Apple has issued threat notifications to users in about 92 countries, alerting them to potential spyware attacks by mercenary groups, which could lead to iPhone hacks.
The iPhone manufacturer said the specific victims are selected for attack possibly because of who they are or what they do.
The company said its threat notifications are “high-confidence alerts” that a user has been individually chosen by a mercenary spyware attack, and should be taken very seriously.
The National looks at Apple’s latest warning and explores the severity of an attack.
What does Apple warning say?
In its warning, Apple clearly said the mercenary spyware attack is trying to remotely compromise the victim’s iPhone.
However, Apple did not divulge many details as it could alert the culprits and allow them to pivot the nature of the attack.
“We are unable to provide more information about what caused us to send you this notification, as that may help mercenary spyware attackers adapt their behaviour to evade detection in the future,” Apple said.
“While Apple has not disclosed many details about the attack, it is reasonable to assume this targeted breach is an identity based attack aimed to steal credentials and further their lateral movement into a user's electronic ecosystem,” Morey Haber, chief security adviser at technology firm BeyondTrust, told The National.
“The initial stages of such attacks are usually so targeted and personal that victims believe them and they are easily convinced to engage out of fear, desperation, or some other emotion based on the contents.”
Why mercenary spyware attacks are hard to detect?
Mercenary spyware attacks are usually backed by substantial funding, and they keep evolving over the time making it hard for security personnel to detect them at early stages, according to cyber experts.
In this case, the Cupertino-based company solely relied on internal threat-intelligence information and investigations to detect such attacks.
It said these attacks are more complex than regular cybercriminal activities and consumer malwares. Attackers use high-end technology and resources to target a very small number of specific individuals and their devices rather than launching a mass attack.
“Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent,” Apple said.
Who are the potential victims?
Apple said mercenary spyware attacks often target selective high-profile individuals such as journalists, activists, politicians and diplomats. They are orchestrated by various entities, including private companies developing mercenary spyware on their behalf.
In its detailed threat update, Apple gave the example of Israeli cyber intelligence firm NSO Group that developed Pegasus spyware for spying on mobile phones and harvesting their data.
Since 2021, Apple has sent such threat notifications multiple times a year, notifying users in over 150 countries. However, it refrained from attributing them to any particular state actor or region.
“The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks makes them some of the most advanced digital threats in existence today. As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions.”
How is Apple informing users?
Affected users are informed through email or iMessage using the details linked with the user's Apple ID. A notification is also displayed at the top of the page after the user signs into appleid.apple.com.
The notifications also provide additional steps that notified users can take to help protect their devices, including enabling lockdown mode.
What to do if you have received an Apple threat notification
Apple recommended the victims to immediately contact security experts at digital security helpline at the non-profit Access Now. They can contact them 24 hours a day, seven days a week through their website.
Outside organisations do not have any information about what caused Apple to send a threat notification, but they can assist targeted users with tailored security advice, the company said.
Why Apple removed 'state-sponsored' with 'mercenary spyware attacks'
Previously labelled as “state-sponsored”, Apple has now replaced all such mentions with “mercenary spyware attacks” when describing the perpetrators.
Apple's removal of the term state-sponsored comes after it repeatedly faced pressure from the Indian government on linking such breaches to state actors, reported Reuters.
India's opposition leaders have accused Prime Minister Narendra Modi's government of attempting to compromise into their mobile phones following Apple's messages in October that warned of “state-sponsored” attacks.
Why are criminals targeting mobile devices?
For threat actors looking to target high-profile individuals, mobile devices have become one of the most vulnerable targets to compromise, industry analysts said.
Apple’s latest action of informing users that their devices may have been targeted is concerning but encouraging to see them taking measures to protect potentially impacted individual, Scott Caveza, staff research engineer at cyber security firm Tenable, told The National.
“Mobile device exploits can fetch millions of dollars … with millions of dollars at play, one thing is certain, data is key and attackers, including nation states, are willing to invest heavily for exploits that can be used against high value targets and individuals."
