Meanwhile in Serbia https://citizenlab.ca/research/pegasus-spyware-infection-of-... "In collaboration with the SHARE Foundation, the Citizen Lab analyzed forensic artefacts from the iPhone of a member of Serbia’s student protest movement after they received an Apple Threat Notification warning of targeting with mercenary spyware." Zero clicks are cheap if NSO can afford to go after students.
That is how companies like Crowdfense can pay up to $5 million for an exploit. The sell it to some service (or have the service themselves) and generate revenue off of that. The person who sells that exploit gets some of that revenue, they're not getting $5 million up front.