back to article Another zero-click Apple spyware maker just popped up on the radar again

Malware reportedly developed by a little-known Israeli commercial spyware maker has been found on devices of journalists, politicians, and an NGO worker in multiple countries, say researchers.  Reports from Microsoft and The University of Toronto's Citizen Lab both conclude that government-serving spyware maker QuaDream used a …

  1. DS999 Silver badge

    Apple should bribe a few people inside repressive governments

    To have any zero click software their government acquires installed onto an Apple controlled phone "posing as" that of a journalist critical of their country's government. Apple can then dissect the malware, patch it, and the company selling it either rolls out a new zero click (lather rinse repeat) or they don't have another one and they get a bunch of very bad people repressive governments after them for having software that "goes bad" within a short time and they have to close up shop and go into hiding. Win win!

    1. Anonymous Coward
      Anonymous Coward

      Re: Apple should bribe a few people inside repressive governments

      Interesting idea but you would first have to be aware that it's happening and then somehow engineer yourself to become a target which could also have more physical consequences - countries like that often also jail people. It would be more interesting to offer a resource for such journo's to have their devices checked more thoroughly.

      <evil gov> will have to find a new solution, though, as this used an iOS 14 vulnerability that has since been fixed, we're at iOS 16.4 or so now (or 16.5 beta 4 :) ).

      I'm wondering if it wouldn't be a good idea to be a beta tester if you're that exposed because that rewrites the OS and reboots every time - makes it so much harder to write something that sticks, you'd have to resort to compromising apps instead and that's easier to do on Android. Not impossible on iOS, just more challenging.

    2. GruntyMcPugh

      Re: Apple should bribe a few people inside repressive governments

      I think it works the other way around, nation state level subversion of technology company employees allows them full access to source code, and to embed dubious code and exploits into commercial products. We get regular briefings from a chap from the NCSC, but NCSC is kind of like the word 'love' tattooed on the knuckles of GCHQ. They are trying to help, while their comrades actively exploit, and do not report vulnerabilities. I suspect some GCHQ staff are also on other payrolls.

  2. BOFH in Training

    If I was an Israeli, I would be concerned

    Cos the current government seems hell bent on controlling the justice system there.

    If they succeed, it's only a matter of time before such "tools" are used widely against the average person there, considering the courts will be toothless to fight the government.

    1. Furious Reg reader John

      Re: If I was an Israeli, I would be concerned

      Maybe a bit more research on the legal reform topic is needed before you go off on tangents.

      1. MiguelC Silver badge

        Re: If I was an Israeli, I would be concerned

        Netanyahu paused the reform because of massive street protests. Notice it's 'paused', not cancelled.

        Do you have any research bits of your own to counter?

    2. Anonymous Coward
      Anonymous Coward

      Re: If I was an Israeli, I would be concerned

      @BOFH_in_Training

      Quote: "....used widely against the average person...."

      So....what makes you think that various spooks, in various countries, are NOT ALREADY using surveillance tools "against the average person"????

      Edward Snowden might have provided some clues ten years ago......yup.....ten years.....

      Another quote (William Burroughs): "The paranoid is a person who knows a little of what is going on."

  3. Anonymous Coward
    Anonymous Coward

    Big Picture Needed......

    So......anyone worrying about NSO or QuaDream.....just set up a burner.....and a different burner every week or so....

    Of course, for this scheme to work effectively, all the private communications need to be WITH OTHER BURNERS.

    (1) Message content might be exfiltrated.....but the spooks don't know who is doing the messaging

    (2) The spooks need to redo their malware every week

    I don't suppose this advice is much good to Angela Merkel by now........

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like