Threat reportMalwareTL-2026-2034
Apple Issues Mercenary Spyware Threat Notifications to Users in 110 Countries
Apple Issues Mercenary Spyware Threat Notifications to Users (TL-2026-2034) is a high-severity malware campaign, first published 2026-08-16. It has no confirmed attribution, affects Apple iPhone (iOS), maps to 14 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 11 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 11Indicators of compromise
Key facts for TL-2026-2034
- Threat ID
- TL-2026-2034
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- government administration, news - media, civil society, humanrights, diplomatic, ngo
- Target regions
- Global, North America, Europe, Middle East, Asia-Pacific, Africa, Latin America
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in Apple Issues Mercenary Spyware Threat Notifications to Users
Malware and tooling: Chrysaor, Graphite, BLASTPASS, FORCEDENTRY
How Apple Issues Mercenary Spyware Threat Notifications to Users works
Apple sent high-confidence threat notifications on August 13, 2026 to targeted users across 110 countries warning of mercenary spyware attacks against their iPhones. Apple did not attribute the alerts to a specific spyware vendor or CVE, citing NSO Group's Pegasus only as the historical example of this attack class.
On August 13, 2026, Apple sent a new wave of "threat notifications" to users in 110 countries, warning that its internal threat-intelligence process had detected, with high confidence, a mercenary spyware attack targeting their iPhone. Apple has operated this alert program since November 2021 and has now notified users in over 150 countries in total across multiple annual waves, including a 100-country wave in May 2025 and an alert to more than a dozen Iranian recipients in July 2025 ahead of the Israel-Iran conflict escalation. Consistent with its standing policy, Apple did not name the spyware family, vendor, or nation-state customer behind the August 2026 wave and disclosed no CVE, stating publicly only that it does not attribute threat notifications to specific attackers or geographic regions in order to avoid helping mercenary spyware operators refine their tradecraft. Apple's own framing of the alert cites NSO Group's Pegasus as the representative historical example of "mercenary spyware" — commercial surveillance tooling sold to government customers and used to individually target journalists, human-rights defenders, political dissidents, opposition politicians, and diplomats because of who they are or what they do, rather than as part of mass exploitation.
Because this notification round carries no confirmed exploit, IOC, or vendor attribution, this record documents the attack class Apple explicitly invoked (mercenary/commercial spyware exemplified by Pegasus) using the three most recent, forensically confirmed, publicly documented exploit chains from that class delivered against iOS: NSO Group's FORCEDENTRY (CVE-2021-30860, 2021) and BLASTPASS (CVE-2023-41064/CVE-2023-41061, 2023), and Paragon Solutions' Graphite (CVE-2025-43200, 2025) — the most recent forensically confirmed case, used against Italian journalist Ciro Pellegrino and at least one other European journalist. All three are zero-click chains delivered over Apple's Messages/iMessage stack that require no user interaction, achieve full device compromise, and are used to harvest messages, call logs, contacts, location, camera, and microphone data before exfiltrating it to attacker-controlled infrastructure. None of these historical CVEs, tools, or IOCs are attributed to the August 2026 notification wave itself — they are recorded here as sourced, dated precedent for the attack class Apple's own alert describes, and to give defenders forensic markers (process names, C2 infrastructure, operator-account designations) associated with the vendor ecosystem Apple is warning about.
Apple's recommended response for recipients centers on enabling Lockdown Mode, which Apple states has never been bypassed by a successfully-delivered attack of this class; keeping devices updated; verifying notification authenticity via account.apple.com or the threat-notifications@email.apple.com sender address; and, for suspected victims, contacting Access Now's 24/7 Digital Security Helpline or a qualified digital-forensics responder. Apple has separately pursued its own lawsuit against NSO Group (filed November 23, 2021) though it moved to dismiss that suit on September 13, 2024, citing risk of exposing sensitive threat-intelligence sources and methods; NSO Group has been on the U.S. Commerce Department's Entity List since November 3, 2021.
