India and 91 other countries that their iPhone may have come under attack from “mercenary spyware”, including Pegasus, a malware developed by the Israeli company NSO Group. Cyber Attack on Apple Phones explained for UPSC Some users in India received threat notification emails around 12.30 am IST on April 11. It is unclear how many people received the email, which said in the subject line “ALERT: Apple detected a targeted mercenary spyware attack against your iPhone”. WHO ARE THE ATTACKERS? Apple has not said who the attackers may be. It has only said that attacks “such as those using Pegasus” are “exceptionally rare and vastly more sophisticated than regular cybercriminal activity or consumer malware”. These attacks, which are “ongoing and global”, are “individually deployed against a very small number of people”, the threat notification said. Apple had sent a similar notification to some users in October 2023. On that occasion, Apple had said that “state-sponsored attackers” were “remotely trying to compromise” their iPhones. Following pressure from the government, Apple had subsequently clarified that it “does not attribute the threat notifications to any specific state-sponsored attacker”. WHEN WAS THE FIRST TIME THESE NOTIFICATIONS WERE SENT? Apple has been sending out these threat notifications since late 2021. These are automated messages that are sent out to alert and help iPhone users whenever Apple’s systems detect activity that matches certain specific patterns. HOW IS THE NOTIFICATION SENT? The “Threat Notification” is sent by email and iMessage to the email addresses and phone numbers that are linked to the affected user’s Apple ID. As part of the standard text of the message, Apple says it is unable to provide information about what causes them to issue the threat notifications, as that may help the attackers “adapt their behaviour to evade detection in the future”.

WHAT SHOULD ONE DO?

  • The notifications by Apple are accompanied by advice on some extra steps that users can take to protect their devices and safeguard their privacy.
  • Some of the general security tips that Apple recommends are updating to the latest software versions, setting a passcode, enabling two-factor authentication, and using a strong password for the Apple ID.
  • It also recommends that users should download apps only from the App Store, use a different password for each online account, and avoid clicking on links or attachments from unknown sources.
  • Apple also suggests that users activate the Lockdown Mode, which is a feature introduced in its latest software updates to specifically protect against rare and sophisticated cyber attacks such as these.