No Specific Vendor Identified

Apple Sends New Warnings About Targeted Spyware Attacks

Apple, Apple spyware, iPhone spyware, Apple Threat Notifications, Apple warning about targeted spyware attacks, how Apple Threat Notifications work, how to verify an Apple spyware warning
Facebook
X
LinkedIn
Reddit
WhatsApp

Apple has once again issued Threat Notifications to individual iPhone users, warning them that they may have been targeted by highly sophisticated mercenary spyware attacks.

According to reports from several users on Reddit, affected individuals received a notification on August 13 stating that Apple had detected a targeted mercenary spyware attack against their iPhone. Apple generally does not identify the specific malware behind individual warnings. As a result, the latest reports do not provide direct evidence linking the attacks to a particular vendor, such as NSO Group and its Pegasus spyware. Apple does, however, cite Pegasus in its support documentation as a historical example of this type of software. Forensic investigations into previous notifications have also confirmed Pegasus infections in some cases.

Ad

According to an Apple support document, the company sends these warnings to users in more than 150 countries when it detects a highly targeted mercenary spyware attack against an individual iPhone user. Historically, journalists, activists, politicians, and diplomats have been among the groups most frequently targeted. Apple describes these attacks as extremely expensive, highly sophisticated, and generally focused on a very small number of individuals:

“Mercenary spyware attacks cost millions of dollars and are often short lived, making them much harder to detect and prevent. The vast majority of users will never be targeted by such attacks.”

Apple

Ad

Apple Urges Recipients to Take the Warning Seriously

Apple says its detection process is based on its own threat intelligence and investigations. The company therefore considers these notifications high confidence warnings rather than precautionary alerts. Apple states:

“While our investigations can never achieve absolute certainty, Apple threat notifications are high confidence alerts that an individual user was targeted by a mercenary spyware attack and should be taken very seriously.”

Apple

Apple deliberately does not disclose the specific circumstances that trigger a notification. The company says this helps prevent attackers from learning how its detection mechanisms work and adapting their techniques to evade future detection. Affected users receive the warning both by email and via iMessage at the email addresses and phone numbers associated with their Apple Account. The notification is typically sent from threat-notifications@email.apple.com.

Because fake versions of these warnings are also circulating, Apple explicitly points out that a genuine notification will never ask users to click a link, open a file or app, or provide their password or verification code. To verify whether a warning is legitimate, Apple recommends signing in directly through account.apple.com, where a genuine notification will appear at the top of the page.

Anyone who believes they may have been targeted should enable Lockdown Mode and consult a cybersecurity professional.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel