Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets
Apple Expands On-Device Lock Screen Alerts for Mercenary (TL-2026-2016), also tracked as Mercenary Spyware Threat Notifications, is a high-severity tracked intrusion set, first published 2026-08-14 and last reviewed 2026-08-20. It is attributed to Commercial mercenary spyware vendors with medium confidence, affects Apple iOS / iPadOS / macOS / watchOS / visionOS (CVE-2025-43200, references 2 CVEs (CVE-2021-30860, CVE-2025-43200), maps to 27 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-2016
- Threat ID
- TL-2026-2016
- Also known as
- Mercenary Spyware Threat Notifications, Apple Threat Notification Program
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-08-14
- Last reviewed
- 2026-08-20
- Attribution
- Commercial mercenary spyware vendors
- Attribution confidence
- MEDIUM
- Motivation
- ESPIONAGE
- Target sectors
- government administration, news - media, civil society, legal, ngo
- Target regions
- Global, Europe
- Detection rules
- 9
- Indicators of compromise
- 28
- Updates
- 2026-08-20 · revalidated 1× · latest source
Malware and tooling in Apple Expands On-Device Lock Screen Alerts for Mercenary
Malware and tooling: Chrysaor, Graphite, Predator, Lockdown Mode
Apple has expanded its mercenary spyware threat-notification program to display high-confidence targeting alerts directly on iPhone Lock Screens and in Settings, supplementing the existing email, iMessage, and Apple Account page notifications. Apple sent the first Lock Screen-based alerts on August 13, 2026 to targets in 110 countries, part of a program that has now notified individuals in over 150 countries since it launched in 2021.
How Apple Expands On-Device Lock Screen Alerts for Mercenary works
Apple has for the first time delivered its mercenary spyware "threat notification" directly as a push alert on the iPhone Lock Screen and inside Settings (under "Apple Threat Notification"), rather than relying solely on email, iMessage, and an account.apple.com banner as it has since the program's 2021 launch. The August 13, 2026 round reached users in 110 countries; Apple says it has now notified individuals in over 150 countries in total since the program began. The alert text reads: "Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device." Apple describes these as high-confidence alerts based on its own internal threat-intelligence investigations and explicitly cites NSO Group's Pegasus as a historical example of the mercenary spyware class the program targets, while stating it does not attribute individual alerts to a specific spyware product or operator.
The program traces back to Apple's response to NSO Group's FORCEDENTRY exploit (CVE-2021-30860), a zero-click, zero-day iMessage exploit that abused an integer-overflow flaw in CoreGraphics/ImageIO JBIG2-encoded PDF processing to deliver Pegasus spyware without any user interaction, and which Citizen Lab captured on a Saudi activist's device in March 2021. Apple patched CVE-2021-30860 on September 13, 2021, and filed suit against NSO Group on November 23, 2021 seeking to permanently bar NSO from Apple's platform and devices; the threat-notification program dates to this same period. Apple's BlastDoor iMessage sandboxing mitigation (introduced in iOS 14) is understood to have driven NSO Group to develop FORCEDENTRY as a bypass after an earlier exploit (KISMET) was neutralized.
The underlying threat class is the commercial ("mercenary") spyware industry — vendors that develop and sell zero-click and one-click mobile intrusion capability to government customers, typically to surveil journalists, human-rights defenders, lawyers, political figures, diplomats, and civil-society organizers. Recent, publicly documented cases in this class include: (1) NSO Group's Pegasus used via the "PWNYOURHOME" zero-click exploit (crafted HomeKit NSKeyedArchive content processed by MessagesBlastDoorService) against former MEP Stelios Kouloglou on October 21, 2022 and again on March 6-7, 2023, while he served on the European Parliament's PEGA Committee investigating Pegasus abuse itself (Citizen Lab Report 194, published July 3, 2026); (2) Poland's ABW and SKW intelligence services' documented misuse of Pegasus against opposition figures, journalists, and prosecutors under the prior government (nearly 600 people targeted), which led to the December 2024 forced testimony of former ABW chief Piotr Pogonowski and the February 25, 2026 formal criminal charges against Pogonowski and former SKW chief Maciej Materka; (3) Paragon Solutions' Graphite spyware, delivered via a zero-click iMessage exploit (CVE-2025-43200, a logic flaw in processing a crafted photo/video shared via an iCloud Link, fixed across iOS/iPadOS/macOS/watchOS/visionOS on January-February 2025 patches), used against Italian journalists Francesco Cancellato and Ciro Pellegrino and activists Luca Casarini and Giuseppe Caccia in December 2024-February 2025, forensically confirmed by Citizen Lab on June 12, 2025 following an Apple threat notification on April 29, 2025; and (4) Intellexa Consortium's Predator spyware, whose developers and enablers (including Felix Bitzios, Andrea Gambazzi, Merom Harpaz, Panagiota Karaoli, Artemis Artemiou, and the BVI shell company Aliada Group Inc.) have been sanctioned multiple times by the US Treasury's Office of Foreign Assets Control for posing what Treasury called a significant threat to US national security.
