[Thread] Amnesty International and Citizen Lab found zero-click iMessage exploits being deployed against iPhones, even with iOS 14.6, to install malware
THREAD with a couple of interesting bits from @AmnestyTech's new report on what they learned from looking for NSO Group's spyware on phones https://www.amnesty.org/...
Later reporting identified ForcedEntry as an iMessage route around iOS 14's BlastDoor protections, and Apple subsequently issued updates for flaws that bypassed those protections. The episode matters because it shows the defensive layer was being tested by a persistent commercial spyware operator.
First-order effects
iPhone users on iOS 14.6, including targets examined by Amnesty International and Citizen Lab, faced malware installation through iMessage without an interaction step.
Apple's iMessage security posture was directly challenged: the reported exploit reached devices despite the protections associated with iOS 14.
Second-order effects
Apple's patch cycle had to address the underlying attack paths rather than treat BlastDoor as a sufficient barrier; the later iOS 14.8 fixes addressed flaws that defeated it.
NSO Group's ability to deploy zero-click chains raises the value of forensic investigations by Citizen Lab and Amnesty International for identifying affected targets and exploit evidence.
If that pattern persists, iMessage security will be judged less by the presence of a single protective subsystem than by how quickly new exploit chains can be found and remediated.
The trend: Commercial spyware operations are repeatedly targeting messaging surfaces with zero-click exploit chains, forcing mobile-platform defenses into a continuing discovery-and-patch cycle.
@AmnestyTech (1) @AmnestyTech saw an iOS 14.6 device hacked with a zero-click iMessage exploit to install Pegasus. We at @citizenlab also saw 14.6 device hacked with a zero-click iMessage exploit to install Pegasus. All this indicates that NSO Group can break into the latest iPho…
Unbelievable work by @AmnestyTech, done in spite of @Apple's reticence to provide means to verify the integrity of iOS devices. What's it going to take for Apple to stop burying its head in the sand? https://twitter.com/...
⚠️ This tells me we're just seeing the tip of the iceberg. NSO seems to have found some kind of authentication flaw in iCloud's content-sharing processes. There's something about the way that Apple shares content across accounts that's being exploited https://www.amnesty.org/... …
Tools like Pegasus are a win/win for authoritarians. For a while, they get to spy covertly on their enemies. And if they get caught, it's just one big advertisement for how omniscient and omnipotent they are.
Devs out there will appreciate how clever this is: “Again, after a successful exploitation, crash reporting was disabled by writing a com[.]apple[.]CrashReporter[.]plist file to the device.” https://www.amnesty.org/...
In this report, Amnesty International shares its methodology and publishes an open-source mobile forensics tool and detailed technical indicators, in order to assist information security researchers and civil society with detecting and responding to 1/n https://www.amnesty.org/..…
@ShaneHuntley Even if we stop them, what stops governments developing their own tools abusing it in a similar way? So it's not really up to governments, it's up to Google and Apple to change the model. Identifying NSO is actually easy. (HINT: open up the sandbox, at least on mana…
With PEGASUS in the news again. Never forget that behind closed doors people will tell you that when PEGASUS was found the first time in the wild Apple forbid researchers to put the samples in the public and they complied because they were scared for their app(s) in the @AppStore
Reminder that your iPhone can be remotely hacked ...& attackers can leverage your device's security/privacy to their benefit. 😥 Examples: 🎯 Invisibly deliver exploits (e.g. protected by iMsg's E2E encryption) 🙈 Remain undetected on device (as iOS prevents introspection) https://t…
The thing that makes identifying NSO hard is that iMessage is encrypted, and Apple doesn't want to upload every suspicious payload for privacy reasons (but also I think because they don't even have the infrastructure to do so.) https://twitter.com/...
(2): @AmnestyTech also found that after @citizenlab's Dec 2020 report mentioning the zero-click hacking of Al Jazeera, NSO Group switched to Amazon's CloudFront to deliver exploits (lololol). @AmnestyTech reported this to Amazon, who took action to try and block the activity. htt…