TL;DR:
- The CIA used NSO Group's Pegasus spyware as a deception weapon during the April 4 rescue of a downed F-15E weapons systems officer in Iran, sending fake messages to IRGC commanders claiming the airman had already been found [1].
- This marks the first confirmed use of commercial spyware for active battlefield deception: not surveillance, but sending fabricated WhatsApp and Signal messages through compromised devices to mislead an enemy in real time.
- The Biden-era executive order banning government use of commercial spyware appears to have been either bypassed or reinterpreted. The CIA's use of Pegasus directly contradicts the 2023 ban, and NSO Group remains on the Commerce Department entity list [2].
- If spyware can send fake messages through your phone, surveillance is the least of your problems: any compromised device becomes a puppet that can impersonate you to your contacts, your employer, or your government.
What Happened Over Iran
On April 4, 2026, an F-15E Strike Eagle was shot down over southern Iran. The pilot was recovered quickly, but the weapons systems officer (callsign "Dude 44 Bravo") ejected separately and ended up alone on a mountainside while thousands of Iranian soldiers and IRGC operatives fanned out to find him [3].
He survived 36 hours in hiding. During that time, the CIA ran a deception campaign that bought the rescue team enough time to extract him Saturday night.
CIA Director John Ratcliffe described the operation as "comparable to hunting for a single grain of sand in the middle of a desert." He said the airman was "invisible to the enemy, but not to the CIA" [4].
What Ratcliffe didn't say publicly, but multiple reports have since confirmed, is that the CIA used NSO Group's Pegasus spyware as a core component of that deception.
Pegasus as a Deception Weapon
According to the Times of Israel, citing intelligence sources, the CIA used Pegasus to send fake messages to Iranian leadership and IRGC operatives claiming the downed airman had already been found [1]. The messages were designed to call off or redirect the search while U.S. forces prepared the extraction.
This is not how anyone thinks about spyware. Pegasus is known for silent phone infiltration: reading messages, activating microphones and cameras, extracting data. That's bad enough. But the Iran operation reveals a capability that's far more dangerous: sending messages from a compromised phone that appear to come from the phone's owner.
Former CIA station chief Dan Hoffman explained the approach: "The CIA would have looked to find those channels of communication that we know we can exploit that the Iranian security force are listening to... supplied some information there, some of it true, to establish the bona fides of the channel" [5].
The operation ran three simultaneous tracks: tracking the airman's location, monitoring Iranian search parties, and running the deception campaign itself. The CIA also reportedly attempted to convince the Iranians that the U.S. was preparing a maritime rescue, while the actual extraction happened by air from the mountains [5].
Ghost Murmur and the Fog of Disclosure
The administration also promoted "Ghost Murmur," allegedly a quantum heartbeat-detection system built by Lockheed Martin's Skunk Works that found the airman from a distance by detecting his heartbeat [6].
Scientists aren't buying it. Researchers at Scientific American and multiple physics departments have pointed out that the described capabilities (detecting a single heartbeat at thousands of feet) contradict established physics. The technology as described "finds no support in decades of peer-reviewed physics, even with the help of AI" [7].
Cybersecurity analysts offer a more plausible reading: Ghost Murmur is likely the name for the deception architecture itself: the network of compromised Iranian devices used to create confusion, not a magical sensor. The airman was probably located through conventional signals intelligence, including his Combat Survivor Evader Locator (CSEL) beacon, a Boeing-manufactured device used since 2009 [6].
The theatrics around Ghost Murmur may themselves be part of the deception, misdirecting attention toward a physics-defying gadget and away from the real story: the CIA is actively using commercial spyware as a weapon.
The Legal Problem
In March 2023, President Biden signed an executive order prohibiting "operational use by the United States Government of commercial spyware that poses risks to national security or has been misused by foreign actors to enable human rights abuses" [8]. NSO Group has been on the Commerce Department entity list since November 2021, blacklisted from receiving American technology after its tools were used to target journalists, activists, and government officials worldwide [9].
NSO Group was ordered to pay $167 million in damages to WhatsApp in May 2025 after a U.S. court found it liable for hacking 1,400 users' devices [10].
So how is the CIA using Pegasus?
Three possibilities:
- The executive order has been quietly rescinded or reinterpreted under the Trump administration. NSO Group spent over $1.8 million on Republican campaigns in the 2024 election cycle and hired lobbyists with close ties to the administration [2].