Apple's stated primary mitigation for at-risk individuals is Lockdown Mode, an opt-in hardened configuration that aggressively restricts message attachments, complex web technologies (like just-in-time JavaScript compilation), unsolicited FaceTime calls, configuration profile installation, and wired connections when locked. Apple states it is not aware of any device with Lockdown Mode enabled having been successfully compromised by known mercenary spyware. Apple directs targeted individuals to Access Now's 24/7 Digital Security Helpline for free incident-response support and warns that phishing actors impersonate the legitimate threat-notification emails (sent from threat-notifications@email.apple.com) to harvest Apple ID credentials, so recipients should verify any alert by logging into account.apple.com directly rather than following links in the notification itself.
MITRE ATT&CK techniques used in TL-2026-2016
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1480 Execution Guardrails; T1630 Indicator Removal on Host
Credential Access
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Command and Control
T1090 Proxy; T1481 Web Service; T1573 Encrypted Channel
Collection
T1113 Screen Capture; T1115 Clipboard Data; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1636 Protected User Data
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1456 Drive-By Compromise; T1566.001 Spearphishing Attachment
Execution
T1203 Exploitation for Client Execution
Privilege Escalation
T1404 Exploitation for Privilege Escalation
Persistence
T1547 Boot or Logon Autostart Execution
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1587.001 Develop Capabilities: Exploits; T1588.006 Obtain Capabilities: Vulnerabilities
Exfiltration
Affected products and versions in Apple Expands On-Device Lock Screen Alerts for Mercenary
- Apple — iOS / iPadOS / macOS / watchOS / visionOS (CVE-2025-43200, Graphite zero-click)
Vulnerable versions: versions prior to iOS 18.3.1/iPadOS 18.3.1; iOS 16.7.11/iPadOS 16.7.11 and earlier 16.x; iOS 15.8.4/iPadOS 15.8.4 and earlier 15.x; iPadOS 17.7.5 and earlier 17.x; watchOS 11.3.1 and earlier; visionOS 2.3.1 and earlier; macOS Sequoia prior to 15.3.1; macOS Sonoma prior to 14.7.4; macOS Ventura prior to 13.7.4
Fixed in: iOS 18.3.1 / iPadOS 18.3.1; iOS 16.7.11 / iPadOS 16.7.11; iOS 15.8.4 / iPadOS 15.8.4; iPadOS 17.7.5; watchOS 11.3.1; visionOS 2.3.1; macOS Sequoia 15.3.1; macOS Sonoma 14.7.4; macOS Ventura 13.7.4 - Apple — iOS / macOS / watchOS (CVE-2021-30860, FORCEDENTRY)
Vulnerable versions: iOS/iPadOS versions prior to 14.8; macOS Big Sur prior to 11.6; watchOS prior to 7.6.2
Fixed in: iOS 14.8 / iPadOS 14.8; macOS Big Sur 11.6; watchOS 7.6.2
Remediation for Apple Expands On-Device Lock Screen Alerts for Mercenary
Patches
- CVE-2021-30860 (FORCEDENTRY): iOS 14.8, iPadOS 14.8, watchOS 7.6.2, macOS Big Sur 11.6 — released September 13, 2021
- CVE-2025-43200 (Graphite iMessage/iCloud-Link zero-click): iOS 18.3.1/iPadOS 18.3.1, iOS 16.7.11/iPadOS 16.7.11, iOS 15.8.4/iPadOS 15.8.4, iPadOS 17.7.5, watchOS 11.3.1, visionOS 2.3.1, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4
Immediate actions
- If you receive an Apple threat notification, update all Apple devices to the latest iOS/iPadOS/macOS/watchOS/visionOS version immediately
- Enable Lockdown Mode on the targeted device (Settings > Privacy & Security > Lockdown Mode)
- Verify the notification's authenticity by logging into account.apple.com directly rather than clicking any link in the email or push alert
- Contact Access Now's 24/7 Digital Security Helpline for free forensic and incident-response support
- Do not enter your Apple ID password or two-factor codes in response to any unsolicited notification
Workarounds
- Enable Lockdown Mode — Apple states it has not confirmed any successful mercenary-spyware compromise of a device with Lockdown Mode active
- Avoid opening unknown links/attachments and answering unrecognized FaceTime calls
- Decline unsolicited configuration profile installation prompts
Longer-term hardening
- Keep automatic software updates enabled
- Use strong, unique passwords and passkeys with hardware security-key-based two-factor authentication for the Apple ID
- Enable Stolen Device Protection
- Restrict app installation to the official App Store only
- High-risk individuals (journalists, activists, lawyers, officials, diplomats) should seek periodic independent mobile forensic screening (e.g., via Citizen Lab or Amnesty International's Security Lab)
CVEs associated with Apple Expands On-Device Lock Screen Alerts for Mercenary
Weaknesses (CWE) in Apple Expands On-Device Lock Screen Alerts for Mercenary
CWE-190, CWE-122, CWE-787
Timeline of Apple Expands On-Device Lock Screen Alerts for Mercenary
Showing the 20 most recent tracked events.
