Pegasus Spyware: so dangerous that it should be banned? OTW explains...
ฝัง
- เผยแพร่เมื่อ 9 มิ.ย. 2024
- Pegasus is used around the world to hack people's phones. It's extremely dangerous and can be used to control a phone remotely without the user knowing that is running.
Big thanks to Brilliant for sponsoring this video! Get started with a free 30 day trial and 20% discount: brilliant.org/DavidBombal
// Mr Robot Playlist //
• Mr Robot
// David's SOCIAL //
Discord: / discord
Twitter: / davidbombal
Instagram: / davidbombal
LinkedIn: / davidbombal
Facebook: / davidbombal.co
TikTok: / davidbombal
TH-cam: / davidbombal
// Occupy The Web social //
Twitter: / three_cube
// OTW Discount //
Use the code BOMBAL to get a 20% discount off anything from OTW's website: davidbombal.wiki/otw
// Occupy The Web books //
Linux Basics for Hackers: amzn.to/3JlAQXe
Getting Started Becoming a Master Hacker: amzn.to/3qCQbvh
Top Hacking Books you need to read: • Top Hacking Books for ...
// Other books //
The Linux Command Line: amzn.to/3ihGP3j
How Linux Works: amzn.to/3qeCHoY
The Car Hacker’s Handbook by Craig Smith: amzn.to/3pBESSM
Hacking Connected Cars by Alissa Knight: amzn.to/3dDUZN8
// MY STUFF //
www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
00:00 - Intro
00:22 - Brilliant Ad
01:59 - OTW Books
03:54 - Pegasus overview
06:54 - Pegasus info
07:40 - Pegasus in use
08:56 - Human rights
09:25 - 0 Day malware
13:33 - Original Pegasus 1 click exploit
14:30 - How it works
16:52 - Remote access
17:48 - Malware links
19:30 - Femtocell
21:01 - Stingray
22:10 - How they work
23:50 - Pegasus 0 click exploit
24:55 - Pegasus malware
25:29 - Human rights
26:51 - ISO/Android vs malware
27:40 - Governments
29:19 - What can we do?
30:35 - Be responsible
32:01 - Governments and malware
32:51 - NSO
35:14 - Privacy
36:03 - Command and control
37:36 - Processes
38:38 - NSO developers
38:53 - Expectations
40:30 - Social engineering
43:04 Eternal blue
44:25 Chrysaor
45:23 Outro thoughts
pegasus
spyware
hacking
hacker
malware
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#pegasus #iphone #andorid
Pegasus is used around the world to hack people's phones. It's extremely dangerous and can be used to control a phone remotely without the user knowing that is running.
Big thanks to Brilliant for sponsoring this video! Get started with a free 30 day trial and 20% discount: brilliant.org/DavidBombal
// Mr Robot Playlist //
th-cam.com/play/PLhfrWIlLOoKNYR8uvEXSAzDfKGAPIDB8q.html
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: twitter.com/davidbombal
Instagram: instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
TH-cam: th-cam.com/users/davidbombal
// Occupy The Web social //
Twitter: twitter.com/three_cube
// OTW Discount //
Use the code BOMBAL to get a 20% discount off anything from OTW's website: davidbombal.wiki/otw
// Occupy The Web books //
Linux Basics for Hackers: amzn.to/3JlAQXe
Getting Started Becoming a Master Hacker: amzn.to/3qCQbvh
Top Hacking Books you need to read: th-cam.com/video/trPJaCGBbKU/w-d-xo.html
// Other books //
The Linux Command Line: amzn.to/3ihGP3j
How Linux Works: amzn.to/3qeCHoY
The Car Hacker’s Handbook by Craig Smith: amzn.to/3pBESSM
Hacking Connected Cars by Alissa Knight: amzn.to/3dDUZN8
// MY STUFF //
www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
00:00 - Intro
00:22 - Brilliant Add
01:59 - OTW Books
03:54 - Pegasus overview
06:54 - Pegasus info
07:40 - Pegasus in use
08:56 - Human rights
09:25 - 0 Day malware
13:33 - Original Pegasus 1 click exploit
14:30 - How it works
16:52 - Remote access
17:48 - Malware links
19:30 - Femtocell
21:01 - Stingray
22:10 - How they work
23:50 - Pegasus 0 click exploit
24:55 - Pegasus malware
25:29 - Human rights
26:51 - ISO/Android vs malware
27:40 - Governments
29:19 - What can we do?
