Several cybersecurity news outlets are covering the announcement from Apple regarding a new notification warning for iPhone users in over a hundred countries today. And it’s one that users should be taking seriously. We are living in a growing state of surveillance, where one’s every location, message, purchase, and behavior is tracked, often without their consent or in violation of their rights to privacy. The new alert will now tell users when their phone detects mercenary spyware targeted at them.
So what is mercenary spyware? As defined by EM360 Tech, it’s a type of malicious software developed and sold by private companies to governments, law enforcement agencies, and sometimes private individuals, and is designed for targeted surveillance. If an infostealer and a spearphishing campaign had a lovechild, it would mercenary spyware. Targets of this attack are generally journalists, human rights defenders, lawyers, political figures, diplomats, and civil society organizers, according to both Cyber Security News and The Hacker News. These victims are usually high value from an intelligence standpoint. But they are not the only ones, and Apple urges their users to take the alert seriously, rather than treating it like a joke, routine phishing warning, or generic security tip. The alert creates a popup on the lockscreen, can be seen in the Settings under ‘Apple Threat Notification’, or at the top of one’s account page when logged in. The wording of the warning is simple: ‘Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device.’
Among those actions is putting the device in Lockdown Mode, which is an optional but extreme security feature designed to reduce an iPhone’s attack surface by aggressively limiting message attachments, complex web technologies, unknown FaceTime calls, configuration profiles, and wired connections. Frankly, these limitations are all good practice anyway, and Apple states that they have not yet observed a successful compromise of a device with Lockdown Mode enabled. It will degrade some functionality of the device, but to my mind is no different than other strict browsing or messaging settings. Why would one leave their device unsecured in this day and age to begin with? (I keep my own phone at the strictest settings, but I’m an Android user.)
Apple also suggests subscribing to Access Now’s 24/7 Digital Security Helpline, which is a free support service for at risk users. And of course, keep the device up to date, a somewhat more difficult prospect given how often the software updates and the economically baffling expectation that every user has the ability to replace their device repeatedly to keep up with increased processing demands. Much simpler, but equally as recommended, is keeping the device secure using a passcode, Touch ID, or Face ID, enable two-factor authentication for one’s account, turn on Stolen Device Protection, install apps only from trusted sources, and do not open links or attachments from unknown senders. The usual precautions.
iPhone users are not the only potential victims of mercenary spyware, as it has also been seen in Android and iOS devices. But to my knowledge, Apple is the first to take an active stance on warning their users of its detection. I know there is a tendency towards complacency regarding popup warnings, but that does not mean they should be ignored. Users are at risk; paying attention is also good practice.