// HACKER NEWS — CYBERSECURITY
Apple threat notifications and spyware: what everyone should know
Since 2001, Apple has been warning its users when they may have been targeted by spyware, using email, iMessage, and banners in their accounts. But in September of this year, the company began to place these threat notifications directly in users’ device Lock Screen and Settings — making them harder to miss. Here’s what you need to know about Apple threat notifications and spyware attacks in general, and what they mean for your digital security.
Put simply, that Apple detected activity in your device signalling that you have been targeted with so-called mercenary spyware, that is, the sophisticated commercial surveillance technology that is sold by companies like NSO Group, Paragon, or Cytrox, often exclusively to government clients.
This alert does not tell you whether or not the spyware attack succeeded, nor does it provide information about who might be behind the attack or what their motives may be. Further analysis is required for you to see a clearer picture.
A threat notification is like a fire alarm; it draws your attention to the possibility of danger, but you still need the fire brigade. If you have received an authentic Apple threat notification, you should immediately seek expert support from trusted professionals or organizations who can help you conduct a digital forensic investigation. Be careful, however, to ensure that the message is authentic to avoid scams or phishing.
A forensic investigation process takes time, but it will help you better assess and take control of the situation.
If you are a member of civil society, such as an activist, journalist, or human rights defender, you can contact Access Now’s Digital Security Helpline to get more tailored advice. As Apple says, “we strongly suggest notified users enlist expert help, such as the rapid-response emergency security assistance provided by the Digital Security Helpline at the nonprofit Access Now.”
When dealing with a spyware attack, it is important to preserve the evidence that a spyware attack or attempt may have left in your device as soon as possible. Time is of the essence, as data is being overwritten every minute that a phone or laptop stays on. Investigators would work with you to preserve that evidence.
Next, investigators would often search system files, logs, and process histories for traces of spyware. Data should be collected in such a way as to minimize, as much as possible, the amount of sensitive data and content that is accessed, such as your personal photos, contacts, or communications. If traces are found, investigators would typically contextualize these findings by connecting them to circumstances and life events surrounding the dates of the traces, including potential travel, sensitive work or conversations, or suspicious messages or device activity. Please note, however, that a lot of sophisticated spyware attacks may not be associated with anything suspicious that you can observe; the lack of obvious signs of an attack does not mean you are safe.
In addition, investigators may also try to test their own findings by submitting their work to peer organizations for an independent analysis. This practice helps solidify and confirm the validity of an investigation’s findings or identify areas where further research may be needed.
A good investigator may not always be able to find evidence to identify a spyware infection, nor can they always find a solution for mitigating the threat, but they are always conscious of their own limitations. In some cases, they may be able to suggest other methodologies or techniques for identifying and preventing spyware, but they rarely issue a blanket statement or guarantee that you are fully safe. That is for good reason; spyware evolves quickly, and it is designed to hide its traces.