About
MVT is a collection of command-line tools that gathers evidence from a phone to help show whether it may have been hacked. Amnesty International's Security Lab built it in July 2021 during the Pegasus Project investigation, and Amnesty and other contributors still maintain it. It can compare a phone's data against public lists of known signs of infection (called indicators of compromise) from documented spyware campaigns. It has two commands, mvt-ios and mvt-android, one for each type of phone.
It's a research tool for technologists and investigators, not an app for everyday users. You need to understand digital forensics and be comfortable on the command line.
Amnesty says it isn't meant for self-checking your own phone. If you're worried about your device's security, get help from a reputable expert. The licence is a modified Mozilla Public License that allows use only with the consent of the person whose data is being analysed.
Features
- Forensic checks for Android and iOS devices
- Scans for known spyware using public indicators of compromise
- Two commands: mvt-ios and mvt-android
- Built by Amnesty International Security Lab (Pegasus Project)
- Installs with pip3 install mvt
- Consent-based licence (analysis only with the owner's permission)
- For technologists and investigators, not everyday users
