/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

[Thread] Amnesty International and Citizen Lab found zero-click iMessage exploits being deployed against iPhones, even with iOS 14.6, to install malware

THREAD with a couple of interesting bits from @AmnestyTech's new report on what they learned from looking for NSO Group's spyware on phones https://www.amnesty.org/...

@billmarczak Bill Marczak

Context & Ripple Effects

The finding extends Citizen Lab's record of an iMessage zero-click chain used against Al Jazeera reporters on iOS 13.5.1: attackers were again reaching iPhones without requiring a target to tap a link or open a message.

Later reporting identified ForcedEntry as an iMessage route around iOS 14's BlastDoor protections, and Apple subsequently issued updates for flaws that bypassed those protections. The episode matters because it shows the defensive layer was being tested by a persistent commercial spyware operator.

First-order effects

  • iPhone users on iOS 14.6, including targets examined by Amnesty International and Citizen Lab, faced malware installation through iMessage without an interaction step.
  • Apple's iMessage security posture was directly challenged: the reported exploit reached devices despite the protections associated with iOS 14.

Second-order effects

  • Apple's patch cycle had to address the underlying attack paths rather than treat BlastDoor as a sufficient barrier; the later iOS 14.8 fixes addressed flaws that defeated it.
  • NSO Group's ability to deploy zero-click chains raises the value of forensic investigations by Citizen Lab and Amnesty International for identifying affected targets and exploit evidence.

Third-order effects

  • The later discovery of additional NSO zero-click hacks on iOS 15 and early iOS 16 suggests a recurring offense-and-patching cycle in which major iOS releases do not end the threat category.
  • If that pattern persists, iMessage security will be judged less by the presence of a single protective subsystem than by how quickly new exploit chains can be found and remediated.

The trend: Commercial spyware operations are repeatedly targeting messaging surfaces with zero-click exploit chains, forcing mobile-platform defenses into a continuing discovery-and-patch cycle.

Discussion

  • @billmarczak Bill Marczak on x
    @AmnestyTech (1) @AmnestyTech saw an iOS 14.6 device hacked with a zero-click iMessage exploit to install Pegasus. We at @citizenlab also saw 14.6 device hacked with a zero-click iMessage exploit to install Pegasus. All this indicates that NSO Group can break into the latest iPho…
  • @ryanaraine Ryan Naraine on x
    Reacting to iOS zero-days: Apple said: “Security researchers agree iPhone is the safest, most secure consumer mobile device on the market.”
  • @juanandres_gs J. A. Guerrero-Saade on x
    Unbelievable work by @AmnestyTech, done in spite of @Apple's reticence to provide means to verify the integrity of iOS devices. What's it going to take for Apple to stop burying its head in the sand? https://twitter.com/...
  • @datadrivenmd Jorge A. Caballero on x
    ⚠️ This tells me we're just seeing the tip of the iceberg. NSO seems to have found some kind of authentication flaw in iCloud's content-sharing processes. There's something about the way that Apple shares content across accounts that's being exploited https://www.amnesty.org/... …
  • @evacide Eva on x
    Tools like Pegasus are a win/win for authoritarians. For a while, they get to spy covertly on their enemies. And if they get caught, it's just one big advertisement for how omniscient and omnipotent they are.
  • @datadrivenmd Jorge A. Caballero on x
    Devs out there will appreciate how clever this is: “Again, after a successful exploitation, crash reporting was disabled by writing a com[.]apple[.]CrashReporter[.]plist file to the device.” https://www.amnesty.org/...
  • @matthew_d_green Matthew Green on x
    Regardless of what you name it, what kind of idiots give such a recognizable name to a process that might be logged by iPhone telemetry?
  • @ayleighk Kayleigh E. Long on x
    “All this indicates that NSO Group can break into the latest iPhones.” https://twitter.com/...
  • @byron_wan Byron Wan on x
    In this report, Amnesty International shares its methodology and publishes an open-source mobile forensics tool and detailed technical indicators, in order to assist information security researchers and civil society with detecting and responding to 1/n https://www.amnesty.org/..…
  • @ihackbanme Zuk on x
    @ShaneHuntley Even if we stop them, what stops governments developing their own tools abusing it in a similar way? So it's not really up to governments, it's up to Google and Apple to change the model. Identifying NSO is actually easy. (HINT: open up the sandbox, at least on mana…
  • @emilybell Emily Bell on x
    Thread - your iPhone is not secure... https://twitter.com/...
  • @i0n1c Stefan Esser on x
    With PEGASUS in the news again. Never forget that behind closed doors people will tell you that when PEGASUS was found the first time in the wild Apple forbid researchers to put the samples in the public and they complied because they were scared for their app(s) in the @AppStore
  • @patrickwardle Patrick Wardle on x
    Reminder that your iPhone can be remotely hacked ...& attackers can leverage your device's security/privacy to their benefit. 😥 Examples: 🎯 Invisibly deliver exploits (e.g. protected by iMsg's E2E encryption) 🙈 Remain undetected on device (as iOS prevents introspection) https://t…
  • @matthew_d_green Matthew Green on x
    The thing that makes identifying NSO hard is that iMessage is encrypted, and Apple doesn't want to upload every suspicious payload for privacy reasons (but also I think because they don't even have the infrastructure to do so.) https://twitter.com/...
  • @datadrivenmd Jorge A. Caballero on x
    🔥 Cyber/InfoSec/NatSec folks: This. Whole. Thread. 👀⤵️ https://twitter.com/...
  • @billmarczak Bill Marczak on x
    (2): @AmnestyTech also found that after @citizenlab's Dec 2020 report mentioning the zero-click hacking of Al Jazeera, NSO Group switched to Amazon's CloudFront to deliver exploits (lololol). @AmnestyTech reported this to Amazon, who took action to try and block the activity. htt…
  • @ndtv @ndtv on x
    Government of India's response to inquiries on the ‘#Pegasus Project’ media report. https://twitter.com/...
  • @evawolfangel Eva Wolfangel on x
    #NSO Group can break into the latest iPhones. 😳 (thread with more interesting facts from @citizenlab) https://twitter.com/...
  • @matthew_d_green Matthew Green on x
    Time to reboot our iPhones I guess.
  • @evacide Eva on x
    India insists that any spying they may or may not have done using Pegasus was nice and legal. https://twitter.com/...