# Apple Issues Mercenary Spyware Threat Notifications to Users in 110 Countries

> Apple sent high-confidence threat notifications on August 13, 2026 to targeted users across 110 countries warning of mercenary spyware attacks against their iPhones. Apple did not attribute the alerts to a specific spyware vendor or CVE, citing NSO Group's Pegasus only as the historical example of this attack class.

- **Published:** 2026-08-16T00:00:00Z
- **Last reviewed:** 2026-08-16T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2034
- **ID:** TL-2026-2034
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On August 13, 2026, Apple sent a new wave of "threat notifications" to users in 110 countries, warning that its internal threat-intelligence process had detected, with high confidence, a mercenary spyware attack targeting their iPhone. Apple has operated this alert program since November 2021 and has now notified users in over 150 countries in total across multiple annual waves, including a 100-country wave in May 2025 and an alert to more than a dozen Iranian recipients in July 2025 ahead of the Israel-Iran conflict escalation. Consistent with its standing policy, Apple did not name the spyware family, vendor, or nation-state customer behind the August 2026 wave and disclosed no CVE, stating publicly only that it does not attribute threat notifications to specific attackers or geographic regions in order to avoid helping mercenary spyware operators refine their tradecraft. Apple's own framing of the alert cites NSO Group's Pegasus as the representative historical example of "mercenary spyware" — commercial surveillance tooling sold to government customers and used to individually target journalists, human-rights defenders, political dissidents, opposition politicians, and diplomats because of who they are or what they do, rather than as part of mass exploitation.

Because this notification round carries no confirmed exploit, IOC, or vendor attribution, this record documents the attack class Apple explicitly invoked (mercenary/commercial spyware exemplified by Pegasus) using the three most recent, forensically confirmed, publicly documented exploit chains from that class delivered against iOS: NSO Group's FORCEDENTRY (CVE-2021-30860, 2021) and BLASTPASS (CVE-2023-41064/CVE-2023-41061, 2023), and Paragon Solutions' Graphite (CVE-2025-43200, 2025) — the most recent forensically confirmed case, used against Italian journalist Ciro Pellegrino and at least one other European journalist. All three are zero-click chains delivered over Apple's Messages/iMessage stack that require no user interaction, achieve full device compromise, and are used to harvest messages, call logs, contacts, location, camera, and microphone data before exfiltrating it to attacker-controlled infrastructure. None of these historical CVEs, tools, or IOCs are attributed to the August 2026 notification wave itself — they are recorded here as sourced, dated precedent for the attack class Apple's own alert describes, and to give defenders forensic markers (process names, C2 infrastructure, operator-account designations) associated with the vendor ecosystem Apple is warning about.

Apple's recommended response for recipients centers on enabling Lockdown Mode, which Apple states has never been bypassed by a successfully-delivered attack of this class; keeping devices updated; verifying notification authenticity via account.apple.com or the threat-notifications@email.apple.com sender address; and, for suspected victims, contacting Access Now's 24/7 Digital Security Helpline or a qualified digital-forensics responder. Apple has separately pursued its own lawsuit against NSO Group (filed November 23, 2021) though it moved to dismiss that suit on September 13, 2024, citing risk of exposing sensitive threat-intelligence sources and methods; NSO Group has been on the U.S. Commerce Department's Entity List since November 3, 2021.

## MITRE ATT&CK

- T1203 Exploitation for Client Execution
- T1055 Process Injection
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1082 System Information Discovery
- T1057 Process Discovery
- T1005 Data from Local System
- T1119 Automated Collection
- T1429 Audio Capture
- T1512 Video Capture
- T1430 Location Tracking
- T1417 Input Capture
- T1071 Application Layer Protocol
- T1573 Encrypted Channel

## Sources

- [Apple sends new threat notification alerts over mercenary spyware attacks](https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks/)
- [Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware](https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html)
- [Apple now uses iPhone alerts for targets of mercenary spyware](https://www.malwarebytes.com/blog/news/2026/08/apple-now-uses-iphone-alerts-for-targets-of-mercenary-spyware)
- [Apple sends fresh wave of mercenary spyware warnings worldwide](https://9to5mac.com/2026/08/13/apple-sends-fresh-wave-of-mercenary-spyware-warnings-worldwide/)
- [About Apple threat notifications and protecting against mercenary spyware](https://support.apple.com/en-us/102174)
- [FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild](https://citizenlab.ca/research/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild/)
- [BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild](https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/)
- [Graphite Caught: First Forensic Confirmation of Paragon's iOS Mercenary Spyware Finds Journalists Targeted](https://citizenlab.ca/research/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/)
- [Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware](https://thehackernews.com/2025/06/apple-zero-click-flaw-in-messages.html)
- [US Sanctions Pegasus-maker NSO Group and 3 Others For Selling Spyware](https://thehackernews.com/2021/11/us-sanctions-pegasus-maker-nso-group.html)
- [Targeted by NSO? Apple will now alert you if it detects an attack](https://9to5mac.com/2021/11/24/targeted-by-nso-apple-alerts/)
- [Apple seeks dismissal of its NSO Group lawsuit, citing risk of exposing 'vital security information'](https://therecord.media/apple-seeks-dismissal-of-nso-lawsuit-pegasus-spyware)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2034
