Threat reportMalwareTL-2026-2034

Apple Issues Mercenary Spyware Threat Notifications to Users in 110 Countries

highACTIVE

Apple Issues Mercenary Spyware Threat Notifications to Users (TL-2026-2034) is a high-severity malware campaign, first published 2026-08-16. It has no confirmed attribution, affects Apple iPhone (iOS), maps to 14 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 11 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
11Indicators of compromise

Key facts for TL-2026-2034

Threat ID
TL-2026-2034
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
government administration, news - media, civil society, humanrights, diplomatic, ngo
Target regions
Global, North America, Europe, Middle East, Asia-Pacific, Africa, Latin America
Detection rules
9
Indicators of compromise
11

Malware and tooling in Apple Issues Mercenary Spyware Threat Notifications to Users

Malware and tooling: Chrysaor, Graphite, BLASTPASS, FORCEDENTRY

How Apple Issues Mercenary Spyware Threat Notifications to Users works

Apple sent high-confidence threat notifications on August 13, 2026 to targeted users across 110 countries warning of mercenary spyware attacks against their iPhones. Apple did not attribute the alerts to a specific spyware vendor or CVE, citing NSO Group's Pegasus only as the historical example of this attack class.

On August 13, 2026, Apple sent a new wave of "threat notifications" to users in 110 countries, warning that its internal threat-intelligence process had detected, with high confidence, a mercenary spyware attack targeting their iPhone. Apple has operated this alert program since November 2021 and has now notified users in over 150 countries in total across multiple annual waves, including a 100-country wave in May 2025 and an alert to more than a dozen Iranian recipients in July 2025 ahead of the Israel-Iran conflict escalation. Consistent with its standing policy, Apple did not name the spyware family, vendor, or nation-state customer behind the August 2026 wave and disclosed no CVE, stating publicly only that it does not attribute threat notifications to specific attackers or geographic regions in order to avoid helping mercenary spyware operators refine their tradecraft. Apple's own framing of the alert cites NSO Group's Pegasus as the representative historical example of "mercenary spyware" — commercial surveillance tooling sold to government customers and used to individually target journalists, human-rights defenders, political dissidents, opposition politicians, and diplomats because of who they are or what they do, rather than as part of mass exploitation.

Because this notification round carries no confirmed exploit, IOC, or vendor attribution, this record documents the attack class Apple explicitly invoked (mercenary/commercial spyware exemplified by Pegasus) using the three most recent, forensically confirmed, publicly documented exploit chains from that class delivered against iOS: NSO Group's FORCEDENTRY (CVE-2021-30860, 2021) and BLASTPASS (CVE-2023-41064/CVE-2023-41061, 2023), and Paragon Solutions' Graphite (CVE-2025-43200, 2025) — the most recent forensically confirmed case, used against Italian journalist Ciro Pellegrino and at least one other European journalist. All three are zero-click chains delivered over Apple's Messages/iMessage stack that require no user interaction, achieve full device compromise, and are used to harvest messages, call logs, contacts, location, camera, and microphone data before exfiltrating it to attacker-controlled infrastructure. None of these historical CVEs, tools, or IOCs are attributed to the August 2026 notification wave itself — they are recorded here as sourced, dated precedent for the attack class Apple's own alert describes, and to give defenders forensic markers (process names, C2 infrastructure, operator-account designations) associated with the vendor ecosystem Apple is warning about.

Apple's recommended response for recipients centers on enabling Lockdown Mode, which Apple states has never been bypassed by a successfully-delivered attack of this class; keeping devices updated; verifying notification authenticity via account.apple.com or the threat-notifications@email.apple.com sender address; and, for suspected victims, contacting Access Now's 24/7 Digital Security Helpline or a qualified digital-forensics responder. Apple has separately pursued its own lawsuit against NSO Group (filed November 23, 2021) though it moved to dismiss that suit on September 13, 2024, citing risk of exposing sensitive threat-intelligence sources and methods; NSO Group has been on the U.S. Commerce Department's Entity List since November 3, 2021.

