Pegasus Detection and Analysis 26 Workshop

From HOPE Wiki
Revision as of 20:59, 2 August 2026 by Steveb (talk | contribs) (Links)

Pegasus Detection and Analysis Lab


Abstract

This lab will be using Amnesty International’s Mobile Verification Toolkit (MVT) to see if your Android or iOS has been compromised by Pegasus. The lab will open with a short overview on mobile spyware and general principles of communications security. Note: The presenters of this lab do not consent to mechanical recording of their presentation, but feel free to take notes.

Day / Time / Location

Day 3, Sunday, 16-August-2026, 12:30pm - 3:30pm
Workshop A (Sutton Place, third floor)

Registration -- NOT required

NOTE: You do NOT need to register to take this workshop
-- please show up early to ensure a seat at the WORKSHOP A room (in Sutton Place, on the third floor).

Expected Skill Level or Experience

Open to all skill levels, provided you are comfortable navigating your Linux or BSD laptop. There will be assistants present to provide help.

Required Software and Hardware / What to bring

  • A fully-charged laptop that uses an open source operating system (Linux or BSD...) that you have the root password for. The laptop's personal firewall (like "ufw") should be enabled.
  • Installation of python 3.X and pip 3 (or an equivalent python module installer that works for you...) on the laptop to be used.
  • A fully-charged Android or iOS phone that you want to diagnose and that you have the password for.
  • A USB DATA cable (not a charging one...) of KNOWN PROVENANCE! (a commercial brand you bought from microcenter, etc.) Check that the gender and USB types will be appropriate for connecting the laptop to the phone (e.g., male A to male C, male C to male C, etc.) It is recommended that you make sure you have a data cable by attempting a file transfer to/from your laptop to the phone before attending.

Note: Since pegasus is a "zero-click" attack vector, aluminum foil will be provided for the more paranoid attendees, allowing them to construct a makeshift Faraday cage for their phones. Of course if you are a pro and have a Faraday bag, you are welcome to bring that.

Presenter(s)

Steve B.: Steve is a software developer of over 30 years and has a fair amount of experience with Linux (including Linux firewalls...). A friend who is an activist came to him with their phone and asked if he could use Amnesty International's Mobile Verification Toolkit (MVT) to see if it was compromised -and it was! And that's why he is offering his services to conduct this lab.

Jonathan Stribling-Uss:

Matt H.: Matt is currently a comp sci major at CUNY Brooklyn, and has a fair amount of experience with python and django (the MVT is written in python...)

Gabe R.: Gabe spends much of his time exploring the latest distros. He also loves meshtastic, which offers superior privacy to android. He feels it is a promising alternative to traditional text messaging as it's a decentralized platform that can be used with no registration and has a strong potential to not have personal information tied to senders and recipients.

Links

Hope Pegasus Detection and Analysis Lab git

Android

Mobile Verification Toolkit

Android Quick Forensics

iOS

libimobiledevice

Guide to iOS quick Forensics

Recommended Videos