Investigation details ForcedEntry, an iMessage “zero-click” attack used by NSO Group that circumvents iOS 14's BlastDoor, likely used by the Bahraini government
Earlier coverage documented an NSO zero-click iMessage chain used against roughly 36 Al Jazeera reporters on iOS 13.5.1. ForcedEntry shows that the threat persisted after Apple introduced BlastDoor, with a different set of targets in Bahrain.
Nine Bahraini activists had their iPhones compromised, giving the suspected operator access through an attack that required no interaction from the targets.
Apple's BlastDoor protection in iOS 14 was shown to be insufficient against ForcedEntry, leaving a specific iMessage attack path available to NSO Group.
Second-order effects
Apple gains a concrete exploit chain to remediate; later coverage of fixes for newer NSO zero-click attacks indicates an ongoing patch cycle rather than a one-time BlastDoor solution.
Because ForcedEntry was also used by QuaDream, a mitigation aimed at the exploit affects more than NSO Group's customer base and raises the value of independently finding shared spyware techniques.
Third-order effects
Repeated zero-click compromises across successive iOS versions point to a durable contest between Apple’s platform defenses and commercial spyware vendors’ exploit development, with researchers’ detections serving as a key corrective mechanism.
If exploit reuse across vendors continues, mobile-security exposure will be shaped less by a single supplier than by the circulation of high-value attack chains among surveillance providers and their government clients.
The trend: Commercial spyware vendors are sustaining zero-click iPhone access through evolving and sometimes shared exploit chains despite successive iOS security defenses.
Details an exploit they call FORCEDENTRY. Works against iOS 14.x and bypasses the MessagesBlastDoorService which Apple added in iOS 14 to make iMessage exploitation more difficult. FORCEDENTRY similar to Megalodon exploitation activity observed by Amnesty Tech earlier this year h…
When asked about the latest iMessage exploit, Apple told @zackwhittaker that “it has strengthened its defenses in iOS 15, which is slated for release in the next month or so.” In other words: there's no immediate patch for this. https://techcrunch.com/...
New: Citizen Lab has discovered a new NSO “zero-click” attack that circumvents Apple's ‘BlastDoor’ security defenses in iOS 14. At least one activist's iPhone was hacked with Pegasus spyware. Apple said it's aware, but no word yet on a security fix. https://techcrunch.com/...
Apple says it “unequivocally condemns” cyberattacks against journalists and human rights defenders, while also telling those same victims — who've just had their iPhones hacked — to basically just wait patiently for a month or two until iOS 15 comes out. https://twitter.com/...
Apple said BlastDoor was “not the end of its efforts to secure iMessage” and pointed to iOS 15, which is slated for released in the next month or so. But Apple wouldn't say if it had fixed the flaw in current versions of iOS 14, or say when — if at all. https://techcrunch.com/...
Two of the activists now reside in London, and at least one was in London when they were hacked. We have only ever seen the Bahrain government spying in Bahrain and Qatar. Thus, the activist in London may have been hacked by a Pegasus operator associated w a different government.
The new exploit, called ForcedEntry, targeted a Bahraini human rights activist living in Bahrain, and likely hacked by the Bahraini government using an iOS 14 exploit to deploy Pegasus, said Citizen Lab. Eight other Bahrainis were also targeted, including @moosaakrawi in London. …
The hacked activists included three members of Waad (a secular Bahraini political society), three members of the Bahrain Center for Human Rights, two exiled Bahraini dissidents, and one member of Al Wefaq (a Shiite Bahraini political society).
At least four of the activists were hacked by LULU, a Pegasus operator that we attribute with high confidence to the government of Bahrain, a well-known abuser of spyware. One of the activists was hacked hours after they revealed that their phone was hacked with Pegasus in 2019.
We identified nine Bahraini activists whose iPhones were successfully hacked with NSO Group's Pegasus spyware from June 2020 - February 2021. Some of the activists were hacked using two zero-click iMessage exploits: the 2020 KISMET exploit and a 2021 exploit we call FORCEDENTRY.
The eight other Bahrainis were targeted with a different, older kind of NSO zero-click that predates ForcedEntry, called Kismet, which doesn't work on iOS 14 (because of BlastDoor). Five of the activists were on the #PegasusProject list of phone numbers. https://techcrunch.com/..…
We shared a list of the targeted phone numbers we identified with Forbidden Stories. They confirmed that numbers associated with five of the hacked devices were contained on the Pegasus Project's list of potential targets of NSO Group's customers.