Tips for all users to safeguard their iPhone
- Update devices to the latest software, as that includes the latest security fixes
- Protect devices with a passcode
- Use two-factor authentication and a strong password for Apple ID
- Install apps only from the App Store
- Use strong and unique passwords online
- Don’t click on links or attachments from unknown senders
The specs: Lamborghini Aventador SVJ
Price, base: Dh1,731,672
Engine: 6.5-litre V12
Gearbox: Seven-speed automatic
Power: 770hp @ 8,500rpm
Torque: 720Nm @ 6,750rpm
Fuel economy: 19.6L / 100km
NO OTHER LAND
Director: Basel Adra, Yuval Abraham, Rachel Szor, Hamdan Ballal
Stars: Basel Adra, Yuval Abraham
Rating: 3.5/5
COMPANY%20PROFILE
%3Cp%3E%3Cstrong%3EName%3A%20%3C%2Fstrong%3ESmartCrowd%0D%3Cbr%3E%3Cstrong%3EStarted%3A%20%3C%2Fstrong%3E2018%0D%3Cbr%3E%3Cstrong%3EFounder%3A%20%3C%2Fstrong%3ESiddiq%20Farid%20and%20Musfique%20Ahmed%0D%3Cbr%3E%3Cstrong%3EBased%3A%20%3C%2Fstrong%3EDubai%0D%3Cbr%3E%3Cstrong%3ESector%3A%20%3C%2Fstrong%3EFinTech%20%2F%20PropTech%0D%3Cbr%3E%3Cstrong%3EInitial%20investment%3A%20%3C%2Fstrong%3E%24650%2C000%0D%3Cbr%3E%3Cstrong%3ECurrent%20number%20of%20staff%3A%3C%2Fstrong%3E%2035%0D%3Cbr%3E%3Cstrong%3EInvestment%20stage%3A%20%3C%2Fstrong%3ESeries%20A%0D%3Cbr%3E%3Cstrong%3EInvestors%3A%20%3C%2Fstrong%3EVarious%20institutional%20investors%20and%20notable%20angel%20investors%20(500%20MENA%2C%20Shurooq%2C%20Mada%2C%20Seedstar%2C%20Tricap)%3C%2Fp%3E%0A
From Zero
Artist: Linkin Park
Label: Warner Records
Number of tracks: 11
Rating: 4/5
COMPANY%20PROFILE%20
%3Cp%3E%3Cstrong%3ECompany%20name%3A%20%3C%2Fstrong%3EAlmouneer%3Cbr%3E%3Cstrong%3EStarted%3A%3C%2Fstrong%3E%202017%3Cbr%3E%3Cstrong%3EFounders%3A%3C%2Fstrong%3E%20Dr%20Noha%20Khater%20and%20Rania%20Kadry%3Cbr%3E%3Cstrong%3EBased%3A%20%3C%2Fstrong%3EEgypt%3Cbr%3E%3Cstrong%3ENumber%20of%20staff%3A%20%3C%2Fstrong%3E120%3Cbr%3E%3Cstrong%3EInvestment%3A%20%3C%2Fstrong%3EBootstrapped%2C%20with%20support%20from%20Insead%20and%20Egyptian%20government%2C%20seed%20round%20of%20%3Cbr%3E%243.6%20million%20led%20by%20Global%20Ventures%3Cbr%3E%3C%2Fp%3E%0A
WHAT%20IS%20THE%20LICENSING%20PROCESS%20FOR%20VARA%3F
%3Cp%3EVara%20will%20cater%20to%20three%20categories%20of%20companies%20in%20Dubai%20(except%20the%20DIFC)%3A%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ECategory%20A%3A%3C%2Fstrong%3E%20Minimum%20viable%20product%20(MVP)%20applicants%20that%20are%20currently%20in%20the%20process%20of%20securing%20an%20MVP%20licence%3A%20This%20is%20a%20three-stage%20process%20starting%20with%20%5B1%5D%20a%20provisional%20permit%2C%20graduating%20to%20%5B2%5D%20preparatory%20licence%20and%20concluding%20with%20%5B3%5D%20operational%20licence.%20Applicants%20that%20are%20already%20in%20the%20MVP%20process%20will%20be%20advised%20by%20Vara%20to%20either%20continue%20within%20the%20MVP%20framework%20or%20be%20transitioned%20to%20the%20full%20market%20product%20licensing%20process.