30:35 - Be responsible
32:01 - Governments and malware
32:51 - NSO
35:14 - Privacy
36:03 - Command and control
37:36 - Processes
38:38 - NSO developers
38:53 - Expectations
40:30 - Social engineering
43:04 Eternal blue
44:25 Chrysaor
45:23 Outro thoughts
pegasus
spyware
hacking
hacker
malware
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
It's extremely dangerous but the pegasus issue is largely a media red herring to avoid discussion of 5 eyes (14 eyes) epic global spying. Why western media don't like Pegasus is someone is cutting into their spying grass. Either end spying globally, including downscaling organizations like NSA, GHCQ, and Chinese, Russian and other large counterparts or a natural consequence is other countries will spy on the countries that lament about spying then hypocritically spy.
Perhaps Pegasus democratization of spying will be a wake up call for the governments of 14 eyes nations. If foreign governments are tapping their own phones, like they have been doing ot others for decades, then maybe they will see why mass computer surveillance they'be been doing of foreign states is morally wrong. Mind you that's wishful thinking. What's more likely to happen is virtue signalling hypocrisy.
How do you even find out if your phone is infected by pegasus?
yep good old pegasus among I think there was one other big one. good ol' Mossad :)
Funny.. see how easy it is to deactivate all google apps and try to go deep in your android with developer settings enabled.
Try to disable google.android.gms.persistence
So who is spying on you?
Who does most governments work closely with?...
But why be scared about someone spying on you if you not harming anyone?
What about Palantir? The number one spy tool that the Government's are using today.
This feels like a honeypot 😂
When a government commissions anything for use, their justification is always "it will be used against our enemies" but invariably it will always be turned inwards against it's own people.
It's not used against its people it's used for ahhh damn I jus drew a blank .
Privacy is one of the most fundamental human rights
❤Yes!
(US "Patriot Act" rolling on it like a tank)
privacy is a facade
And yet blanket geo location warrents are done almost every day with out legal ramifications, from the gov.... its by the gov....on the USA...by the USA orders..... 🍿🍿🍿🍿🍿🍿🍿🍿
@@sefzxm6486definitely seems that way
When these two get together, it ALWAYS seems to end too soon....just can't get enough. Thanks guys!
As a Retired combat Marine I want to tell you that as what you are doing is just as important as any warrior on the battlefield. You are waging warfare against cheater on the digital battlefield. You are defending and protecting the most vulnerable of our society against these predators and cheaters. Keep up the good work Team *Topphase Resolution* ..
The problem is not Pegasus, it is phone makers that don’t let you install a proper firewall and a proper app locker.
it can also be a problem with pegasus. Anyone can use it if you have the money (a lot of money as its license is around 600k for the base version).
Yes
But you can control your phone with a rooted device and learn about android system
Pegasus attacks the hardware
I believe someone once said "you control the endpoint, you control the network?"
@@IfindPortchPirates yeah like elliot from mr robot or something, maybe Otw
Thinking that the government or corporations care, and are not one and the same, is foolish. There is no privacy period. Thanks for both of your work.
Thank you, both of you for addressing this issue and educating us
You're welcome! OTW has an amazing wealth of knowledge and it's great to have him share it with all of us! 😀
@@davidbombalalways looking forward for your videos 🙏🏻
We need to stop treating phones as secure devices. The mindset has to change. I don't keep any sensitive data on my phone, my cameras have tapes on them etc.
What is a "secure device"? I was taught security is merely a state of mind.
John McAfee once said, "Computer Security is an Oxymoron."
Many thanks to you two David & OTW, your collaboration is always top-notch.👌 Keep up the good work. 🙏🙏
Dear David and OTW, you guys together are amazing! Hope this collaboration will continue for a long time, because I’m looking forward to any new video you guys work on! Great job!
It’s always a good time with David and OccupyTheWeb!
Thanks for the upload! I know most of the stuff discussed, but it was interesting to be able to confirm my understanding was correct. I hope such videos get more attention and people stop clicking on links outside a sandbox, at the very least!
You and Occupy the web are a great combo for sure. Well done
Getting a search warrant to surveil a subject should not include the use of a Stingray! All the phones in the area will connect to it. LEOs don't have a search warrant for everyone in the transceiver area!
@@Andrew-zy7jz Local LEOs can’t get one.
They have stuff way better than stingrays now. They also have CelleBrite. If they get your phone for even a second, they plug it in, and that’s all she wrote.
I think bringing awareness to things like this is the first step to implementing policies to help protect privacy rights for people
Dear Mr. Bomball and Mr. OccupyTheWeb,
Thank you for educating us on these issues. I would like to kindly please you to teach us how we can technically detect such spywares on our phones? What lessons or tutorials should we learn in order to find out whether our phones are being spied? Please help us learning that great area of cyber security.
thats a great question i would also like the answer to
Yes!!!
Both your content and OTW content are addictive-especially helpful to gain value when you’re hooked, though 🙌🏽
Top content David....Love the videos you collaborate with OTW.
That was an awesome interview Dave.
My best wishes to Neal, stay positive, fast 2 days at least a week exercise a lot , green diet , less sugar and red meat, a lot of water .
Win your life back don’t give up and you will a champion in Golf as you are In Cybersecurity.
All the best.
I am so happy to have found your channel. #1 favorite content! Thanks so much!
Thank you so much! 😀
Thanks a lot David, awesome content as usual. I would love to see you interviewing Ryan Montgomery!
Hopefully soon 😀
The Term (ZERODAY) hence the name (ODAY) meaning that you have "ZERO TIME" to respond to the attack.
Thank you, David, for another brilliant video! I always feel just a little bit smarter, much more hungry and inspired to learn more. OTW's classes are top notch! You are the best! Cheers!!
thank you for bringing back OTW
It's alarming to think about the misuse of tools like Pegasus spyware, especially when it comes to infringing on individual privacy and human rights. I'd say "unbelievable", but sadly... Its not.
It was created for misuse
Misuse?
Thank you !!😊 It helped me learn about the danger lurking around me.
Hey David
first im learning from you and your videos for years and I'm fascinating by social engineer
you have any recommendation on specific place that i can learn more about this skill and upgrade my self bit more?
That would be great a technical demostration of Eternal blue ! we will wait for the session David,
Always love to listen to otw and David!!
Mann your community, the majority of IT community, David B, OTW, and etc all dropping diamond and gems!! Letting us know how to win!! We need more people like y’all mann!! God bless y’all!! We appreciate you David and OTW!!!
Hi.Thanks for very in-depth video. If I have installed a distro such as arch linux on your phone, then access still be gained to your phone?
This is real content!!! Thanks David and OTW sharing all your knowledge.
Welcome back Master OTW
Thnkz both of u ...
Another great video David. OTW is correct you do have the best YT channel for cyber
Fantastically informative, thank you for the awesome content.
How effective is Pegasus malware on linux phones,I know they are not many linux phones but will have the same effect like on apple and android phones?
there should be a rule that all email client applications are required to run in a sandbox regardless of how thoroughly annoying this is.
