38 Matching Annotations
  1. May 2023
  2. Jul 2021
    1. multiple successful zero-click infections in May and June 2021. We can see one example of this on 17 May 2021. An unfamiliar iMessage account is recorded and in the following minutes at least 20 iMessage attachment chunks are created on disk.

      adding email to contact list to trigger user-discovery routine as a trigger for the infection.

    2. While we have not been able to extract records from Cache.db databases due to the inability to jailbreak these two devices, additional diagnostic data extracted from these iPhones show numerous iMessage push notifications immediately preceding the execution of Pegasus processes

      malware pushed using a legitimate app's push message. first of its kind of attack.

    3. However, while it is only effective on domestic networks, the targeting of foreign targets or of individuals in diaspora communities also changed

      possibly the malware synced in through rogue icloud accounts which were surreptitiously added to the target device, or through a trigger based on iMessage sync for a canary email address.

    4. Network injection is an effective and cost-efficient attack vector for domestic use especially in countries with leverage over mobile operators

      leverage with mobile operators can be used for redirection attacks. if mobile no is equal to this, when the user requests this url, redirect him to this url