HARIS SHIELD
Back to blog

Threat Intelligence

Pegasus Spyware Check: How to Find Out If Your iPhone Is Infected

July 25, 202610 min read

Most articles about Pegasus tell you what it is. Very few tell you how to find out whether it is on your phone. This one is about the second question, including the parts that are inconvenient.

Start with the honest framing: Pegasus is not a mass-market threat. It is sold by NSO Group to government clients, each deployment is expensive, and it is aimed at specific people, usually journalists, human rights defenders, lawyers, opposition politicians and diplomats. If you are worried because your phone is slow, the overwhelmingly likely explanation is that your phone is slow.

But targeted people are not rare in absolute terms. Apple has sent threat notifications to users in more than 150 countries since 2021, and a single round of notifications in April 2024 reached people in 92 countries. If your work makes you a plausible target, the question deserves a real answer rather than reassurance.

Why you cannot detect Pegasus by looking at your phone

Pegasus is zero-click. There is no suspicious link you failed to avoid, no app icon to spot, no permission dialog you accepted. It has been delivered through iMessage and other messaging platforms without any interaction at all. Once resident it can reach messages, mail, calls, camera, microphone and location.

It is also deliberately quiet. Some variants live only in memory, which means a reboot removes them, and removes most of the evidence with them. Others have been observed cleaning up log files behind themselves.

This means the usual advice list, watch for battery drain, look for unknown apps, check for pop-ups, is close to useless here. Those symptoms describe consumer stalkerware, which is a different threat with a different budget. Against state-grade spyware, the absence of symptoms tells you nothing.

There is exactly one class of answer that works: forensic analysis of the phone's data from outside the phone.

The three checks worth doing, in order

1. Check whether Apple has already told you

Apple notifies people it believes have been individually targeted. This is the single highest-value check available, it takes two minutes, and it is free.

Sign in at account.apple.com and look for an alert at the top of the page. Apple additionally sends an email and an iMessage to the addresses associated with your Apple ID.

Two things to keep in mind. A notification is strong evidence that you were targeted, but its absence is not evidence that you were not, since Apple's detection cannot be complete. And because the notifications are alarming and widely reported, they are heavily impersonated: a real one never asks you to click a link, install software, open an attachment or supply a password.

2. Have the phone's own records examined

Traces do survive on the device, in places apps cannot reach:

  • Databases that record which processes used the network, and when
  • Crash logs from exploit attempts that failed
  • A system file recording shutdowns, which can retain anomalies around an infection
  • Message attachment metadata and cache artefacts

Amnesty International's Security Lab reconstructed the Pegasus infection chain from exactly this kind of material, and published both the methodology and the tooling in July 2021 as part of the Pegasus Project. Their open-source Mobile Verification Toolkit, usually called MVT, compares an iPhone backup against indicators of compromise: domains, process names and file artefacts associated with known campaigns.

If you are comfortable in a terminal, MVT is the reference implementation and it is free. You install it with Python, produce an encrypted backup of the iPhone, download an up-to-date indicator file, and run the analysis. The output is a set of JSON files that you then need to interpret.

If that sentence made your stomach drop, that is the real barrier. The method is public and sound; the practical distance between a worried journalist and a completed forensic analysis is what stops most people. Haris Shield exists to close that distance: the same external, backup-based analysis, presented as a report rather than as JSON. We are not claiming to see things Amnesty's methodology cannot. We are claiming you should not need a command line to use it.

3. Understand what a clean result means

A clean analysis means no known indicators were found in the data examined. It does not mean your phone has never been compromised. If a memory-only variant was present and the phone has since restarted, there may be nothing left to find. If the campaign against you used tooling that no researcher has published indicators for yet, there is nothing to match against.

Anyone who tells you they can certify an iPhone as clean is overselling. Forensics finds evidence; it does not prove absence.

What to do if something is found

Do not reboot or factory reset immediately. Your instinct will be to wipe the phone. If you may want the finding to be usable, by a lawyer, a newsroom, a court, or by researchers tracking the campaign, then the device and its data are evidence, and resetting destroys them.

Assume the account, not just the phone, is compromised. Change your Apple ID password and any critical passwords from a different device you trust. Review which devices are signed in to your Apple ID and remove ones you do not recognise.

Get expert help. Several organisations do this work for at-risk people, often at no cost. Access Now runs a Digital Security Helpline for civil society; Amnesty's Security Lab investigates cases involving human rights defenders. If your work put you in this position, you are their intended audience.

Think about the human side. If you are a journalist, sources who contacted you may also be exposed. That is frequently the actual objective.

Reducing the risk going forward

  • Lockdown Mode is the strongest single measure available on iOS. It disables most message attachment types, certain web technologies and some connection features. Apple has stated it is not aware of any successful mercenary spyware attack against a device with Lockdown Mode turned on. It is in Settings, Privacy and Security. It does make the phone less convenient, which is the trade.
  • Update immediately. These chains depend on unpatched flaws; delay is the vulnerability.
  • Reboot regularly. Against memory-resident variants a reboot removes the infection. It also removes the evidence, so if you suspect an active compromise, seek advice before restarting.
  • Reduce your attack surface. Fewer messaging apps, fewer accounts reachable by strangers.
  • Compartmentalise. For genuinely high-risk work, a separate device for sensitive contacts limits how much a single compromise costs you.

Frequently asked, briefly

Is there an app that detects Pegasus? Not on iOS. Apps run in a sandbox and cannot inspect the system, which is why every credible detection method works from a computer against a backup.

Would a factory reset remove it? Probably, and it also removes the evidence, and it does not fix whatever exposure got you targeted. It is a step, not a solution.

Can I be infected without clicking anything? Yes. That is the defining property of these campaigns.

Should I be worried? If you are a journalist, activist, lawyer or political figure, particularly one working on subjects a government dislikes, the question is reasonable and worth resolving properly. If you are not, and nothing specific prompted this search, the answer is almost certainly no, and ordinary stalkerware is the far more likely concern. Our guide to detecting spyware on iPhone covers that case.

Sources

Worried your phone is being watched?

Scan your phone for spyware, stalkerware, and Pegasus — free. No app installation needed.

Scan your phone free