Mercenary Spyware Threats Targeting iPhone Users Across 110 Countries
On August 13th, Apple disseminated a significant wave of high-confidence threat notifications to users allegedly targeted by mercenary spyware attacks.
Apple clarified that these alerts are generated when their internal threat intelligence and investigations suggest that an individual may have been compromised.
As confirmed in a statement to Fox News by journalist Kurt Knutsson, these notifications reached users in an astounding 110 countries; however, Apple refrained from publicly disclosing the specific regions involved in this latest notification cycle.
According to Apple, mercenary spyware attacks are intricate and financially burdensome endeavors, typically aimed at a select cohort of individuals due to their prominence or actions.
Unlike conventional malware, which is widely propagated, this spyware is meticulously designed to infiltrate specific devices, potentially granting access to confidential information and communications.
The company emphasized that historical accounts from civil society organizations, tech firms, and investigative journalists indicate that such high-cost operations are commonly linked to state-sponsored actors or private entities manufacturing spyware on their behalf.
One notable instance referenced by Apple is the notorious Pegasus spyware developed by NSO Group, based in Israel.
However, the tech giant has not drawn explicit connections between the current alerts and Pegasus or any particular spyware.
Previously, in 2021, Apple initiated legal action against NSO Group after identifying incidents where an iOS vulnerability was exploited to install Pegasus on targeted devices.
This spyware could potentially allow access to sensitive components such as a device’s microphone and camera.
Receiving these alerts indicates that Apple has recognized potential targeting attempts against an individual; nevertheless, it does not confirm that the device has been successfully compromised.
Apple opts against revealing the specifics of the spyware, the perpetrator, or the nation behind each notification, arguing that such disclosures could inadvertently equip attackers with knowledge to bypass detection in the future.
This recent alert wave also underscores the expansive reach of commercial spyware. Since 2021, Apple has notified users in more than 150 countries, and it confirmed that the August notifications affected users in 110 nations.
Following these alerts, Access Now’s Digital Security Helpline reported a remarkable uptick in requests for support, approximately 30–40% more than usual after an Apple notification round.
Similarly, Citizen Lab researcher John Scott-Railton characterized the scale and geographic diversity of the public notifications as unprecedented.
In light of the alerts, Apple recommends users update their devices, enable Lockdown Mode, and seek specialized support.
They caution that authentic threat notifications will never solicit users to click on links, install software, or provide passwords or verification codes.
Comprehensive guidance on protecting devices and validating the authenticity of notifications is accessible via Apple’s security guidance.
Significance of the Alerts
These alerts illuminate critical policy discussions regarding the commercial landscape for sophisticated surveillance tools.
Governments may procure spyware for law enforcement or national security objectives, yet documented instances involving journalists, activists, politicians, and diplomats have intensified scrutiny on the procurement and authorization processes for these tools, as well as the safeguards and oversight that govern their utilization and export.
Furthermore, these notifications reflect the intensified role of technology companies in identifying complex surveillance activities, alerting affected users, and creating technical defenses.

Simultaneously, the ambiguity surrounding specific alerts complicates efforts to ascertain the identity of those deploying the spyware and the authorities under which they operate, thereby hindering investigations into potential abuses and the accountability of those involved.
Source link: Dig.watch.



