Hello,

We noticed you're browsing in private or incognito mode.

To continue reading this article, please exit incognito mode or log in.

Not an Insider? Subscribe now for unlimited access to online articles.

Connectivity

Israeli Hacking Firm Said to Be Behind Groundbreaking iOS Malware

NSO Group, a firm that trades in spyware, stands accused of peddling an unprecedented attack on iPhones.

Apple has rushed out a patch for its mobile operating system, iOS, after malware—reportedly developed by an Israeli firm that sells spying software to governments—was able to remotely surveil an up-to-date iPhone 6.

The attack attempts to encourage users to open a URL via text message. When that link is followed, the attack uses three individual zero-day flaws to leverage a weakness in Safari’s browser engine, which enables access to the operating system’s kernel and installation of malware to effectively jailbreak the iPhone. From that point on, the malware can be used to spy on virtually every aspect of the phone’s use, from phone calls and text messages to calendar data and video feeds.

This appears to be the first known example of hackers having the ability to remotely jailbreak an iPhone 6, and Motherboard claims that it’s the first iPhone attack of this kind. The vulnerability was identified by researchers at the University of Toronto's Citizen Lab after Ahmed Mansoor, a human rights activist and United Arab Emirates dissident, was targeted using the attack.

The Citizen Lab team claims that the malware was developed by the Israeli firm NSO Group, which creates spy software for governments. It’s no secret that NSO makes software capable of surveilling smartphones: in 2014, the Wall Street Journal reported that an NSO slide claimed to provide technology that “allows remote and stealth monitoring and full data extraction from remote devices via untraceable commands.” It’s currently unclear who exactly used the malware to target Mansoor.

Reuters suggests that such a piece of software, able to spy on an up-to-date iPhone 6, could retail for as much as $1 million.

Citizen Lab researchers informed Apple of the vulnerability over a week ago, and the iPhone maker has released a patch for devices running iOS 9. Apple claims devices running up-to-date beta versions of iOS 10 are unaffected.

Apple recently announced a bug-bounty program, which will see it pay out up to $200,000 for (invited) hackers who manage to identify the kinds of flaws leveraged by this malware. Perhaps it should’ve started sooner.

(Read more: Citizen Lab,  Reuters, Motherboard, "The Growth Industry Helping Governments Hack Terrorists, Criminals—and Political Opponents")

Cut off? Read unlimited articles today.

Become an Insider
Already an Insider? Log in.

Uh oh–you've read all of your free articles for this month.

Insider Premium
$179.95/yr US PRICE

More from Connectivity

What it means to be constantly connected with each other and vast sources of information.

Want more award-winning journalism? Subscribe and become an Insider.
  • Insider Plus {! insider.prices.plus !}* Best Value

    {! insider.display.menuOptionsLabel !}

    Everything included in Insider Basic, plus the digital magazine, extensive archive, ad-free web experience, and discounts to partner offerings and MIT Technology Review events.

    See details+

    What's Included

    Unlimited 24/7 access to MIT Technology Review’s website

    The Download: our daily newsletter of what's important in technology and innovation

    Bimonthly print magazine (6 issues per year)

    Bimonthly digital/PDF edition

    Access to the magazine PDF archive—thousands of articles going back to 1899 at your fingertips

    Special interest publications

    Discount to MIT Technology Review events

    Special discounts to select partner offerings

    Ad-free web experience

  • Insider Basic {! insider.prices.basic !}*

    {! insider.display.menuOptionsLabel !}

    Six issues of our award winning print magazine, unlimited online access plus The Download with the top tech stories delivered daily to your inbox.

    See details+

    What's Included

    Unlimited 24/7 access to MIT Technology Review’s website

    The Download: our daily newsletter of what's important in technology and innovation

    Bimonthly print magazine (6 issues per year)

  • Insider Online Only {! insider.prices.online !}*

    {! insider.display.menuOptionsLabel !}

    Unlimited online access including articles and video, plus The Download with the top tech stories delivered daily to your inbox.

    See details+

    What's Included

    Unlimited 24/7 access to MIT Technology Review’s website

    The Download: our daily newsletter of what's important in technology and innovation

/
You've read all of your free articles this month. This is your last free article this month. You've read of free articles this month. or  for unlimited online access.