HomeSecurityiPhone: Zero-click exploit used in NSO spyware attacks

iPhone: Zero-click exploit used in NSO spyware attacks

A new zero-click exploit discovered by Citizen Lab researchers in iMessage is being used to install NSO spyware on iPhones belonging to Catalan politicians, journalists, and activists.

See also: iPhone 14: How much could the new series cost?

zero-click exploit

The previously unknown zero-click exploit on iOSis called HOMAGE and affects some versions prior to iOS 13.2.

It was discovered to have been used in a malicious campaign that targeted at least 65 people with NSO's Pegasus spyware between 2017 and 2020, along with the Kismet iMessage exploit and a WhatsApp flaw .

Among the victims of these attacks are Catalan members of the European Parliament (EP), all Catalan presidents since 2010, as well as Catalan legislators, lawyers, journalists and members of civil society organizations and their families.

“We are not aware of any zero-day, zero-click exploits deployed for Catalan targets after iOS 13.1.3 and before iOS 13.5.1,” Citizen Lab said.

The company reported and provided Apple with the forensic evidence needed to investigate the exploit and says there is no evidence that Apple customers using the latest versions of iOS are exposed to HOMAGE attacks.

See also: Mirai malware now delivered using Spring4Shell exploits

«At this time, Citizen Lab does not definitively attribute these hacking operations to a specific government, however a number of circumstantial evidence suggests a strong connection to one or more entities within the Spanish government.».

iPhone

According to Reuters, NSO spyware was also used in attacks targeting senior European Commission officials last year, including the European Commissioner for Justice.

As stated by Citizen Lab director Ron Deibert, multiple suspected Pegasus spyware infections have also been observed on official UK networks.

A suspected infection on a device belonging to an official in the Prime Minister's Office was linked to Pegasus operators linked to the UAE, while attacks involving the UK Foreign and Commonwealth Office were linked to the UAE, India, Cyprus and Jordan.

The European Parliament is setting up a committee of inquiry, which will hold its first meeting on April 19, to investigate breaches of EU law stemming from the use of NSO Pegasus and related spyware.

See also: Log4Shell exploits used to DDoS botnets and install cryptominers

For those unfamiliar with it, Pegasus is a spyware tool developed by Israeli surveillance company NSO Group and marketed as licensed surveillance software to governments around the world for “crime and terrorism investigation.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS