Apple Sues NSO Group to Curb the Abuse of State-Sponsored Spyware

Apple also announced a $10 million contribution to support cybersurveillance researchers and advocates

Apple® today filed a lawsuit against NSO Group and its parent company to hold it accountable for the surveillance and targeting of Apple users. The complaint provides new information on how NSO Group infected victims' devices with its Pegasus spyware. To prevent further abuse and harm to its users, Apple is also seeking a permanent injunction to ban NSO Group from using any Apple software, services, or devices.

NSO Group creates sophisticated, state-sponsored surveillance technology that allows its highly targeted spyware to surveil its victims. These attacks are only aimed at a very small number of users, and they impact people across multiple platforms, including iOS and Android. Researchers and journalists have publicly documented a history of this spyware being abused to target journalists, activists, dissidents, academics, and government officials. 1

"State-sponsored actors like the NSO Group spend millions of dollars on sophisticated surveillance technologies without effective accountability. That needs to change," said Craig Federighi, Apple's senior vice president of Software Engineering. "Apple devices are the most secure consumer hardware on the market — but private companies developing state-sponsored spyware have become even more dangerous. While these cybersecurity threats only impact a very small number of our customers, we take any attack on our users very seriously, and we're constantly working to strengthen the security and privacy protections in iOS to keep all our users safe."

NSO Group's FORCEDENTRY Exploit
Apple's legal complaint provides new information on NSO Group's FORCEDENTRY, an exploit for a now-patched vulnerability previously used to break into a victim's Apple device and install the latest version of NSO Group's spyware product, Pegasus. The exploit was originally identified by the Citizen Lab, a research group at the University of Toronto.

The spyware was used to attack a small number of Apple users worldwide with dangerous malware and spyware. Apple's lawsuit seeks to ban NSO Group from further harming individuals by using Apple's products and services. The lawsuit also seeks redress for NSO Group's flagrant violations of US federal and state law, arising out of its efforts to target and attack Apple and its users.

NSO Group and its clients devote the immense resources and capabilities of nation-states to conduct highly targeted cyberattacks, allowing them to access the microphone, camera, and other sensitive data on Apple and Android devices. To deliver FORCEDENTRY to Apple devices, attackers created Apple IDs to send malicious data to a victim's device — allowing NSO Group or its clients to deliver and install Pegasus spyware without a victim's knowledge. Though misused to deliver FORCEDENTRY, Apple servers were not hacked or compromised in the attacks.

Apple makes the most secure mobile devices on the market, and constantly invests in strengthening privacy and security protections for its users. For example, researchers have found that other mobile platforms have 15 times more malware infections than iPhone®, 2 and a recent study showed that less than 2 percent of mobile malware targets iOS devices. 3

iOS 15 includes a number of new security protections, including significant upgrades to the BlastDoor security mechanism. While NSO Group spyware continues to evolve, Apple has not observed any evidence of successful remote attacks against devices running iOS 15 and later versions. Apple urges all users to update their iPhone and always use the latest software.

"At Apple, we are always working to defend our users against even the most complex cyberattacks. The steps we're taking today will send a clear message: in a free society, it is unacceptable to weaponize powerful state-sponsored spyware against those who seek to make the world a better place," said Ivan Krstić, head of Apple Security Engineering and Architecture. "Our threat intelligence and engineering teams work around the clock to analyze new threats, rapidly patch vulnerabilities, and develop industry-leading new protections in our software and silicon. Apple runs one of the most sophisticated security engineering operations in the world, and we will continue to work tirelessly to protect our users from abusive state-sponsored actors like NSO Group."

Apple's Continuing Efforts to Protect its Users
Apple commends groups like the Citizen Lab and Amnesty Tech for their groundbreaking work to identify cybersurveillance abuses and help protect victims. To further strengthen efforts like these, Apple will be contributing $10 million, as well as any damages from the lawsuit, to organizations pursuing cybersurveillance research and advocacy.

Apple will also support the accomplished researchers at the Citizen Lab with pro-bono technical, threat intelligence, and engineering assistance to aid their independent research mission, and where appropriate, will offer the same assistance to other organizations doing critical work in this space.

"Mercenary spyware firms like NSO Group have facilitated some of the world's worst human rights abuses and acts of transnational repression, while enriching themselves and their investors," said Ron Deibert, director of the Citizen Lab at the University of Toronto. "I applaud Apple for holding them accountable for their abuses, and hope in doing so Apple will help to bring justice to all who have been victimized by NSO Group's reckless behavior."

Apple is notifying the small number of users that it discovered may have been targeted by FORCEDENTRY. Any time Apple discovers activity consistent with a state-sponsored spyware attack, Apple will notify the affected users in accordance with industry best practices.

Apple believes privacy is a fundamental human right, and security is a constant focus for teams across the company. For years, Apple has led the industry with new protections to disrupt sophisticated attacks and defend its users, including features such as pointer authentication codes (PAC), BlastDoor, and the Page Protection Layer (PPL). For more information about Apple's platform security, visit support.apple.com/guide/security/welcome/web .

