Knowing how to detect Pegasus on Android, just like on iOS, is a very common question these days after the latest attack of this spyware against two members of the Spanish government. Beyond the social alarm that this virus has partly caused, is it really possible to detect it? Yes, but we have already told you that it is a almost impossible task.
Detecting Pegasus on iPhone with tools like iMazing is not easy, but it is possible. However, on Android, the issue is further complicated by the peculiarities of the system and the silent and almost hidden character of Pegasus. And it is that even the best mobile antiviruses are not effective for this task. The reasons and how to at least try to detect it are listed below.
The reason we (probably) never get infected with Pegasus
First, we want to put some context on the matter and talk a bit about the origin of Pegasus. And it is that it is a malware developed by the Israeli company NSO and that it is basically oriented towards spy on important people: members of governments, opposition politicians, leaders of important companies, journalists with mediatized information…
Pegasus is not aimed at ordinary citizens, neither because of its sophistication nor because of its high cost to hire.
In short, Pegasus is designed to attack the devices of people around the world who have some power and interest behind them, for which a person (or rather an entity or an organized group) would be willing to pay the ballpark price. half a million dollars it costs hire him according to the New York Times estimates a few years ago. Because no, Pegasus is not new and his first attacks were already known in 2016.
Therefore, first of all, we must tell you that it is very unlikely that someone will decide to attack you personally with Pegasus. Its contracting is done individually, that is to say that it provides for a single attack which, whether it takes effect or not, will not be reimbursable. So, conspiracy aside, I think few people may be at the center of these infections.
Since entering, it is already showing signs of sophistication
Apart from the fact that we are more or less the target audience for this spyware, the truth is that most likely we were never aware of it. Not at least on our own by doing research over the phone or using appropriate tools. Since Pegasus enters the smartphone -this can go through a simple link much more sophisticated than simple phishing- we would be lost.
A harmless SMS message with a link to a “safe web” and a clean, silent connection are the main ingredients of Pegasus.
Security updates from Google and those from the Android layer makers themselves plan to cover possible device vulnerabilities, but Pegasus still comes in with unknown featseven as a complement to fake phone towers or external devices capable of cloaking a seemingly innocuous link and directing us to another website.
Pegasus also takes advantage of system privilege escalation to be able to carry out the spy action, get admin permissions completely silent. Even sending our data will not be visible and of course you will not be able to recognize it between system processes.
Its detection is an almost impossible task
There is a tool to detect Pegasus, but it’s for professionals
As mentioned in the previous paragraph, the fragmentation of Android versions considerably complicate the detection of Pegasus. And it is that not only would there not be a single file in the system, but it could be distributed throughout the system and be practically unrecognizable due to its excellent camouflage ability.
Amnesty International’s tool, called TVM, it can help find clues on Android and iOS. However, its use seems really complicated and even more so if you don’t have a high level of technical knowledge of the operating system.
MVT, which actually stands for Mobile Verification Toolkit, does not offer a detection system per se, but rather serves as a helper element to extract forensic evidence of the presence of Pegasus in the system. However, no easy detection method with which we simply press a button, a scan is performed and we get a response. At least today.
Practical tips to avoid this and other malware
With regard to avoiding being infected by Pegasus, we again emphasize the strong improbability that exists that ordinary people can be infected. In any case, as is always recommended above all, don’t trust text messages or emails with links which, although they seem normal, may be phishing. If in doubt, always inform the person or entity sending said links through a safe and well-known channel.
Likewise, always try to avoid download suspicious apps or files of any kind. And even more so if they come from places other than Google Play or an official site that has certified their safety.
Always beware of the links received, do not download untrustworthy applications and have the latest version of the system available are essential for prevention.
Another action always recommended and also applicable to other operating systems that are not Android is to always have the software up to date with the latest version. This way you can make sure that you have the latest security patches and your mobile will be less vulnerable. And we insist on the “minus” because (surprise) You will never have a 100% secure mobile.
As we mentioned recently about the use of Faraday shells or cases for mobile phones, the most effective method to avoid hacking is to always turn off the mobile and never turn it on. A solution that may seem paradoxical or even stupid, but which will always be the most effective. Obviously, this won’t be ideal for you, so using your mobile with common sense and following advice such as the ones above could be more than enough.
Table of Contents