MITRE ATT&CK techniques used in TL-2026-2034

Collection

T1005 Data from Local System; T1119 Automated Collection; T1417 Input Capture; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Command and Control

T1071 Application Layer Protocol; T1573 Encrypted Channel

Execution

T1203 Exploitation for Client Execution

Affected products and versions in Apple Issues Mercenary Spyware Threat Notifications to Users

  • Apple — iPhone (iOS)
    Vulnerable versions: Not disclosed by Apple for this notification round; no specific build, version, or CVE confirmed
    Fixed in: Historical precedent chains for this attack class were fixed in iOS 14.8 (CVE-2021-30860), iOS 16.6.1 (CVE-2023-41064 / CVE-2023-41061), and iOS 18.3.1 (CVE-2025-43200); Lockdown Mode is Apple's standing mitigation against the class as a whole

Remediation for Apple Issues Mercenary Spyware Threat Notifications to Users

Patches

  • iOS 14.8 / macOS Big Sur 11.6 / watchOS 7.6.2 — CVE-2021-30860 (FORCEDENTRY)
  • iOS 16.6.1 — CVE-2023-41064 and CVE-2023-41061 (BLASTPASS)
  • iOS 18.3.1 — CVE-2025-43200 (Paragon Graphite delivery vector)

Immediate actions

  • Enable Lockdown Mode on iPhone, iPad, and Mac, especially if you are a high-risk individual (journalist, activist, politician, diplomat) or have received a threat notification
  • Update all Apple devices to the latest iOS, iPadOS, and macOS versions immediately
  • Verify the authenticity of any threat notification via account.apple.com or by confirming the sender domain email.apple.com before taking any action inside the message

Workarounds

  • Lockdown Mode — Apple states it has never seen a device successfully compromised by this class of attack while Lockdown Mode is enabled
  • Enable Stolen Device Protection and strong two-factor authentication on the Apple Account

Longer-term hardening

  • Treat repeated threat notifications as an indicator of sustained, individualized targeting and adjust operational security accordingly
  • Engage Access Now's Digital Security Helpline or a qualified incident-response/digital-forensics team for device imaging if compromise is suspected
  • Adopt compartmentalized-device and minimized-attack-surface practices for at-risk personnel (journalists, activists, diplomats, politicians)

Timeline of Apple Issues Mercenary Spyware Threat Notifications to Users

  • The Pegasus Project media consortium (Forbidden Stories, Amnesty International, and partners) publishes findings on NSO Group's Pegasus spyware being used globally against journalists, activists, and politicians, escalating scrutiny of the mercenary spyware industry.
  • Citizen Lab publishes FORCEDENTRY, an NSO Group zero-click iMessage exploit (CVE-2021-30860) that bypassed Apple's BlastDoor sandbox via a crafted JBIG2-encoded PDF to deliver Pegasus; Apple ships iOS 14.8 patching it the same day.
  • The U.S. Commerce Department adds NSO Group and Candiru to its Entity List for developing and supplying spyware used to target journalists, activists, and dissidents.
  • Apple files a federal lawsuit against NSO Group over Pegasus attacks on Apple users.
  • Apple announces and begins its ongoing threat-notification program to alert users individually targeted by state-sponsored or mercenary spyware attacks.
  • Citizen Lab discloses BLASTPASS, an NSO Group zero-click exploit chain (CVE-2023-41064 ImageIO buffer overflow plus CVE-2023-41061 Wallet/PassKit validation flaw) that compromised fully-patched iPhones running iOS 16.6 to deliver Pegasus; Apple ships an emergency patch.
  • Apple files a motion to dismiss its own lawsuit against NSO Group, citing the risk that continued litigation could expose sensitive Apple threat-intelligence sources and methods.
  • Apple ships iOS 18.3.1, patching CVE-2025-43200, later confirmed as the zero-click iMessage/iCloud Link vulnerability used to deliver Paragon Solutions' Graphite spyware.
  • Apple sends threat notifications to iOS users later forensically confirmed to have been targeted with Paragon Graphite spyware, including Italian journalist Ciro Pellegrino.
  • Apple sends a prior threat-notification wave warning users in 100 countries of iPhone targeting, part of the same recurring alert program.
  • Citizen Lab publishes the first forensic confirmation of Paragon Graphite spyware use against iOS-owning journalists, formally attributing exploitation to CVE-2025-43200 and identifying C2 server 46.183.184.91.
  • Apple alerts more than a dozen Iranian threat-notification recipients ahead of the escalation in the Israel-Iran conflict, continuing the recurring notification cadence.
  • Apple issues the current high-confidence mercenary-spyware threat-notification wave to targeted users across 110 countries, without attributing it to a specific vendor, actor, or CVE.
  • Security and technology press (BleepingComputer, The Hacker News, 9to5Mac, Malwarebytes, AppleInsider) report on the August 13 notification wave and its historical context within Apple's threat-notification program.

Sources cited for Apple Issues Mercenary Spyware Threat Notifications to Users

Detection coverage for TL-2026-2034

As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2034 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
11 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2034

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats