How to install and use MVT to check for Pegasus infestation

I tried to install MVT per the instructions here. https://docs.mvt.re/en/latest/ios/backup/check.html Unfortunately, there are lots of installation errors, and it isn't clear where the executables will reside. Has anyone succeeded in doing it on MacOS Big Sur? What I'm looking for are detailed instructions to install and also to run the check on my iPhone, iPad Pro, and on my MacBook Pro.


I'm also wondering whether the new release of MacOS 11.6 will remove any Pegasus infestation or whether it merely prevents it from being installed. If it's the latter, then I'm looking for detailed instructions to remove Pegasus.

MacBook Pro 16″, macOS 11.6

Posted on Sep 15, 2021 7:38 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 15, 2021 1:06 PM

This tool is not intended for end-user self-assessment and it is designed for IT Security / IT Forensics professionals. It is not like MalwareBytes, etc.


Did you follow the instructions?

https://docs.mvt.re/en/latest/install.html


Dependencies required on macOS:

  1. You need to install Xcode (Mac App Store)
  2. You need to install Xcode Command Line Utilities via Terminal (sudo xcode-select --install)
  3. You need to install Homebrew (https://brew.sh)
  4. You need to install the Homebrew packages via Terminal (brew install python3 libusb sqlite3) [libusb only for Android]
  5. You need to add "export PATH=$PATH:~/.local/bin" to your .bashrc or .zshrc file
  6. You need to install mvt via Terminal (pip3 install mvt)


That's just to get the tooling installed. Now you have to jump through hoops to actually create iTunes backups and scan them with the mvt-ios tool.


Download the STIX2 Pegasus file (https://raw.githubusercontent.com/AmnestyTech/investigations/master/2021-07-18_nso/pegasus.stix2) and put in ~/iOS/malware.stix2 then run the command below:


mvt-ios check-backup --iocs ~/ios/malware.stix2 --output /path/to/iphone/output /path/to/backup


MVT is a forensic research tool intended for technologists and investigators. Using it requires understanding the basics of forensic analysis and using command-line tools. MVT is not intended for end-user self-assessment. If you are concerned with the security of your device please seek expert assistance.


Note: MVT does not scan Mac's only mobile devices.





Similar questions

7 replies
Question marked as Top-ranking reply

Sep 15, 2021 1:06 PM in response to stevegoldfield

This tool is not intended for end-user self-assessment and it is designed for IT Security / IT Forensics professionals. It is not like MalwareBytes, etc.


Did you follow the instructions?

https://docs.mvt.re/en/latest/install.html


Dependencies required on macOS:

  1. You need to install Xcode (Mac App Store)
  2. You need to install Xcode Command Line Utilities via Terminal (sudo xcode-select --install)
  3. You need to install Homebrew (https://brew.sh)
  4. You need to install the Homebrew packages via Terminal (brew install python3 libusb sqlite3) [libusb only for Android]
  5. You need to add "export PATH=$PATH:~/.local/bin" to your .bashrc or .zshrc file
  6. You need to install mvt via Terminal (pip3 install mvt)


That's just to get the tooling installed. Now you have to jump through hoops to actually create iTunes backups and scan them with the mvt-ios tool.


Download the STIX2 Pegasus file (https://raw.githubusercontent.com/AmnestyTech/investigations/master/2021-07-18_nso/pegasus.stix2) and put in ~/iOS/malware.stix2 then run the command below:


mvt-ios check-backup --iocs ~/ios/malware.stix2 --output /path/to/iphone/output /path/to/backup


MVT is a forensic research tool intended for technologists and investigators. Using it requires understanding the basics of forensic analysis and using command-line tools. MVT is not intended for end-user self-assessment. If you are concerned with the security of your device please seek expert assistance.


Note: MVT does not scan Mac's only mobile devices.





This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How to install and use MVT to check for Pegasus infestation

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.