What an enthralling captivating discussion! Thank you David! I look forward to hearing more! 👍👏
Back in the DOS days, PC Tools, did a program byte count of the code in a software product. If the scanner found a different number of code bytes, say less or more, than the original known ( size ) of the code including key, count, it would send up the red flag. Think about thar for a second. One way to detect key loggers is get your hard drive used information motion, type 100 words on notepad, the delete it, re read hard drive bytes used,if it's the same count after you erased it, that's good, but if now you drive says it's more than the count you first logged, say about the amount you typed in, I would suspect a keylogger installed. Keep a watchful eye on disk storage usage. It's a pain, but.
As always thank you both so much for the content!! Amazing as always! Happy Father's day yall and all other fathers out there!
Same to you! Thank you!
we all love our great teacher, doing a great job and educating about digital era and talking about privacy that is core thing for human society .
Legendary thanks David. From south Australia at work chatting about u Chanel interesting hey many people watching u Chanel
Always assume your devices are already compromised.
thx David for such a good material and thank for the OccupyTheWeb sharing such a good info
What's crazy is there are probably 10 or more that we don't know about. Great video David.
That is a worry 😢
@@davidbombal Agreed, one of the reasons I don't use anything made by Apple. Their code is dog s**t. 100% believe it's harder to pwn an android these days.
@@camelotenglishtuition6394 OTW disagrees with you. And I think many other people do too and say that Android is more vulnerable.
@David Bombal I understand, but I disagree with OTW over several things. I would ask specifically what you think makes ios stronger when it has so many issues. Specifically with webkit, unused features in code, poor code review, and also very slow patch times.
Technical details aside, it's easier to make mistakes on an android because your phone allows you to. A lot of iOS security is designed around blocking you from compromising your device. Android doesn't tend to care beyond asking "Are you sure?"
Thank you for the guest. Amazing video.
Thanks for the video. I have known about this technology for a while and even had a tech demonstrate it on one of our instructors phone.
Question...if you ditch that smartphone and get a different handset is Pegasus transfered to the new one. Or would that agency have to target the new handset and infect it?
Thankyou!!
Looking forward to Occupy the web talking On the AIGC era we are living in & how it impacts different Cybersecurity Fields
Regards Pegasus if its sending messages back to servers would this traffic not end up detected by BOT activity security? I wounder if Zscaler et al could detect this malicious communication from the device to identify it as compromised?
Thank you so much for the great content and this was one of the best
Thank you! Glad you enjoyed it!
would it be possible to investigate malware and resend it to the originator by working on the device in a faraday cage and send it when you remove the device from the cage?
Great video many many thanks @David
You're very welcome!
Wow , really interesting topic!!! Thank you
And malware too😂😂😂
Guys great show, more info then I can wrap my head around. Will be listening more.
What we need are some huge Class-Action lawsuits against Apple and Google to give them an incentive to make more secure phones.... They will not respond to public pressure, they will only respond to financial pressure.
Google makes some of the most secure phones available given the right care. Its all about hardware.
so what you want them to do? they patch as soon as it is found. They can't test every vulnerability in house.
And Samsung
Thanks David Bombal, just one quick request. Next time you interview OTW, can you ask about the release date of 'cyberwarrior handbook'?, because I already have read all his other books.
Thanks for the info
Always a treat. Thank you so much
Thank you Derrick!
One of the best OTW videos. Thanks.
Great episode!
Thx
Why isn't it stopped by firewalls or detected by router software?
You guys together are best ❤❤❤, amazing video ❤❤❤
my mind is never invurniable to the knowledge you guys have...
Loving these occupy the web videos David!!!!!
Another great episode by OTW 🎉
Thanks David your teach us new things for everytime
My iphone has been having these issues. I deleted the email associated with that account and it locked my iphone. This should completely disable messaging but it turns on by itself when I turn I off. Also my voicemail box was set up Andi purposely didn't activate it. I need help but I don't know what to do as the police want proof... But proof they understand apparently.
Any advice would be so grateful
Eye opener content .keep rocking ....
This couldnt have been timed before! Pegasus was my blindspot.