1 Citizen Lab, "NSO Group iMessage Zero-Click Exploit Captured in the Wild," Sept. 13, 2021.
2 Nokia, "Threat Intelligence Report 2020," 2020.
3 PurpleSec, "2021 Cyber Security Statistics: The Ultimate List Of Stats, Data & Trends," 2021.

Apple revolutionized personal technology with the introduction of the Macintosh in 1984. Today, Apple leads the world in innovation with iPhone, iPad, Mac, Apple Watch, and Apple TV. Apple's five software platforms — iOS, iPadOS, macOS, watchOS, and tvOS — provide seamless experiences across all Apple devices and empower people with breakthrough services including the App Store, Apple Music, Apple Pay, and iCloud. Apple's more than 100,000 employees are dedicated to making the best products on earth, and to leaving the world better than we found it.

NOTE TO EDITORS: For additional information visit Apple Newsroom ( www.apple.com/newsroom ), or call Apple's Media Helpline at (408) 974-2042.

© 2021 Apple Inc. All rights reserved. Apple, the Apple logo, and iPhone are trademarks of Apple. Other company and product names may be trademarks of their respective owners.

Press Contacts:
 
Scott Radcliffe
Apple
sradcliffe@apple.com

Fred Sainz
Apple
sainz@apple.com

News Provided by Business Wire via QuoteMedia

The Conversation (0)
cell phone lying on table with app icons floating above it

How to Invest in Mobile Apps (Updated 2024)

The ubiquity of mobile devices and their prominence in everyday life has led to the development of mobile apps for everything from gaming and dating to banking and stock trading.

Mobile apps began rising to prominence in 2007 with the launch of the iPhone, which heralded a new era in connectivity brought about by revolutionary touch technology. The field has grown widely from thereon out, and the diversity of today’s offerings makes investing in mobile apps an appealing prospect.

With about 2.87 million apps in Google’s (NASDAQ: GOOGL) Google Play Store and around 1.96 million apps available in Apple’s (NASDAQ:AAPL) App Store, there is no shortage of app choices for mobile devices.

Keep reading...Show less
Icons for various apps floating above a smartphone.

Social Media Stocks: 5 Biggest Companies

The world’s largest social media platforms have revolutionized the way people connect on the internet, and the companies behind these platforms can offer major investment opportunities.

This year's strong rally in technology stocks, led by Meta Platforms (NASDAQ:FB), is a clear example of the huge presence social media companies have in the stock market. In late April, shares of the social media giant jumped 14.6 percent on higher-than-expected earnings. The news came alongside increasing investor confidence in the broader tech industry.

“Meta earnings show the company’s commitment to cost discipline while driving accelerating N-T revenue growth and also continuing to invest in longer-term transformational technologies like artificial intelligence (AI) and the metaverse,” said Doug Anmuth, an analyst at JPMorgan Chase (NYSE:JPM).

Keep reading...Show less
BlackBerry Extends Partnership with Leading Managed Security Services Provider  to Ensure SMBs are Set Up for Cyber Success

BlackBerry Extends Partnership with Leading Managed Security Services Provider to Ensure SMBs are Set Up for Cyber Success

BlackBerry Limited (NYSE: BB; TSX: BB) and Solutions Granted today announced an extended partnership, naming the leading cybersecurity services provider a Master Managed Security Services Provider (MSSP), enabling it to better scale and meet the growing demand for cybersecurity services among small and medium-sized businesses (SMBs).

BlackBerry Logo Black (PRNewsfoto/Blackberry Limited)

"Solutions Granted has been honored as BlackBerry MSSP Partner of the Year for North America for five consecutive years and we're excited to take our partnership to the next level by crowning them as our top Master MSSP," said Adam Enterkin , Chief Revenue Officer, Americas, BlackBerry Cybersecurity. "BlackBerry is dedicated to increasing its focus on MSSP partners to ensure they're set up for success. Endpoints are proliferating, and so are the cyberattacks against them. Our extended partnership with Solutions Granted will help hundreds of small and mid-size businesses continuously adapt to an ever-changing threat landscape."

As a 'Master MSSP', Solutions Granted will be better positioned to help its own partners to deliver Managed Detection and Response (MDR) and other Managed Security Services to their mid-market and SMB clients.  In partnership with BlackBerry and heavily leveraging the Cylance® AI-powered portfolio, Solutions Granted helps thousands of clients secure their environments and prevent attacks. By working with Solutions Granted, MSSPs and managed service providers (MSPs) can offer industry leading managed security, without making the significant investment of building out their own security operations center (SOC).

CylanceENDPOINT™ is among the solutions it helps managed service providers (MSPs) deploy to clients, either as individual managed services or integrated into a SOC-as-a-service offering.