- The CIA had Pegasus before the ban and continued using it. The New York Times reported in 2022 that the CIA had arranged for Djibouti's government to purchase Pegasus, and the agency was known to have tested the tool [2].
- Intelligence agencies consider wartime operations exempt from the commercial spyware ban, a legal interpretation that hasn't been publicly tested.
None of these answers is reassuring. All of them confirm that the guardrails on commercial spyware are weaker than advertised.
Why This Changes Everything
The surveillance debate has always focused on who's watching. This story is about something worse: who's speaking through your phone without your knowledge.
If Pegasus can send fake WhatsApp and Signal messages from a compromised device, messages that appear to come from the device's owner, the implications extend far beyond military operations:
- Journalists: A compromised phone could send fabricated messages that destroy source relationships or create false paper trails.
- Activists: Fake messages could provoke infighting, coordinate fake meetups, or frame targets for crimes they didn't plan.
- Executives: Fabricated communications from a CEO's phone could move markets, authorize transactions, or trigger investigations.
- Ordinary people: A compromised phone that can impersonate you is identity theft weaponized at the operating system level.
The CIA used this capability against Iranian military commanders. But 45 governments have purchased Pegasus [2]. The same tool is deployed against dissidents in Saudi Arabia, politicians in Poland, and journalists in Mexico. The deception capability doesn't disappear when a different government uses it.
The Oversight Gap
Several lawmakers were already pressing for clearer oversight of private cyberweapons contracts before this story broke. The reported CIA-NSO collaboration "cuts directly across the legal framework governing intelligence community use of commercial vendors" [1].
But congressional oversight of intelligence activities is notoriously thin. The Iran rescue is being celebrated as a success, and it was, operationally. That makes challenging the methods politically costly. No legislator wants to be the person who criticizes the operation that saved an American servicemember's life.
Which is exactly why this moment matters. If offensive spyware use gets normalized under the cover of a successful rescue, the precedent is set. The next use won't be on an Iranian battlefield. It'll be wherever the next administration decides it's convenient.
What You Can Do
- Understand that end-to-end encryption doesn't protect against device compromise: Signal and WhatsApp encrypt messages in transit, but Pegasus operates on the device itself. If your phone is compromised, encryption is irrelevant because the attacker reads messages before they're encrypted, and can send messages as you.
- Keep your devices updated: Pegasus exploits known and zero-day vulnerabilities. Updates won't stop a nation-state, but they close the easier attack paths.
- Use Lockdown Mode on Apple devices: Apple's Lockdown Mode disables many of the features Pegasus exploits. It limits functionality but significantly raises the difficulty of compromise.
- Verify sensitive communications through separate channels: If someone sends you an unexpected or unusual message, confirm through a different medium: a phone call, in person, or through a separate device.
- Support organizations fighting commercial spyware: Citizen Lab, EFF, Amnesty International's Security Lab, and Access Now all do critical work tracking and exposing spyware deployments.
The Bottom Line
The CIA turned commercial spyware into a battlefield deception weapon. That's a line that's never been publicly crossed before. Pegasus was already dangerous as a surveillance tool. Now it's been demonstrated as a tool that can put words in your mouth, send messages from your phone, and impersonate you to anyone in your contacts.
The rescue of "Dude 44 Bravo" was heroic. But the methods used have implications that extend far beyond one mountainside in Iran. If the world's most notorious spyware can be used offensively by a government that supposedly banned it, the question isn't whether Pegasus is dangerous. It's whether any phone anywhere is trustworthy.
Sources
- Times of Israel: "CIA reportedly used Pegasus software for deception op during rescue of airman in Iran"
- Wikipedia: "Pegasus (spyware)", NSO Group history, government purchases, Biden executive order, lobbying
- Nextgov/FCW: "CIA deception campaign helped US rescue downed airman in Iran, director says"
- Newsweek: "What Is Ghost Murmur? Secretive CIA Tool Linked to Iran Airman Rescue"
- Fox News: "Ex-CIA station chief reveals agency exploited Iranian communication channels in airman rescue"
- GreekReporter: "CIA's 'Ghost Murmur' Device That Located US Airman Sparks Physics Debate"
- Scientific American: "What is the quantum 'Ghost Murmur' purportedly used in Iran? Scientists question CIA's claim"
- TechMonitor: "US government banned from using spyware like Pegasus"
- Washington Post: "U.S. sanctions Israel's NSO Group over Pegasus spyware"
- Amnesty International: "US: Spyware ruling a welcome step towards accountability"