Several cybersecurity news outlets are covering the announcement from Apple regarding a new notification warning for iPhone users in over a hundred countries today. And itâs one that users should be taking seriously. We are living in a growing state of surveillance, where oneâs every location, message, purchase, and behavior is tracked, often without their consent or in violation of their rights to privacy. The new alert will now tell users when their phone detects mercenary spyware targeted at them.
So what is mercenary spyware? As defined by EM360 Tech, itâs a type of malicious software developed and sold by private companies to governments, law enforcement agencies, and sometimes private individuals, and is designed for targeted surveillance. If an infostealer and a spearphishing campaign had a lovechild, it would mercenary spyware. Targets of this attack are generally journalists, human rights defenders, lawyers, political figures, diplomats, and civil society organizers, according to both Cyber Security News and The Hacker News. These victims are usually high value from an intelligence standpoint. But they are not the only ones, and Apple urges their users to take the alert seriously, rather than treating it like a joke, routine phishing warning, or generic security tip. The alert creates a popup on the lockscreen, can be seen in the Settings under âApple Threat Notificationâ, or at the top of oneâs account page when logged in. The wording of the warning is simple: âApple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device.â
Among those actions is putting the device in Lockdown Mode, which is an optional but extreme security feature designed to reduce an iPhoneâs attack surface by aggressively limiting message attachments, complex web technologies, unknown FaceTime calls, configuration profiles, and wired connections. Frankly, these limitations are all good practice anyway, and Apple states that they have not yet observed a successful compromise of a device with Lockdown Mode enabled. It will degrade some functionality of the device, but to my mind is no different than other strict browsing or messaging settings. Why would one leave their device unsecured in this day and age to begin with? (I keep my own phone at the strictest settings, but Iâm an Android user.)
Apple also suggests subscribing to Access Nowâs 24/7 Digital Security Helpline, which is a free support service for at risk users. And of course, keep the device up to date, a somewhat more difficult prospect given how often the software updates and the economically baffling expectation that every user has the ability to replace their device repeatedly to keep up with increased processing demands. Much simpler, but equally as recommended, is keeping the device secure using a passcode, Touch ID, or Face ID, enable two-factor authentication for oneâs account, turn on Stolen Device Protection, install apps only from trusted sources, and do not open links or attachments from unknown senders. The usual precautions.
iPhone users are not the only potential victims of mercenary spyware, as it has also been seen in Android and iOS devices. But to my knowledge, Apple is the first to take an active stance on warning their users of its detection. I know there is a tendency towards complacency regarding popup warnings, but that does not mean they should be ignored. Users are at risk; paying attention is also good practice.