"BlackBerry's support for our business model provides the flexibility we need to continue to meet customer demand and provide the best possible product support for their business needs," said Michael E. Crean , Chief Executive Officer, Solutions Granted. "We value the investment BlackBerry is making in our partnership and know this will go a long way in setting up our customers for success."

To learn more about BlackBerry MSSP Partners, visit blackberry.com/us/en/partners/mssp-partners .

About BlackBerry

BlackBerry (NYSE: BB; TSX: BB) provides intelligent security software and services to enterprises and governments around the world.  The company secures more than 500M endpoints including over 215M vehicles.  Based in Waterloo, Ontario , the company leverages AI and machine learning to deliver innovative solutions in the areas of cybersecurity, safety and data privacy solutions, and is a leader in the areas of endpoint management, endpoint security, encryption, and embedded systems.  BlackBerry's vision is clear - to secure a connected future you can trust.

BlackBerry. Intelligent Security. Everywhere.

For more information, visit BlackBerry.com and follow @BlackBerry.

Trademarks, including but not limited to BlackBerry and EMBLEM Design are the trademarks or registered trademarks of BlackBerry Limited, and the exclusive rights to such trademarks are expressly reserved.  All other trademarks are the property of their respective owners.  BlackBerry is not responsible for any third-party products or services.

About Solutions Granted Inc.

Solutions Granted is a Master Managed Security Services Provider (Master MSSP). They offer cybersecurity solutions to North American MSPs and MSSPs and are committed to delivering solutions without requiring minimums, commitments, or long-term contracts. They proudly offer many security layers as well as a 24x7 U.S.-based Security Operations Center (SOC). Over the past several years, Solutions Granted has emerged as a clear leader in the channel, by winning countless awards including the CRN Security 100 list, Top 100 MSSP List, Top Global MSSP List, and BlackBerry MSSP Partner of the Year. Learn more at https://www.SolutionsGranted.com

Media Contacts:

BlackBerry Media Relations

+1 (519) 597-7273

mediarelations@BlackBerry.com

Cision View original content to download multimedia: https://www.prnewswire.com/news-releases/blackberry-extends-partnership-with-leading-managed-security-services-provider-mssp-to-ensure-smbs-are-set-up-for-cyber-success-301803800.html

SOURCE BlackBerry Limited

News Provided by PR Newswire via QuoteMedia

Keep reading...Show less
BlackBerry's Quarterly Threat Intelligence Report Finds Banks, Healthcare Providers and Food Retailers are Top Targets for Cybercrime

BlackBerry's Quarterly Threat Intelligence Report Finds Banks, Healthcare Providers and Food Retailers are Top Targets for Cybercrime

Geopolitical unrest positions key industries as targets for state-sponsored actors and financially motivated attacks

BlackBerry Limited (NYSE: BB; TSX: BB) today released its latest Quarterly Global Threat Intelligence Report highlighting an increase in cyberattacks directed at financial institutions, food retailers and healthcare providers, with 60 percent of all attacks targeting these three key industries.

News Provided by PR Newswire via QuoteMedia

Keep reading...Show less
person using credit card to pay for something on their phone

Mobile Investing in Australia

After lagging behind for a prolonged period, Australia's tech sector is ramping up at an accelerated pace. The tech sector is now equivalent to 8.5 percent of the country's GDP as of the end of 2021, an increase of 26 percent since the onset of COVID-19 through June 2021 and a massive 79 percent increase over the past five years. Tech contributes AU$167 billion to the Australian economy, trailing only the mining (AU$205 billion) and financial/insurance (AU$169 billion) sectors.

Australia's characteristically resilient economy — which had not experienced a recession in nearly 30 years prior to COVID-19 lockdowns — has provided a sturdy backdrop for its growing tech sector. The growth in the tech sector’s contribution to the GDP has outpaced average growth of other industries by more than 400 percent, a gain partly attributable to accelerated digital technology adoption during the pandemic.

This dramatic expansion is largely in response to Australia's need to catch up to the rest of the world and assert itself in the global tech marketplace. Should the tech sector continue to grow at its current rate it will eventually surpass the relative GDP contribution of the long dominant mining sector. This will also complete the process of bringing Australia more in line with other western economies such as the UK, and notably Canada, which is comparable to Australia in terms of its dominant mining and agricultural industries.

Keep reading...Show less
DGTL Holdings Completes Acquisition of Engagement Labs

DGTL Holdings Completes Acquisition of Engagement Labs

DGTL Holdings Inc. (TSXV: DGTL) (OTCQB: DGTHF) (WKN: A2QB0L) (FSE: D0G) ("DGTL Holdings") and Engagement Labs Inc. (TSXV: EL) ("Engagement Labs") are pleased to announce that DGTL has completed its previously announced acquisition of Engagement Labs by way of a plan of arrangement (the "Arrangement").

Transaction Details

News Provided by Newsfile via QuoteMedia

Keep reading...Show less

Latest Press Releases

Related News

×