logo

Clipping Wings: Our Analysis of a Pegasus Spyware Sample

ID: 766acb0e-d20d-58b4-9672-5aff6a22e514

STIX ID: report--766acb0e-d20d-58b4-9672-5aff6a22e514

Feed Name: iVerify Blog

Threat Score
80/100

Date Published: 2026-03-03

Date Updated: 2026-04-28

...
...

This post previews a Black Hat Asia 2024 briefing on an analysis of an iOS spyware exploit sample (linked to Pegasus/BLASTPASS) recovered from an iTunes backup; it highlights repeated homed and MessagesBlastDoorService crashes, IMTransferAgent activity delivering files named sample.pkpass, and a pkpass archive containing a large WebP image and a binary plist (NSKeyedArchiver) consistent with known BLASTPASS exploitation techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.