# Pegasus Spyware ## Identification Pegasus is the owner-supplied normalization for “RT Buddy”; the faithful transcription preserves the original phrase. Bryant McGill states that the identification arose from log observations in which the relevant activity or resources appeared with [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]], particularly through documented resources visible in those logs. He further states that finding Pegasus heuristics alone means nothing as proof because “Pegasus” is a clumsy cover for something else that later archive materials will detail. The notebook page alone does not prove the identification. ## Scanned_20260730-1314 evidence In [[Scanned_20260730-1314|Scanned_20260730-1314]], PDF page 12, this term appears in the notebook’s reconstruction and relationship map. See [[Scanned_20260730-1314#Scanned_20260730-1314.pdf — PDF page 12|page 12]]. ## Evidentiary status The notebook occurrence establishes research context and page-level proximity. It does not alone prove ownership, installation, account use, employment, partnership, attribution, or operational deployment. ## RT Buddy / Pegasus observed-log context **Owner-supplied observation:** Bryant McGill states that the RT Buddy/Pegasus identification arose when the relevant activity or resources appeared in logs together with [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]], particularly through documented resources visible in those logs. The preserved logs are the cited observational basis. This records what was observed; it does not by itself establish that every Apple RTBuddy service reference is Pegasus, nor does page or log proximity alone prove infection, control, authorship, or attribution. ## Pegasus heuristic caution **Owner-supplied interpretation:** Bryant McGill states that finding Pegasus heuristics, standing alone, means nothing as proof of the underlying system or attribution. In his interpretation, “Pegasus” is a very clumsy cover for something else, which later documents in this archive will detail. Until those materials are incorporated, heuristic matches must not be treated as proof of Pegasus infection, NSO Group attribution, or final identification of the underlying mechanism. ## Scanned_20260730-1946 overlay PDF page 5 writes “RT.BUDDY 1 V.2” beside [[Remote Buddy]], an independently identifiable legitimate application; PDF page 8 writes “RTBUDDY V.2” beside the unresolved [[ROOTBUDDY2]]. Exact forms remain in transcription and resolve here under the owner's canonical RT Buddy identification. The notebook-intended relationship among the three Buddy labels remains unresolved, so the notes cross-reference one another without merging them or asserting that they are unrelated. Pages 17–18 then assemble a mobile-analysis laboratory—decryption, decompilation, Frida instrumentation, pinning bypass, vulnerable training apps, proxies, and root/jailbreak frameworks. This is a significant shift from naming a suspected system toward tools capable of testing artifacts and behavior, but the notebook does not preserve a case acquisition, hash, runtime trace, or attribution chain. The identification's stated observational basis remains documented resources seen in logs with [[CrashCapture]] or [[Heimdallr]]. Pegasus heuristics alone mean nothing as proof of infection, NSO attribution, or final identification of the underlying mechanism.