Pegasus spyware was allegedly used by governments to spy upon prominent journalists, politicians and activists.- A Google blog has revealed how the sophisticated software was used to attack
iPhone users. - The software used a vulnerability in iMessages to hack into iPhones without the user’s knowledge.
Now, a Google $4 from the Project Zero team called the attacks technically sophisticated exploits and assessed the software to have capabilities rivalling spywares previously thought to be accessible to only a handful of nations.
The company has also faced multiple lawsuits including one in India where the Supreme Court (SC) set up a $4 headed by former SC judge RV Raveendran to probe whether the software was used by the government to spy on journalists and other dissidents.
Apart from India, Apple has also sued the Israeli firm after having patched its security exploit. The company was also banned in the United States after the details of the spyware were revealed. Let’s take a look at how this advanced snooping technology discretely worked on iPhones.
According to the Project Zero blog, a sample of the ForcedEntry exploit was worked upon by the team and Apple’s Security Engineering and Architecture (SEAR) group. Pegasus attacks on iPhones were possible due to the ForcedEntry exploit.
Here, the NSO hackers took advantage of how iMessage handled GIFs to insert a PDF file into an iPhone in the disguise of a GIF. Then, a vulnerability in the compression tool that is used to process texts in images, was exploited by the software.
ForcedEntry built a virtual computer in the iPhone to communicate with the command-and-control centre that would send instructions. The presence of a virtual computer made it harder to detect the attacks.
Pegasus could do it all without needing input from the user. They just needed the phone number or Apple ID to send the malicious file and then hack into the iPhone. As soon as the message was received by the iPhone, the hack became active without the user knowing of its presence on their device.
Although Apple has patched the vulnerability and informed its users who were $4 using the Pegasus software, there would still be companies developing spywares to hack into iOS and Android devices. With most of our devices being vulnerable, here’s $4.
SEE ALSO:
$4
$4