Apple recently issued warnings to some users, stating that it has detected a new wave of highly targeted attacks aimed at infiltrating iPhone, iPad, and Mac devices using so-called “mercenary spyware.” Once successfully infiltrated, such spyware can bypass all built-in encryption mechanisms, access private files, eavesdrop on communications, record audio and video, track location, and even remotely control the entire device.

Apple Warns Users of New Spyware Attacks and How to Respond
Apple confirmed to foreign media outlet TechCrunch that it sent threat notifications to specific users in 110 countries on Thursday. The company emphasized that this type of “mercenary” spyware is typically developed or commissioned by state-level actors, and the targets are not ordinary citizens but specific individuals with social influence, such as journalists, activists, politicians, and diplomats. Even though the scale of attacks may be limited, the consequences for those who become victims can be extremely severe.
existsin the updated support documentApple noted: “These attacks are far more sophisticated than typical cybercrime, and the operators of mercenary spyware invest significant resources to target a very small number of individuals and their devices. These attacks often cost millions of dollars and are short-lived, making detection and defense even more difficult.”

According to John Scott-Railton, a senior researcher at Citizen Lab, affected users will see an “Apple threat notification” on their device. It reads: “Apple detected a mercenary spyware attack targeting your iPhone, and you can take immediate steps to protect your data and device.” These attacks typically arrive in waves, and Apple issued similar notifications twice in 2024 to alert users to possible spyware activity targeting them. Apple says it sends warnings to users worldwide multiple times a year, now covering more than 150 countries.

In past cases, NSO Group has frequently been linked to such attacks, and the company’s notorious “Pegasus” spyware has repeatedly been exposed for monitoring high-risk groups. Despite NSO’s repeated denials of abuse, claiming its products are for government and law enforcement use only, Apple and other tech companies have filed lawsuits against it and forced related vendors to patch vulnerabilities exploited by Pegasus.

Apple recommends that all users who received a threat notification immediately enable Lockdown Mode, which will:
- Block most message attachments and link previews
- Restrict advanced network technology
- Restrict FaceTime Calls
- Disable features such as SharePlay, Game Center, and others.
- Block some Apple service invitations.
- Remove shared album and hide photo location information.
- Requires the device to be unlocked before connecting accessories or a computer.
- Block insecure Wi-Fi
- Installation of device management configuration profiles is prohibited.

The activation method is as follows:
- iPhone / iPad:
Go to “Settings” → “Privacy & Security” → scroll to the bottom → tap “Lockdown Mode” → “Turn On Lockdown Mode”. - Mac:
Go to “System Settings” → “Privacy & Security” → “Lockdown Mode” → click Enable.
Even if you have not received a threat notification, Apple still recommends that all users take the following security steps:
- Update your device to the latest version to ensure you get the latest security patches.
- Protect your device with a password, Touch ID, or Face ID.
- Enable anti-theft protection.
- Set a strong password for your Apple ID and enable two-factor authentication.
- Only install apps from the App Store.
- Use strong and unique passwords online, and use passkeys when supported.
- Do not open links or attachments from unknown senders.
Source: KOCPC Chinese