesty International's Security Lab. Taking strict security precautions, they discussed "the List"-tens of thousands of phone numbers targeted by NSO Group's Pegasus spyware.
The magnitude of the task was dizzying-fifty thousand possible leads worldwide. They needed to authenticate the data beyond just trusting their source, determine what being on the list meant, and identify as many phone numbers as possible. For guidance on high-stakes journalism conducted in secrecy, they turned to Bastian Obermayer, the journalist who had broken the Panama Papers story.
Unlike the Panama Papers, which explicitly named subjects in millions of documents, their investigation required finding evidence of spyware attacks in actual phones. This depended on Claudio Guarnieri's expertise, as he and Donncha were developing forensic tools to capture traces of Pegasus infections. Without their technical capabilities, the list remained indecipherable digital hieroglyphics.
The investigation expanded methodically, starting with trusted media outlets like the Washington Post, Le Monde, Die Zeit, and Suddeutsche Zeitung, then growing worldwide to chase promising leads. The team decided to break the story simultaneously across all partners rather than in geographic waves, as NSO's aggressive legal team might intimidate partners still working on stories.
By early 2021, the project was gaining momentum. The technical team had ingeniously created their own caller ID operation to match numbers to names, starting with Truecaller, an app with over 200 million users worldwide that automatically scrapes contacts from users' phones. They reverse-engineered the code and wrote a Python script that could safely crawl the database. Initially limited to about sixty matches per day, they soon expanded to using twenty different anonymous phones with separate Truecaller accounts, increasing their capacity to around 1,200 identifications daily.
This digital treasure hunt was already yielding significant discoveries, including members of French President Macron's government and a son of Turkish President Erdogan. As more media partners joined, the operation expanded beyond simple identification to verification through multiple sources, background research on potential targets, and analysis of targeting patterns in the data.
Chapter 8
The Reckoning: Publication and Aftermath
At 6 p.m. French time on Sunday, July 18, 2021, the Pegasus Project went live across seventeen media outlets in ten countries. Edward Snowden tweeted: "Stop what you're doing and read this. This leak is just going to be the story of the year."
The backlash from NSO was predictable. Shalev initially maintained a conciliatory tone, claiming NSO "cares about journalists and activists" while repeating company talking points: they only sell to governments, have no visibility into targets, and operate under Israeli regulation. But as the consortium's stories gained global traction, NSO's response grew angrier and more conspiratorial. They claimed the list had no relation to them, called the number of selections "insane," and disputed the forensics without identifying specific errors. Three days in, NSO declared "Enough is enough" and announced they would no longer respond to media inquiries.
Official confirmations of Pegasus attacks continued emerging after publication. France's National Cybersecurity Agency verified findings about targeted journalists, plus identified additional victims including five government ministers. Other revelations followed: the emir of Dubai using Pegasus against his estranged wife, Israel targeting Palestinian activists, and Mexico arresting someone for using Pegasus against journalist Carmen Aristegui-the first known case of a private company deploying the spyware against a citizen.
Apple responded by patching the Megalodon exploit, developing a Lockdown Mode for its devices, and suing NSO as "amoral 21st century mercenaries." The company began alerting iPhone users to spyware attacks, revealing eleven US embassy employees in Uganda had been hacked. The US government then took the unprecedented step of blacklisting NSO, cutting the Israeli company off from American technology suppliers like Dell, Intel, Cisco, and Microsoft.
By November 2021, four months after publication, NSO was taking on serious water. Their incoming CEO fled before his official start date, citing "special circumstances." Novalpina, the private equity firm that had become majority owner in 2019, had collapsed, leaving consultants to manage shareholder interests. Even the Oregon state pension fund was questioning its investment in what the US government now called a tool of "transnational repression."
Sales of Pegasus slowed to a trickle, with Moody's warning of possible debt default. In a desperate move, Shalev proposed selling to "elevated-risk" customers again, alarming NSO's financial minders. Despite securing a $10 million loan to cover payroll, Shalev's "phoenix plan" to offload Pegasus liabilities failed to materialize.
Chapter 9
The Ongoing Battle for Digital Privacy
While NSO's demise serves as a cautionary tale for spyware traffickers, the fundamental problems remain unsolved. Despite numerous government hearings and investigations following the Pegasus Project, including high-profile sessions in the European Parliament and U.S. Congress, there has been plenty of "lip-flapping" but very little actual regulation. The cybersurveillance industry continues to operate without real guardrails, exploiting loopholes in international law and the inherent difficulties in regulating borderless digital threats.
Meanwhile, other companies have rushed to fill the void left by NSO's decline. The UAE created its own sophisticated spyware operation, DarkMatter, aggressively hiring away NSO's top talent and former NSA agents with seven-figure salary offers. Similar operations have emerged in Cyprus, Bulgaria, and other countries with advanced tech sectors but limited oversight. Most concerning is that the client governments who abused Pegasus-Azerbaijan, UAE, Morocco, Rwanda, Saudi Arabia-have suffered virtually no diplomatic, economic, or political consequences for their actions, essentially creating a consequence-free environment for surveillance abuse.
The economics driving this industry remain overwhelmingly compelling: one prominent cybersecurity CEO reported being offered $200 million by Saudi Arabia just months after the Pegasus investigation, highlighting how the demand for these tools has only intensified. Some companies are now offering "Pegasus alternatives" at even higher price points, marketing themselves as more discreet options for government clients. As Rachel Maddow noted in her introduction to the book, our phones have become extensions of our minds, containing our most intimate thoughts, communications, photos, and location data, yet Pegasus-style technology can breach this privacy for anyone who attracts the attention of a powerful adversary.
The Pegasus Project revealed a fundamental truth about our digital age: the same technologies that connect us can be weaponized against us by those with power and resources. In a world where smartphones have become extensions of our consciousness, containing everything from health data to banking information to private conversations, the ability to invisibly penetrate these devices represents not just a privacy violation but an existential threat to human dignity, journalism, and democracy itself. The investigation documented cases where this surveillance led directly to harassment, imprisonment, and even murder of targeted individuals.
The question remains whether governments will finally implement meaningful regulation of this dangerous industry, or if the cycle will simply continue with new companies stepping in to meet the insatiable demand for tools of digital surveillance. Current proposals range from export controls to mandatory disclosure requirements, but achieving international consensus has proved challenging. As Laurent Richard and Sandrine Rigaud demonstrate in their powerful account, the stakes could not be higher-for journalists, activists, dissidents, and ultimately, for all of us who carry these potential spies in our pockets every day. Without decisive action, the arms race between privacy protection and surveillance technology threatens to fundamentally reshape the relationship between citizens and states in the digital age.