{"id":488323,"date":"2023-04-19T12:41:38","date_gmt":"2023-04-19T10:41:38","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=488323"},"modified":"2023-04-19T12:47:21","modified_gmt":"2023-04-19T10:47:21","slug":"government-spyware-vendor-targets-iphones-with-zero-click-attack","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/488323-government-spyware-vendor-targets-iphones-with-zero-click-attack.html","title":{"rendered":"Government spyware vendor targets iPhones with zero-click attack"},"content":{"rendered":"<p>Security researchers at <a href=\"https:\/\/citizenlab.ca\/2023\/04\/nso-groups-pegasus-spyware-returns-in-2022\/\" target=\"_blank\" rel=\"noopener\"><strong>Citizen Lab have revealed<\/strong><\/a> that customers of notorious Israeli spyware company NSO Group used three new zero-click exploits to hack iPhones in 2022.<\/p>\n<p>While most security vulnerabilities that could lead to malware being deployed on a user&#8217;s phone typically require a victim to open a malicious link or compromised file, zero-click exploits execute an attack without any user action.<\/p>\n<p>Citizen Lab discovered infections on iPhones belonging to members of Mexican civil society groups, including human rights advocates from a firm representing victims of military abuse in that country.<\/p>\n<p>&#8220;Our ensuing investigation led us to conclude that, in 2022, NSO Group customers widely deployed at least three iOS 15 and iOS 16 zero-click exploit chains against civil society targets around the world,&#8221; the researchers said.<\/p>\n<p>The attacks exploited vulnerabilities in several iOS features \u2014 including Find My, iMessage, and HomeKit.<\/p>\n<p>The three zero-click exploits were labelled and described as follows:<\/p>\n<ul>\n<li><strong>PWNYOURHOME<\/strong> \u2014 Novel two-step exploit that first targets the HomeKit and then the iMessage processes in iOS 15 and iOS 16.<\/li>\n<li><strong>FINDMYPWN<\/strong> \u2014 Another two-step exploit that targets the Find My feature and then iMessage in iOS 16.<\/li>\n<li><strong>LATENTIMAGE<\/strong> \u2014 Detected on a single phone with an unspecified iOS version. It could also involve the <em>Find My<\/em> feature but uses a different exploit chain.<\/li>\n<\/ul>\n<p>Citizen Lab held back releasing details of these exploits to give Apple time to fix the vulnerabilities.<\/p>\n<p>NSO Group is infamous for providing its Pegasus spyware to governments with poor human rights histories to spy on their high-profile opponents.<\/p>\n<p>Mexico&#8217;s government and military have a history of serious human rights abuses, with an estimated 1,200 disappearances of individuals fighting against the Institutional Revolutionary Party-controlled government between 1968 and 1980.<\/p>\n<p>The United Nations said that the total number of officially-registered disappearances in the country stood at 100,000 last year.<\/p>\n<p>An <a href=\"https:\/\/mybroadband.co.za\/news\/security\/406906-ramaphosas-phone-identified-in-leaked-pegasus-spy-project-records.html\" target=\"_blank\" rel=\"noopener\"><strong>investigation dubbed the Pegasus Project<\/strong><\/a> found that Rwanda had been one of NSO Group&#8217;s biggest customers between 2016 and 2021.<\/p>\n<p>Rwandan President Paul Kagame reportedly put more than 3,500 phone numbers on a list of persons of interest for surveillance, including South African President Cyril Ramaphosa.<\/p>\n<p>Apple introduced a <a href=\"https:\/\/mybroadband.co.za\/news\/software\/451652-apple-announced-lockdown-mode-to-protect-against-state-sponsored-mercenary-spyware.html\" target=\"_blank\" rel=\"noopener\"><strong>Lockdown Mode security feature<\/strong><\/a> in July 2022,\u00a0 specifically aimed at users who might be prime targets of government surveillance.<\/p>\n<p>It severely limits certain iPhone features to minimise the risk of zero-click attacks.<\/p>\n<p>Citizen Lab said the feature had sent real-time warnings to some targeted users that prevented the PWNYOURHOME exploit from running on their devices.<\/p>\n<p>&#8220;Although NSO Group may have later devised a workaround for this real-time warning, we have not seen PWNYOURHOME successfully used against any devices on which Lockdown Mode is enabled,&#8221; Citizen Lab said.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/487965-major-ransomware-campaign-targets-mac-devices.html\" rel=\"bookmark\">Major ransomware campaign targets Mac devices<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>While most security vulnerabilities that could lead to malware being deployed on a user&#8217;s phone typically require a victim to open a malicious link or compromised file, zero-click exploits execute an attack without any user action.<\/p>\n","protected":false},"author":23,"featured_media":488333,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[19296,1952,801,54297,85705,59020,40280,18564,85695],"class_list":["post-488323","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-citizen-lab","tag-cyril-ramaphosa","tag-malware","tag-nso-group","tag-paul-kagame","tag-pegasus-spyware","tag-rwanda","tag-spyware","tag-zero-click-exploit"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/488323"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=488323"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/488323\/revisions"}],"predecessor-version":[{"id":488325,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/488323\/revisions\/488325"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/488333"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=488323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=488323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=488323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}