You have commented 339 times on Rantburg.

Your Name
Your e-mail (optional)
Website (optional)
My Original Nic        Pic-a-Nic        Sorry. Comments have been closed on this article.
Bold Italic Underline Strike Bullet Blockquote Small Big Link Squish Foto Photo
Science & Technology
Newly unearthed iPhone spyware tool sold to governments for targeted surveillance
2023-04-25
[FoxNews] A new type of spyware has been discovered being sold to various governments throughout the world and is meant to be used to spy mainly on journalists, activists, and political opponents. Here is what we know so far and how you can make sure your devices are always protected.

WHAT IS THIS NEW SPYWARE?
A report released from Citizen Lab reveals that the spyware, which has been given the name Reign, is being used to monitor the activities of targeted high-profile individuals. The Microsoft Threat Intelligence team was able to analyze the spyware and found that it was provided by the Israeli company QuaDream.

QuaDream is known for developing advanced spyware tools and caters to several prominent governments throughout the world. There have been at least five targeted spyware cases in North America, Central Asia, Southeast Asia, Europe, and the Middle East.

HOW DOES REIGN ATTACK PEOPLE'S DEVICES?
The spyware reaches all these devices through what is known as the "Endofdays" iOS 14 zero-click exploit. This uses backdated iCloud calendar invites that when sent to targeted people are automatically accepted. Once the invitation is on a person's device, spyware operators can access multiple iOS features. Hackers can get to your audio recordings of calls, iPhone microphone and camera access, access to the iPhone Files app, iPhone location tracking, generation of iCloud 2FA passwords, and more.

HOW WAS REIGN DISCOVERED?
Reign was discovered because it comes with a feature that ironically was supposed to help it remain undiscoverable. The feature was one of self-destruction where Reign could remove traces of itself on a device so that no one would be able to find it. However, this ended up helping research teams in identifying when a target was attacked.

It is believed by Citizen Lab that QuaDream's spyware has been linked to over 600 servers and 200 domains since late 2021. The company also believes that QuaDream spyware is currently operating in the following countries:

  • Czech Republic

  • Hungary

  • Ghana

  • Bulgaria

  • Romania

  • Israel

  • Mexico

  • United Arab Emirates (UAE)

  • Uzbekistan

  • Singapore

HOW CAN I PROTECT MYSELF FROM SPYWARE?
Although Reign has not yet been detected as a threat to the U.S. government, and it doesn't seem to be targeting citizens with low-profile statuses, it's important that you still know how to protect yourself from spyware.

HAVE GOOD ANTIVIRUS SOFTWARE ON ALL YOUR DEVICES
This story is another reminder to always have good antivirus software running on your devices as it will protect you from accidentally clicking malicious links and it will remove any malware from your devices.
Related:
Citizen Lab: 2021-11-11 PA’s foreign ministry accuses Israel of using NSO’s Pegasus spyware against it
Citizen Lab: 2021-11-08 Palestinian activists hacked by Israeli firm NSO spyware
Citizen Lab: 2021-09-16 Apple releases emergency software update due to spyware flaw
Posted by:Skidmark

#2  I am protected by my strong password.
Posted by: Super Hose   2023-04-25 12:20  

#1  The best thing is to not use or carry a phone... I leave mine in the truck, truck is traceable as well through norstar. I hate this. We talk about stuff and it shows up as adds, opening our phones listening to conversations and all is at the USG fingertips. They talk about the threat to the USG, not the systems the USG is currently using which exceeds this things capability....
Posted by: 49 Pan   2023-04-25 10:00  

00:00