To be, or not to be: legitimate targets for NSO Pegasus and other legal surveillance malware?
One of the long-running claims by NSO Group is that its Pegasus surveillance tool is only used to target criminals and terrorists. How come…
To be, or not to be: legitimate targets for NSO Pegasus and other legal surveillance malware?
One of the long-running claims by NSO Group is that its Pegasus surveillance tool is only used to target criminals and terrorists. How come we see it in other places?
Pegasus is an expensive suite; in the range of millions if not tens of millions USD. Law enforcement rarely affords such budgets. A friend of mine who worked for Law Enforcement said a few years ago their cyber budget to catch criminals was a hefty $3000.
Now, imagine you have purchased an expensive spyware suite worth several millions USD which effectively gives you the option to hack any smartphone with a click of a button. How would you use it? Given the amount of “bullets” is limited, one must choose their targets very carefully. Let’s look closely at the categories that you might want to target with, say, iOS 0-click spyware:
Criminals — these are legit targets and constantly highlighted as the reason why governments purchase software such as Pegasus. We should however keep in mind they must be really big criminals to justify the millions USD investment. Then, however, really big criminals don’t use iPhones. As we see from other stories, such as the fake secure phone network that the FBI ran, major criminals stay away from regular devices and instead use various “Secure” phones. So, it’s not very well justified for this purpose.
Terrorists — basically, on the most entry level jihadists forums, in the tech section, “opsec for dummies”, the recommendations are to stay away from iPhones. These fellas often use dumb phones, as opposed to smart phones. They use old devices without GPS or capability to run user apps. So, again, 0-click iOS exploits + malware — it’s not very well justified for this category. Also, while at it, how many terrorists were caught lately, say in Europe or US?
Drug dealers — here, the budget may very well be justified. Actually, there are stories where drug dealers were successfully targeted and caught by such technologies. However, again, top criminals will likely use custom devices or dumb phones.
Cybersecurity personnel/researchers — these are top threats for governments engaging in shady operations, so it is a perfect targeting case! The budget is not an issue, because it is usually black budget, with no auditing. We are actually aware of security researchers who have been targeted by Pegasus.
Extremists — this can be a very good justification and budget surely fits the purpose. The only issue is that extremism can be relative to the government or governing processes in a certain country. In oppressive regimes, activists can be extremists. These are easy to justify and easy to target because they rarely care about opsec.
Journalists, media, reporters — does not fit the initial goal, but again, plenty of evidence this is happening. Reason is simple — governments are worried about the stories they can write, their sources, and potentially bad PR. Budget can be justified quite easily by designating these extremists, foreign agents, enemies of the state.
To summarize — the categories for which the usage of highly expensive cyber warfare products is justified with a ROI are drug dealers (sometimes), security people, extremist activists, journalists, mass media and reporters.
Is this worrying? Probably. So, what would an ideal, corruption free, legitimate cyber offensive business look like? I say, unprofitable, independent and externally audited. When you see that an offensive cybersecurity company is owned by an investment fund, venture capital — this means their top goal is to make as much money as possible. Profit, sell to anyone then try to find arguments or loopholes to justify the sales.
So Costin, I hear you asking, is this a threat to democracy or our civilization as a whole? Democracy — yes, civilization probably not. One thing, though — are these mercenary tools solving the problem (be it criminals, terrorism or extremism)?
Definitively no.
메타데이터
- post_id
- c2fb25eeeaeb
- slug
- to-be-or-not-to-be-legitimate-targets-for-nso-pegasus-and-other-legal-surveillance-malware-c2fb25eeeaeb
- url
- https://medium.com/@costin.raiu/to-be-or-not-to-be-legitimate-targets-for-nso-pegasus-and-other-legal-surveillance-malware-c2fb25eeeaeb
- canonical_url
- https://medium.com/@costin.raiu/to-be-or-not-to-be-legitimate-targets-for-nso-pegasus-and-other-legal-surveillance-malware-c2fb25eeeaeb
- author_url
- https://medium.com/@costin.raiu
- status
- ok
- fetched_at
- 2026-08-15 20:49:55