MITRE ATT&CK techniques used in TL-2026-2034
Collection
T1005 Data from Local System; T1119 Automated Collection; T1417 Input Capture; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Command and Control
T1071 Application Layer Protocol; T1573 Encrypted Channel
Execution
Affected products and versions in Apple Issues Mercenary Spyware Threat Notifications to Users
- Apple — iPhone (iOS)
Vulnerable versions: Not disclosed by Apple for this notification round; no specific build, version, or CVE confirmed
Fixed in: Historical precedent chains for this attack class were fixed in iOS 14.8 (CVE-2021-30860), iOS 16.6.1 (CVE-2023-41064 / CVE-2023-41061), and iOS 18.3.1 (CVE-2025-43200); Lockdown Mode is Apple's standing mitigation against the class as a whole
Remediation for Apple Issues Mercenary Spyware Threat Notifications to Users
Patches
- iOS 14.8 / macOS Big Sur 11.6 / watchOS 7.6.2 — CVE-2021-30860 (FORCEDENTRY)
- iOS 16.6.1 — CVE-2023-41064 and CVE-2023-41061 (BLASTPASS)
- iOS 18.3.1 — CVE-2025-43200 (Paragon Graphite delivery vector)
Immediate actions
- Enable Lockdown Mode on iPhone, iPad, and Mac, especially if you are a high-risk individual (journalist, activist, politician, diplomat) or have received a threat notification
- Update all Apple devices to the latest iOS, iPadOS, and macOS versions immediately
- Verify the authenticity of any threat notification via account.apple.com or by confirming the sender domain email.apple.com before taking any action inside the message
Workarounds
- Lockdown Mode — Apple states it has never seen a device successfully compromised by this class of attack while Lockdown Mode is enabled
- Enable Stolen Device Protection and strong two-factor authentication on the Apple Account
Longer-term hardening
- Treat repeated threat notifications as an indicator of sustained, individualized targeting and adjust operational security accordingly
- Engage Access Now's Digital Security Helpline or a qualified incident-response/digital-forensics team for device imaging if compromise is suspected
- Adopt compartmentalized-device and minimized-attack-surface practices for at-risk personnel (journalists, activists, diplomats, politicians)
Timeline of Apple Issues Mercenary Spyware Threat Notifications to Users
- The Pegasus Project media consortium (Forbidden Stories, Amnesty International, and partners) publishes findings on NSO Group's Pegasus spyware being used globally against journalists, activists, and politicians, escalating scrutiny of the mercenary spyware industry.
- Citizen Lab publishes FORCEDENTRY, an NSO Group zero-click iMessage exploit (CVE-2021-30860) that bypassed Apple's BlastDoor sandbox via a crafted JBIG2-encoded PDF to deliver Pegasus; Apple ships iOS 14.8 patching it the same day.
- The U.S. Commerce Department adds NSO Group and Candiru to its Entity List for developing and supplying spyware used to target journalists, activists, and dissidents.
- Apple files a federal lawsuit against NSO Group over Pegasus attacks on Apple users.
- Apple announces and begins its ongoing threat-notification program to alert users individually targeted by state-sponsored or mercenary spyware attacks.
- Citizen Lab discloses BLASTPASS, an NSO Group zero-click exploit chain (CVE-2023-41064 ImageIO buffer overflow plus CVE-2023-41061 Wallet/PassKit validation flaw) that compromised fully-patched iPhones running iOS 16.6 to deliver Pegasus; Apple ships an emergency patch.
- Apple files a motion to dismiss its own lawsuit against NSO Group, citing the risk that continued litigation could expose sensitive Apple threat-intelligence sources and methods.
- Apple ships iOS 18.3.1, patching CVE-2025-43200, later confirmed as the zero-click iMessage/iCloud Link vulnerability used to deliver Paragon Solutions' Graphite spyware.
- Apple sends threat notifications to iOS users later forensically confirmed to have been targeted with Paragon Graphite spyware, including Italian journalist Ciro Pellegrino.
- Apple sends a prior threat-notification wave warning users in 100 countries of iPhone targeting, part of the same recurring alert program.
- Citizen Lab publishes the first forensic confirmation of Paragon Graphite spyware use against iOS-owning journalists, formally attributing exploitation to CVE-2025-43200 and identifying C2 server 46.183.184.91.
- Apple alerts more than a dozen Iranian threat-notification recipients ahead of the escalation in the Israel-Iran conflict, continuing the recurring notification cadence.
- Apple issues the current high-confidence mercenary-spyware threat-notification wave to targeted users across 110 countries, without attributing it to a specific vendor, actor, or CVE.
- Security and technology press (BleepingComputer, The Hacker News, 9to5Mac, Malwarebytes, AppleInsider) report on the August 13 notification wave and its historical context within Apple's threat-notification program.
Sources cited for Apple Issues Mercenary Spyware Threat Notifications to Users
- Apple sends new threat notification alerts over mercenary spyware attacks
- Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
- Apple now uses iPhone alerts for targets of mercenary spyware
- Apple sends fresh wave of mercenary spyware warnings worldwide
- About Apple threat notifications and protecting against mercenary spyware
- FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild
- BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild
- Graphite Caught: First Forensic Confirmation of Paragon's iOS Mercenary Spyware Finds Journalists Targeted
- Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware
- US Sanctions Pegasus-maker NSO Group and 3 Others For Selling Spyware
- Targeted by NSO? Apple will now alert you if it detects an attack
- Apple seeks dismissal of its NSO Group lawsuit, citing risk of exposing 'vital security information'
Detection coverage for TL-2026-2034
As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2034 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2034
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.