%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ECategory%20B%3A%3C%2Fstrong%3E%20Existing%20legacy%20virtual%20asset%20service%20providers%20prior%20to%20February%207%2C%202023%2C%20which%20are%20required%20to%20come%20under%20Vara%20supervision.%20All%20operating%20service%20proviers%20in%20Dubai%20(excluding%20the%20DIFC)%20fall%20under%20Vara%E2%80%99s%20supervision.%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ECategory%20C%3A%3C%2Fstrong%3E%20New%20applicants%20seeking%20a%20Vara%20licence%20or%20existing%20applicants%20adding%20new%20activities.%20All%20applicants%20that%20do%20not%20fall%20under%20Category%20A%20or%20B%20can%20begin%20the%20application%20process%20through%20their%20current%20or%20prospective%20commercial%20licensor%20%E2%80%94%20the%20DET%20or%20Free%20Zone%20Authority%20%E2%80%94%20or%20directly%20through%20Vara%20in%20the%20instance%20that%20they%20have%20yet%20to%20determine%20the%20commercial%20operating%20zone%20in%20Dubai.%C2%A0%3C%2Fp%3E%0A
INDIA V SOUTH AFRICA
First Test: October 2-6, at Visakhapatnam
Second Test: October 10-14, at Maharashtra
Third Test: October 19-23, at Ranchi
EVIL%20DEAD%20RISE
%3Cp%3E%3Cstrong%3EDirector%3A%20%3C%2Fstrong%3ELee%20Cronin%3Cbr%3E%3Cstrong%3EStars%3A%20%3C%2Fstrong%3EAlyssa%20Sutherland%2C%20Morgan%20Davies%2C%20Lily%20Sullivan%3Cbr%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%205%2F5%3C%2Fp%3E%0A
Reputation
Taylor Swift
(Big Machine Records)
Results:
6.30pm: Maiden | US$45,000 (Dirt) | 1,400 metres
Winner: Tabarak, Royston Ffrench (jockey), Rashed Bouresly (trainer)
7.05pm: Handicap | $175,000 (Turf) | 3,200m
Winner: Dubhe, William Buick, Charlie Appleby
7.40pm: UAE 2000 Guineas Group 3 | $250,000 (D) | 1,600m
Winner: Estihdaaf, Christophe Soumillon, Saeed bin Suroor
8.15pm: Handicap | $135,000 (T) | 1,800m
Winner: Nordic Lights, William Buick, Charlie Appleby
8.50pm: Al Maktoum Challenge Round 2 Group 2 | $450,000 (D) | 1,900m
Winner: North America, Richard Mullen, Satish Seemar
9.25pm: Handicap | $175,000 (T) | 1,200m
Winner: Mazzini, Adrie de Vries, Fawzi Nass
10pm: Handicap | $135,000 (T) | 1,400m.
Winner: Mubtasim, William Buick, Charlie Appleby
The specs
Engine: 6.2-litre V8
Power: 502hp at 7,600rpm
Torque: 637Nm at 5,150rpm
Transmission: 8-speed dual-clutch auto
Price: from Dh317,671
On sale: now
'Top Gun: Maverick'
Rating: 4/5
Directed by: Joseph Kosinski
Starring: Tom Cruise, Val Kilmer, Jennifer Connelly, Jon Hamm, Miles Teller, Glen Powell, Ed Harris
The biog
Name: Abeer Al Shahi
Emirate: Sharjah – Khor Fakkan
Education: Master’s degree in special education, preparing for a PhD in philosophy.
Favourite activities: Bungee jumping
Favourite quote: “My people and I will not settle for anything less than first place” – Sheikh Mohammed bin Rashid.
