Citizen Lab Confirms Amnesty International's Pegasus Spyware Detection Methods
The Citizen Lab completes an independent peer review validating Amnesty International's forensic methodology for identifying NSO Group's Pegasus spyware. The analysis confirms that the detection techniques accurately identify infections across multiple examined devices.
The Citizen Lab completes an independent peer review of Amnesty International's forensic methodology following a major investigation into NSO Group's Pegasus spyware. After receiving iTunes backups and a methodology brief without any additional context, the research team independently validates that Amnesty International correctly identifies Pegasus infections within the provided device data.
The peer review determines that the overall forensic methodology is sound across several specific areas. The researchers confirm that the techniques for identifying Pegasus Process Names, establishing precise times of device compromise, and linking zero-click exploits on iOS 14.6 to NSO Group all rely on reliable temporal correlations and accurate log analysis.
Furthermore, the Citizen Lab verifies that Amnesty International successfully detects Version 4 Pegasus servers and accurately links malicious activity involving Amazon CloudFront servers to the NSO Pegasus killchain. The Citizen Lab notes that its own separate research independently arrives at the same key findings as Amnesty International's analysis, further strengthening the credibility of the forensic evidence.