iVerify's iOS app detected a Pegasus infection in 11 new cases in December 2024, and about half of them did not receive Threat Notifications from Apple
This number adds to seven other devices the company found infected with Pegasus throughout last year — iverify.io/blog/how-dem... @iverify : 🚨 Democratizing Threat Hunting is Changing Mobile Security! — Our latest investigation led to 18,000+ device scans, uncovering 11 new Pegasus spyware infections—many targeting business executives. 📱💼 — Take control of your security—scan your device today! 🔍 …
Context & Ripple Effects
iVerify had already reported seven Pegasus detections from its Mobile Threat Hunting tool after its May 2024 launch. The December findings raise its reported total to 18 and come from a much larger scan base, making the results more consequential for organizations whose executives use iPhones.
The cases also sit within a longer record of iPhone-focused commercial spyware activity, including Citizen Lab's reporting on new zero-click iPhone exploits. What is newly salient here is the reported gap between independent device detections and Apple's Threat Notifications.
First-order effects
- iVerify's scans identified 11 additional Pegasus infections in December, giving affected users and their organizations evidence to investigate potential compromise and secure the devices.
- About half of the detected devices reportedly received no Apple Threat Notification, limiting the notification system's reach in this set of cases.
Second-order effects
- Mobile-security teams, especially those protecting executives, have a concrete reason to use device scanning alongside platform notifications rather than treating either as a complete detection layer.
- The results strengthen the case for mobile threat-hunting vendors to sell continuous or targeted scanning to organizations with high-risk users, while raising the bar for Apple to explain notification coverage.
Third-order effects
- If repeated across broader samples, the pattern would shift iPhone security toward layered detection: platform protections supplemented by independent endpoint visibility and incident-response workflows.
- It also suggests that commercial spyware defense will be assessed less by whether a platform blocks known exploits and more by whether organizations can discover targeted compromises that evade user-facing alerts.
The trend: Targeted mobile-spyware defense is moving from reliance on platform notifications toward layered, enterprise-run threat hunting for high-risk users.