Apple has issued a warning about highly sophisticated spyware attacks targeting a select group of its users. The company has a threat alert systemdesigned to warn and support people who may have been targeted because of their profession or public profile, such as journalists, activists, politicians and diplomats.

These attacks are much more sophisticated than typical cybercriminal activities. Spyware often state-sponsored and designed to target a few specific individuals.
Due to their complexity and often short lifespan, they are difficult to detect and prevent. Historically, these types of advanced, targeted attacks have been linked to government agencies or private companies that develop spyware on their behalf.
See also: Hackers exploit Open-Source AdaptixC2 in attacks
Notable examples of such software include Pegasus from NSO Group, as well as Predator, Graphite, and Triangulation. Although only a small number of people are affected, these attacks continue to this day and have a global reach.
Since 2021, Apple has sent alerts to users in over 150 countries, highlighting the widespread nature of this threat. Due to the extreme cost and complexity of these operations, Apple does not attribute the attacks to specific entities or geographic locations.

Spyware: How Apple warns users
When Apple's internal systems detect activity consistent with a spyware attack, they notify the targeted user via two methods:
- First method: A Threat Notification banner appears at the top of the page when the user logs in to the account.apple.com portal.
- Second method: An email and iMessage notification is sent to the contact points associated with the user's Apple account.
These official notifications will never ask a user to click on links , open files , install apps , or provide their Apple account password or verification code
To confirm the authenticity of an alert, users will need to log in directly to their Apple account. Apple urges anyone who receives a threat alert to take it very seriously and seek help from experts.
The company recommends contacting the Digital Safety Helpline, a service provided by the nonprofit organization Access Now, which offers emergency safety support.
See also: L7 Botnet compromised 5.76 million devices for mass attacks
Those who have received a relevant notification are urged to avoid making any changes to the device, such as resetting it or deleting applications, as this could hinder investigations by security experts.

Protection against spyware attacks
For additional protection, especially for those who have been notified or believe they are at high risk, Apple recommends enabling Lockdown Mode on their devices. This feature enhances security by restricting certain features that could be exploited by cybercriminals.
For all users, Apple reiterates the importance of adhering to general cybersecurity best practices:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
– Keep devices up to date with the latest software.
– Protect devices with a strong password.
– Use two-factor authentication for your Apple account.
– Install apps only from the App Store.
– Use strong, unique passwords for online accounts.
– Avoid clicking on links or attachments from unknown senders.
While the vast majority of users will not be the target of such sophisticated attacks, adhering to these security measures provides a strong defense against more common cyber threats.
See also: ZynorRAT targets Windows and Linux systems
Apple's latest warning emphasizes that spyware is not a theoretical threat, but an active tool of state espionage with a global reach. Early warning and collaboration with organizations like Access Now show that cybersecurity, especially for vulnerable groups, is essential.
