Apple sent security warnings to some iPhone users who are believed to have been identified as targets of mercenary spyware. It was not a general notice sent to all users, but a high-confidence alert delivered when movement indicating an attack aimed at specific individuals is detected.
According to Apple and TechCrunch on the 18th, Apple sent new threat notifications on the 13th (local time) to targeted users in 110 countries. It did not disclose the number of people affected or the status by country. It was not confirmed whether Korean users were included.
On the iPhones of those warned, a message appears stating that the device may be a target of a mercenary spyware attack and that security measures are needed. Since this year, Apple has strengthened its alert system by displaying warnings on the lock screen and in the Settings app, and by allowing users to check related information via the email registered to the Apple account and the account webpage.
Receiving a warning does not mean the device has already been hacked or infected with spyware. However, Apple emphasized that, because this is a high-confidence assessment based on its own threat intelligence and investigation results, the user should take it seriously. Considering the possibility that attackers may change their methods to evade detection, it did not disclose specific assessment criteria or information about the spyware used or the actors behind it.
Unlike phishing and malware that target unspecified large numbers of people, mercenary spyware is a commercial tool used to closely monitor a small number of specific individuals such as journalists, politicians, activists, and diplomats. Attacks can involve millions of dollars, and there are known cases where private companies linked to state agencies are involved. Israel's NSO Group's "Pegasus" is representative, but no evidence has been found connecting it to the latest attacks.
The short validity period of attack techniques and their constant mutations also make response difficult. However, because significant expense and technical expertise are required, most ordinary iPhone users are not targeted. Apple also said there is no need to interpret this matter as a large-scale security incident affecting all users.
Since 2021, Apple has sent warnings several times a year whenever it detects related attacks, and targets have appeared in more than 150 countries so far. It recommended that warned users turn on "Lockdown Mode," which restricts some iPhone features to reduce the likelihood of attack. It also suggested seeking help from specialized organizations, such as the Digital Security Helpline run by the nonprofit Access Now.
Beware of fake alerts as well. Apple's official warnings do not ask via email or phone to click a link, open a file, install an app or profile, or enter a password or verification code. To confirm whether a warning is genuine, users should directly visit the Apple account webpage and check the notification at the top of the screen.