GithubHelp home page GithubHelp logo

pegasus_spyware's Introduction

Pegasus Spyware Samples Decompiled & Recompiled

Pegasus Spyware Product Manual 2013

Author: Jonathan Scott @jonathandata1

CURRENT VERSION 4.0

About Jonathan Scott

My name is Jonathan Scott, and I'm an American Security Researcher. I am currently a computer science PhD student at North Central University. My research focus is mobile spyware. I have been a mobile security engineer for ~13 years.

I was recently assigned an LVE from LG that affects all LG mobile devices in the world. I discovered a backdoor in all LG Mobile Devices that allows the attacker to live inside your device undetected. This has been built into the MTK chipsets since the 1st LG Smart Mobile Device (Cellphones and Tablets).

LVE-SMP-210010 source: https://lgsecurity.lge.com/bulletins/mobile#updateDetails PEGASUS SPYWARE 5.1

Description:

Operating System: AndroidOS

Samples 1-5.1 are executable and functional. I am still working on cleaning up Sample #6, but most the XML data can be read.

Steps To Install & Research The Spyware Samples

  1. Enable ADB on your android
  2. Disable Android Protect
  3. adb install sample#.apk
  4. launch the apk, example adb shell am start com.xxGameAssistant.pao/.SplashActivity

Update: Sample 5.1

This sample can be installed as a standalone apk, but you will need to uninstall sample 5.

adb uninstall com.network.android

Sample 5.1 is also called com.network.android

Samples Included

Sample # Hash
Sample 1 d257cfde7599f4e20ee08a62053e6b3b936c87d373e6805f0e0c65f1d39ec320
Sample 2 cc9517aafb58279091ac17533293edc1
Sample 3 bd8cda80aaee3e4a17e9967a1c062ac5c8e4aefd7eaa3362f54044c2c94db52a
Sample 4 144778790d4a43a1d93dff6b660a6acb3a6d37a19e6a6f0a6bf1ef47e919648e
Sample 5 7c3ad8fec33465fed6563bbfabb5b13d
Sample 5.1 3474625e63d0893fc8f83034e835472d95195254e1e4bdf99153b7c74eb44d86
Sample 6 530b4f4d139f3ef987d661b2a9f74f5f
Product Manual 2013 f6f0170d41075766b5ea18508453fa68dc946b8c58eaea4281b36207a32c7ade

Acknowledgements

@vxunderground for providing the samples

@recordedfuture for sample validation

@botherder Claudio Guarnieri - (Head of Security Lab at Amnesty International) - 2013 Product Manual

PEGASUS SPYWARE 5.1

Product Manual: 2013 Edition

Author: Guy Molho - Former NSO Director, Product Management

Document Hash: f6f0170d41075766b5ea18508453fa68dc946b8c58eaea4281b36207a32c7ade https://www.virustotal.com/gui/file/f6f0170d41075766b5ea18508453fa68dc946b8c58eaea4281b36207a32c7ade

Author Validation:

exiftool 2013-NSO-Pegasus.pdf Creator Tool : Adobe Acrobat 8.0 Combine Files Create Date : 2013:12:23 14:53:39-06:00 Metadata Date : 2013:12:23 14:53:39-06:00 Producer : Adobe Acrobat 8.0 Creator : Guy Molho Format : application/pdf

PEGASUS SPYWARE User Manual

PEGASUS SPYWARE RAW DECOMPILED

pegasus_spyware's People

Contributors

jonathandata1 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

pegasus_spyware's Issues

Offer

I need someone who thinks big and actually owns the software. If anyone is interested and has what I need send a message for negotiation.

Only for those who actually have the software, it's no use trying to deceive because the level of knowledge is high.

I could really use your genius right now

Hi Jonathan. :)
My name is Amanda, and I’ll be straight with you - I really don’t understand any of this, but 1 hacked Apple device led to another, and another, and another, and another finally led me to you. 6 police reports, 3 fbi reports, on the brink of losing my family because everyone thinks I’m crazy (or on drugs). All of my devices have been compromised. This has been going on since June 2021, when I first started my job as executive assistant to the CEO of Ampac USA, Inc, which manufactures & distributes OrangeDaily skincare products, globally. It followed me home, and I have not been able to get rid of it or convince anyone it’s happening. 1. I’m not in any form or fashion IT. 2. I’ve had to resign to keep the company safe. 3. Everything I do, on every device I have had (since October 2021 that I know of), is being monitored. Obscure permissions on every phone, if not, some form of parental software. I need your help. Please let me know if you’re willing to let me buy you a coffee and take 10min of your time. I live in Plano. Starbucks on me? I’d love to pick your brain. :)

Hope to hear from you soon,
Amanda
[email protected]

SIMJACKER

I understand that pegasus is more like a SIMJACKER, only with an SMS or push notification the device can be intervened and this is more like a RAT and it is necessary to install an APPLICATION That normally the operating system blocks it or puts a warning and needs human intervention from the attacker to force the installation and permissions.

Only if you are up to date with the vulnerabilities of each operating system is it possible to cleanly attack with a RAT without being detected, which I think is very sick to be spending all your time looking at every vulnerability without real monetary benefit.

Removal from acknowledgements

Please remove my name from the acknowledgements list. I was not asked, nor do I wish to be associated with this project.

How can we made this work ?

Hello bro, hope you are well,.

This is really nice, but could you please tell me how can I test it ? I know that I need to infect some test device but is not clear how to control it.

Thanks in advance.
Regads.

How to detect spyware in android

Hi,
I would like to know if it is possible to detect these spywares in android phone.
Whatever it is, the data finally has to go through network adapters for communication.
Although monitoring the network in idle state, gives the DNS and IP address, I would like to know the possibility of detecting this internally.
Are there any software which can detect these in android. This is a serious privacy issue if someone is doing without consent.

Thank you

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.