You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Do I have Pegasus on my mac?

Hi, can anyone tell if my mac has the Pegasus spyware? I'm on Ventura 13.3.1. Found these pretty much right after I bought it at my local Best Buy.


MacBook Pro 14″, macOS 13.3

Posted on May 2, 2023 4:06 AM

Reply
Question marked as Top-ranking reply

Posted on Jan 29, 2024 5:22 AM

ErikDPhillips wrote:

What? How is it “normal to have some Pegasus files” on your computer or phone?
Do you mind explaining what you mean there?

Those are files made by Apple. They pre-date the malware. It is no coincidence that the name "Pegasus" was then chosen by Israeli cyber-warfare company as a way to hide, confuse, and cause chaos.

11 replies
Question marked as Top-ranking reply

Jan 29, 2024 5:22 AM in response to ErikDPhillips

ErikDPhillips wrote:

What? How is it “normal to have some Pegasus files” on your computer or phone?
Do you mind explaining what you mean there?

Those are files made by Apple. They pre-date the malware. It is no coincidence that the name "Pegasus" was then chosen by Israeli cyber-warfare company as a way to hide, confuse, and cause chaos.

Jan 29, 2024 5:24 AM in response to Joe Gramm

Joe Gramm wrote:

I know this is an old thread, but I was curious about something. If spyware is installed, is it installed on the System or User Folder.

Most malware is installed in user folders, unless the user has granted the spyware enhanced permissions, as they often do.

For an existing Mac, not a new Mac, would restoring the Mac by doing a clean install, then importing the Home Folder back via Time Machine work.

Yes. That would work to reinstall the malware.


But to be clear, neither you nor anyone in this thread has the malware installed.

May 2, 2023 11:58 AM in response to ui295

It is usually best to perform a clean install of any computers from Best Buy since Best Buy is known for installing addition crapware on systems they sell. I don't know if this happens with Macs, but I know this occurs with the Windows PCs they sell.


Most of those entries look like they are associated with the Command Line tools which people using the command line will usually need to have installed. If you have not elected to install the Command Line tools (or allowed any apps to do so), then perhaps this is a pre-owned computer or Best Buy customized the computer by installing extra software.


May 2, 2023 12:19 PM in response to ui295

It is HIGHLY unlikely you have the Pegasus spyware. Pegasus is used by nation states to spy on journalists, dissidents, political activists. So unless you consider yourself a prime target for government surveillance you shouldn’t be worried. Pegasus is not in the arsenal of the everyday hacker looking to steal your bank account. Pegasus costs $500,000.00 from the developer NSO, an Israeli company. So there’s that.


Add to that Pegasus is primarily an iPhone thing, not Mac. So what you are seeing is something not related to the spyware. Lots of legitimate software could be named Pegasus.

May 2, 2023 12:40 PM in response to lkrupp

And on top of that, there are a fair number of items with Pegasus in the name installed by the OS itself. Those in the System folder of course, since only Apple can touch that folder, and associated items in the user folder (I have the same ones listed in the image above).


From what I can tell, these have all been placed there by Apple to protect against any possible use of Pegasus in macOS.


Still, as HWTech noted, the very first thing you should do with any computer purchased from Best Buy is to wipe the drive and install the OS from scratch. Such as, all of those SDK entries are not part of a normal install. Either someone was using this Mac before ui295 for software development, or Best Buy put them there (though it makes no sense why they would).

Do I have Pegasus on my mac?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.