- Citizen Lab reveals Poland's PiS government used Pegasus against opposition senator Krzysztof Brejza dozens of times ahead of the 2019 parliamentary elections.
- Apple announces Lockdown Mode at WWDC 2022, an extreme optional security setting designed to protect against mercenary spyware zero-click exploits.
- Former MEP Stelios Kouloglou's iPhone is infected with NSO Group's Pegasus via the PWNYOURHOME zero-click exploit while he serves on the European Parliament's PEGA Committee investigating Pegasus abuse.
- Kouloglou's device is infected with Pegasus a second time via PWNYOURHOME.
- Citizen Lab and Google Project Zero disclose BLASTPASS, an NSO zero-click iMessage exploit using PassKit/WebP heap overflow (Huffman table corruption).
- Poland's Justice Minister Adam Bodnar reveals Pegasus was used against 578 individuals from 2017-2022 across three government agencies, calling the scale 'shocking and depressing'.
- US Treasury OFAC sanctions individuals and entities tied to the Intellexa Consortium, developer of Predator spyware, citing a significant threat to US national security.
- Former Polish ABW chief Piotr Pogonowski is forcibly brought to testify before parliament's Pegasus investigative committee after refusing three summonses.
- Forensic analysis later finds the phones of journalist Francesco Cancellato and activists Giuseppe Caccia and Luca Casarini show traces of spyware infection in the early hours of this date, per Rome and Naples prosecutors.
- Google Project Zero publishes 'Blasting Past WebP' technical analysis of BLASTPASS, confirming continued NSO zero-click exploit development through 2024 via in-the-wild crash logs.
- Apple sends a threat notification to a targeted Italian/European journalist later confirmed to have been infected with Paragon's Graphite spyware.
- Citizen Lab publishes forensic confirmation that Paragon's Graphite spyware, delivered via a zero-click iMessage exploit (CVE-2025-43200), targeted Italian journalists and activists.
- Access Now reports the Digital Security Helpline investigates approximately 1,000 suspected government spyware cases annually, with ~500 leading to active investigations.
- Poland's National Prosecutors' Office formally charges former ABW chief Piotr Pogonowski and former SKW chief Maciej Materka over Pegasus misuse.
- Citizen Lab publishes Report 194 detailing the Pegasus hacking of former MEP Stelios Kouloglou while he investigated Pegasus abuse.
- Amnesty International publishes 'Inside Pegasus' comprehensive report documenting NSO infection process, vector evolution, and anonymized server infrastructure.
- Apple sends its latest round of mercenary-spyware threat notifications, for the first time delivered as iPhone Lock Screen push alerts, to targets in 110 countries.
- Coverage of Apple's expanded Lock Screen threat-notification capability and its 150+ country cumulative notification total is published.
- TechCrunch reports Access Now Digital Security Helpline experienced a 30-40% increase in contacts; a Ukrainian Armed Forces soldier confirms receiving the notification while serving on the front lines.
- Citizen Lab publishes analysis of the notification wave, with senior researcher John Scott-Railton describing the scale and geographic diversity of public reports as 'pretty unprecedented.'
Update history for TL-2026-2016
- 2026-08-20 — Unprecedented Wave of Mercenary Spyware Attacks Across 110 Countries Detected by Apple Threat Notifications — August 2026: What changed Severity MEDIUM → HIGH: the August 13, 2026 wave is now confirmed as the largest single batch of Apple threat notifications ever sent, described by Citizen Lab's John Scott-Railton as 'pretty unprecedented' in scale and geograp
Sources cited for Apple Expands On-Device Lock Screen Alerts for Mercenary
- Apple now uses iPhone alerts for targets of mercenary spyware
- If Apple sends you a push notification alerting you to a spyware attack, take it seriously
- Apple sends new 'Threat Notification' alerts over mercenary spyware attacks
- Apple Sends Mercenary Spyware Attack Alerts to iPhone Users in 110 Countries
- About Apple threat notifications and protecting against mercenary spyware
- FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild
- Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus (Report 194)
- Graphite Caught: First Forensic Confirmation of Paragon's iOS Mercenary Spyware Finds Journalists Targeted
- Poland charges ex-intel chiefs for using Israel's Pegasus spyware
- Poland arrests former spy chief in Pegasus spyware probe
- Italy: New case of journalist targeted with Graphite spyware confirms widespread use of unlawful surveillance
- U.S. Treasury Sanctions Intellexa Spyware Amid Shifting Threat Landscape
- CVE-2025-43200: Apple iPadOS Logic Issue Vulnerability
Threats related to Apple Expands On-Device Lock Screen Alerts for Mercenary
- Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group)
- NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor
- UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case (Shehabi v Kingdom of Bahrain)
Detection coverage for TL-2026-2016
As of 2026-08-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2016 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.