Everytime you release one of these videos w/ OTW, I get the urge to change my career into cyber security. Thank you for continuing these conversations.
Same lol😂😂😂
Lol,Love how he's right,He said there's really no way to scan for any of these because when hackers catch wind that you're on to them they jump ship.
I agree with OTW, David Bombal is probably the best TH-cam channel I have come across when it comes to updated information about security, when it comes to other stuff, in my opinion, I prefer John Hammond as my 2nd source for education, and Null Byte as my 3rd
Great segment! Just curious, is there a tool/app that I can install on either my laptop (connected to my mobile device via USB) or on my mobile that will reveal spyware that has been installed on my mobile device? I take it that something like Pegasus isn't detectable through consumer based anti-virus software. Thank you to you both.
Just interested in reply😊
Same
hay could you do a practical example of how to set up a subnet. I looked up a few tutorials but they all only explain the theory and how tlit works with IP but no practical examples of how to set it up on routers
Cant get enough of your content gents. More please! You're the perfect combination... IMHO
Keep it going David !👍
Thank you for the video. I am new in hacking and interested in learning. How can i become a student of the facilitator/join his class?? Thanks
This is more exciting and interesting than Netflix! ,
For those not familiar with EquationGroup, that is (in large) the NSA.
So if they are using a stingray and someone is outside using their mobile, does that mean they can fake their location/falsify their location to make it look like you are somewhere else, like if someone mysteriously vanishes?
That's an interesting question
How do I join the classes or become his student? The link in the desc doesn't work
Fascinating! Can't wait for y'all to cover eternalblue
Thanks David.
Could we make a software that scans the number of code running in the phone and then if any other code wants to run on the device the software would stop it. like a gate keeper. for pegasus.
These types of laundry rooms are standard if you rent your flat. If you own your flat you usually have the washy things inside your flat.
When I got a device that monitors my data usage (up and down) in the upper right hand corner, bc it is integrated in my custom Rom and I'm not doing anything, then "sb listening to my mic or taking pictures/a video of me" (I got stickers), will result in data usage, which I will notice eventually.
How do i enroll in your courses remotelly or purchase these books as a beginner
I'd love to see a video on hacking and AI and how crazy things might or could get in the future while we still have the training wheels on for AI? The last part of the video really made me think hmmmm AI hacking big problem?!
In passing I'd really like you to touch up on LOIC(Low Orbit Iron Cannon) and the evolution of DOS/DDOSes.
Thanks David, love this content
Thank you Charles. Very happy to hear that.
I like that guy just waiting that class in October by what channel
22:07 or you turn off mobile data while at home to prevent your device from connecting to the strongest signal.
I am educated every time I open your channel. Thank you, David and OTW. Excellent presentation as always when you and OTW are grouping up fantastic knowledge.
Great to hear that Leroy! OTW is amazing 😀
הפרשן שכח להזכיר שבגרסה האחרונה של פגסוס..היה פשוט ניתן להשתלט על הסמרטפון ללא לחיצה על כלום!
Said this on Twitter it needs a repeat,Thank you for the birthday courses.
Does doing factory reset on the phone able to delete the malware?
I had a iphone 12 around the time this video came out and i got on my phone and it was in the files and the only file that was there was Pegasus, i tried to factory reset but my phones screen flashed and i was at the startup screen that said my phone was locked due to the passcode being changed...
I was staying at a hotel one time and overnight the first night, I got an alert that my phone had used 50GB of mobile data. If I recall correctly, I had tried to join a wireless network at the airport that was not successful. Always wondered what the heck it was that happened. I figure either my phone was hacked and they got all my pics including nudes lol. Or the only other possibility is that I fell asleep as I was browsing a web page that had some videos and things playing, and maybe that stupid website was downloading crap ads and videos all night.
I remember many many years ago, I had to learn how to hack/crack so that I could properly protect clients, I did PEN testing for companies often.
If these "zero day" developers were not criminals, they would immediately notify the owner of the site, to protect them. But nooooooo