Exploit archaeology: a forensic history of in-the-wild NSO Group exploits
ID: 5fd69014-2ed0-401a-909b-76bd16b702ed
STIX ID: report--5fd69014-2ed0-401a-909b-76bd16b702ed
Threat Score
92/100
Uploaded: 2026-08-11
Published Date: 2022-09-19
Last Modified Date: 2022-09-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This forensic report documents NSO Group's long-running use of zero-click and one-click exploits to deploy Pegasus spyware against civil-society targets from 2017–2021, identifying six distinct iOS zero-click chains (including ForcedEntry/Megalodon) and an Android WhatsApp exploit, providing technical artifacts, timelines, and indicators useful for detection and attribution.
