Pegasus: Google reveals how the sophisticated spyware hacked into iPhones without user’s knowledge
spywarewas allegedly used by governments to spy upon prominent journalists, politicians and activists.
- A Google blog has revealed how the sophisticated software was used to attack
- The software used a vulnerability in iMessages to hack into iPhones without the user’s knowledge.
AdvertisementThe Pegasus spyware, developed by Israel’s NSO group, made headlines for being used by governments and regimes across the world including India to spy on journalists, activists, opposition leaders, ministers, lawyers and others. The spyware is accused of hacking into the phones of at least 180 journalists around the world, of which 40 are notable Indian personalities.
Now, a Google blog from the Project Zero team called the attacks technically sophisticated exploits and assessed the software to have capabilities rivalling spywares previously thought to be accessible to only a handful of nations.
The company has also faced multiple lawsuits including one in India where the Supreme Court (SC) set up a three-member panel headed by former SC judge RV Raveendran to probe whether the software was used by the government to spy on journalists and other dissidents.
Apart from India, Apple has also sued the Israeli firm after having patched its security exploit. The company was also banned in the United States after the details of the spyware were revealed. Let’s take a look at how this advanced snooping technology discretely worked on iPhones.
How Pegasus hacked iPhones
According to the Project Zero blog, a sample of the ForcedEntry exploit was worked upon by the team and Apple’s Security Engineering and Architecture (SEAR) group. Pegasus attacks on iPhones were possible due to the ForcedEntry exploit.
Here, the NSO hackers took advantage of how iMessage handled GIFs to insert a PDF file into an iPhone in the disguise of a GIF. Then, a vulnerability in the compression tool that is used to process texts in images, was exploited by the software.
ForcedEntry built a virtual computer in the iPhone to communicate with the command-and-control centre that would send instructions. The presence of a virtual computer made it harder to detect the attacks.
Although Apple has patched the vulnerability and informed its users who were spied upon using the Pegasus software, there would still be companies developing spywares to hack into iOS and Android devices. With most of our devices being vulnerable, here’s how you can protect your data.
AdvertisementInstagram now lets you embed a miniature version of your profile to websites — Here’s how you can do it
Xiaomi's MIUI 13: Release date, expected features and supported devices
Popular on BI
- India's best relaxing holiday spots for peaceful retreats
- Inter-ministerial approval board can permit demarcation of non-processing area under IT sector SEZs
- Winter wellness: 10 Amla recipes to embrace this season
- ‘Confident’ Indians might splurge on big-ticket items in 2024
- Tata Power stock zooms ahead after brokerage on upgrade