ZARYA-PUB-2026 · Public Document · KB-001 — KB-007
ZARYA логотип
ZARYA
ZRY-PUB-2026-00003·The Archive of Strategic Risks·July 29, 2026·2 min read

What happens when the state buys the unknown?

Pegasus (NSO Group)

This material is an independent analytical review prepared by ZARYA based exclusively on publicly available sources (court rulings, official regulatory filings, reputable media). It is not a report commissioned by a client and does not indicate ZARYA involvement in any investigation of the case described.

ZRY-PUB-2026-00003

ZARYA
Public Document

AnalyticalBulletin

Issue No. 2

The reason for this newsletter was recent publications about the alleged mechanisms for the acquisition of the Pegasus complex by the Moroccan State through intermediaries. Regardless of the reliability of individual claims, the story itself raises a broader question: what does the state actually buy when it acquires such systems?

The Pegasus story is usually presented as a digital surveillance story. The legality of the application, the range of potential goals and the responsibility of specific participants are discussed around it.

But this approach misses the main point: for an analyst, not only the tool itself is important, but also the basis on which the decision to purchase it is made. This is especially important when it comes to technology that potentially affects national security, counterintelligence, and the stability of the government circuit.

In other words, it's not just a question of what the system does. The question is, what was known about the system at the time of purchase and what, in principle, could have been checked independently.

It is this zone that seems to be central. Not only in the case of Pegasus, but also in relation to any complex closed solution on which the management of sensitive data, operations or infrastructure depends.

Where does the analysis usually break down? The error often starts with task substitution. The discussion quickly turns to the question: are the statements of former employees, journalists, or company representatives true? In our opinion, this is important, but not primary.

If information appears that can change the risk profile of an object, the analyst should not immediately turn it into either truth or noise. His task is to determine which assumptions become invalid without verification, if this information can be at least partially correct.

This is how disparate evidence turns into a reason to review the entire risk model.

What should have been evaluated before the deal?

Regardless of the brand, country of origin, or field of application, such purchases require answers to questions that cannot be considered secondary.

Is it possible to independently confirm the stated capabilities of the system?

Which elements of the architecture are under the direct control of the customer, and which are beyond his field of vision?

What kind of supplier's statements does the customer have to rely on without the possibility of his own verification?

Does the customer have a technical mechanism for monitoring that service information, logs, telemetry or other data does not go beyond its contour?

Is it possible to check the composition of the transmitted data without the developer's participation?

What happens to the system if the interaction with the supplier stops?

Public data does not provide an opportunity to answer these questions with sufficient certainty in relation to Pegasus. But this is exactly the crux of the problem: in such projects, the lack of an answer is in itself a risk.

It's not just about information security anymore. We are talking about strategic dependence on an external supplier and the limits of control over a critical tool.

Analyst's question

What risks arise if a critically important technology is acquired by the state in an environment where some of the key assumptions about its operation cannot be independently verified?

What is publicly known

Open sources allow you to fix several basic positions. Closed architecture. Pegasus belongs to the class of commercial software systems with a closed architecture. This in itself is not a violation: many suppliers do not disclose the internal structure of their products by default. But for analytics, this means an obvious limitation — by default, an external observer does not see the entire system and cannot check it completely. A separate exception is the materials from Amnesty International (July 2026) based on leaked court documents, which described part of the architecture for the first time; this is the result of a leak, not the supplier's staff transparency. Limited independent verification. Research organizations are able to analyze artifacts on end devices, indirect traces of exploitation, and individual technical indicators. However, this is not enough for a full—fledged audit of the entire chain, from architecture to operating mode. Consequently, a significant part of the assessment in such cases is inevitably based not on direct verification, but on a combination of indirect data, assumptions and trust in sources. Mismatched versions in the public field. Publications by journalists, court materials, and statements by former employees contain different and sometimes mutually exclusive descriptions of the architecture and how the system is used. Some of these statements concern whether individual infrastructure elements could be outside the direct control of the end customer. We do not have sufficient grounds to independently confirm or deny these versions. But it is analytically important that they exist: they change the list of questions that should have been raised in advance.

Analytical assessment

The history of Pegasus shows a broader class of problems. The more complex the technology, the more important it becomes not only its functionality, but also the ability to independently verify exactly how it works and how it behaves in operation. If the purchase decision is made in an environment where some of the key assumptions cannot be confirmed by own means, then not only technology becomes the object of management. The uncertainty surrounding the technology becomes the object of management. That is why the statements of former employees, investigations and court materials are quite valuable, not as a sensation. Their value lies elsewhere: they point to questions that should have been asked before the deal, not after it.

Epistemic status

Established facts · expand

Pegasus is a commercial software package. The full architecture has not been publicly disclosed for a long time; in July 2026, Amnesty International for the first time described individual elements of the system based on trial documents, which is not equivalent to an independent technical audit. An independent audit on open data is limited by definition. In the public domain, there are various and sometimes contradictory descriptions of the architecture and operation of the system.

Open hypotheses · expand

That individual elements of the Pegasus infrastructure could be located outside the immediate technical contour of the end customer. That the level of actual understanding of the system by specific customers could be lower than the level of their stated assumptions. That part of the operational processes could be based not on full technical verification, but on trust in the supplier and his description of the product. That it was the limitations of the independent assessment, and not just the political or legal context, that could become one of the key sources of risk.

Data gaps · expand

How much technical information did specific customers have? Which elements of the infrastructure were in their immediate control loop. Which independent verification mechanisms were actually used, if any. How was the composition of the transmitted data and technical telemetry confirmed?

Analyst's conclusion

Pegasus is often seen as a digital surveillance case. That's true, but not enough. A more accurate conclusion is that modern closed technologies can create not only functional capabilities, but also areas of system dependence that the customer is not able to fully control and verify on their own. In such cases, they don't just buy the product. They buy an assumption about his work — and with it the risk of error, which cannot be completely covered by their own means. And this is no longer a matter of technique per se, but of the quality of a managerial and strategic decision. Mature analytics should answer more than just the question: What do we know? She is required to answer questions separately.: What don't we know? Why is this important? What kind of risk arises from this ignorance? The most dangerous asset is not the one that hides information. The most dangerous asset is the one for which it is impossible to determine with certainty what information it is hiding.