THE%20SWIMMERS
%3Cp%3E%3Cstrong%3EDirector%3A%20%3C%2Fstrong%3ESally%20El-Hosaini%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStars%3A%20%3C%2Fstrong%3ENathalie%20Issa%2C%20Manal%20Issa%2C%20Ahmed%20Malek%20and%20Ali%20Suliman%C2%A0%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%20%3C%2Fstrong%3E4%2F5%3C%2Fp%3E%0A
THE BIG THREE
NOVAK DJOKOVIC
19 grand slam singles titles
Wimbledon: 5 (2011, 14, 15, 18, 19)
French Open: 2 (2016, 21)
US Open: 3 (2011, 15, 18)
Australian Open: 9 (2008, 11, 12, 13, 15, 16, 19, 20, 21)
Prize money: $150m
ROGER FEDERER
20 grand slam singles titles
Wimbledon: 8 (2003, 04, 05, 06, 07, 09, 12, 17)
French Open: 1 (2009)
US Open: 5 (2004, 05, 06, 07, 08)
Australian Open: 6 (2004, 06, 07, 10, 17, 18)
Prize money: $130m
RAFAEL NADAL
20 grand slam singles titles
Wimbledon: 2 (2008, 10)
French Open: 13 (2005, 06, 07, 08, 10, 11, 12, 13, 14, 17, 18, 19, 20)
US Open: 4 (2010, 13, 17, 19)
Australian Open: 1 (2009)
Prize money: $125m
All Black 39-12 British & Irish Lions
MATCH INFO
Europa League semi-final, second leg
Atletico Madrid (1) v Arsenal (1)
Where: Wanda Metropolitano
When: Thursday, May 3
Live: On BeIN Sports HD
Indian origin executives leading top technology firms
Sundar Pichai
Chief executive, Google and Alphabet
Satya Nadella
Chief executive, Microsoft
Ajaypal Singh Banga
President and chief executive, Mastercard
Shantanu Narayen
Chief executive, chairman, and president, Adobe
Indra Nooyi
Board of directors, Amazon and former chief executive, PepsiCo
The National's picks
4.35pm: Tilal Al Khalediah
5.10pm: Continous
5.45pm: Raging Torrent
6.20pm: West Acre
7pm: Flood Zone
7.40pm: Straight No Chaser
8.15pm: Romantic Warrior
8.50pm: Calandogan
9.30pm: Forever Young
Result
Tottenhan Hotspur 2 Roma 3
Tottenham: Winks 87', Janssen 90 1'
Roma 3
D Perotti 13' (pen), C Under 70', M Tumminello 90 2"
Washmen Profile
Date Started: May 2015
Founders: Rami Shaar and Jad Halaoui
Based: Dubai, UAE
Sector: Laundry
Employees: 170
Funding: about $8m
Funders: Addventure, B&Y Partners, Clara Ventures, Cedar Mundi Partners, Henkel Ventures
The%C2%A0specs%20
%3Cp%3E%3Cstrong%3EEngine%3A%3C%2Fstrong%3E%204-cylinder%202.0L%20TSI%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%3C%2Fstrong%3E%20Dual%20clutch%207-speed%0D%3Cbr%3E%3Cstrong%3EPower%3A%3C%2Fstrong%3E%20320HP%20%2F%20235kW%0D%3Cbr%3E%3Cstrong%3ETorque%3A%3C%2Fstrong%3E%20400Nm%0D%3Cbr%3E%3Cstrong%3EPrice%3A%20%3C%2Fstrong%3Efrom%20%2449%2C709%20%0D%3Cbr%3E%3Cstrong%3EOn%20sale%3A%3C%2Fstrong%3E%20now%3C%2Fp%3E%0A
THE DRAFT
The final phase of player recruitment for the T10 League has taken place, with UAE and Indian players being drafted to each of the eight teams.
Bengal Tigers
UAE players: Chirag Suri, Mohammed Usman
Indian: Zaheer Khan
Karachians
UAE players: Ahmed Raza, Ghulam Shabber
Indian: Pravin Tambe
Kerala Kings
UAE players: Mohammed Naveed, Abdul Shakoor
Indian: RS Sodhi
Maratha Arabians
UAE players: Zahoor Khan, Amir Hayat
Indian: S Badrinath
Northern Warriors
UAE players: Imran Haider, Rahul Bhatia
Indian: Amitoze Singh
Pakhtoons
UAE players: Hafiz Kaleem, Sheer Walli
Indian: RP Singh
Punjabi Legends
UAE players: Shaiman Anwar, Sandy Singh
Indian: Praveen Kumar
Rajputs
UAE players: Rohan Mustafa, Ashfaq Ahmed
Indian: Munaf Patel