ZeroHour
CyberScooppublished ()ingested @AJVicens

NSO Group's latest spyware on par with nation

criticalMalware exploited in the wildimportance 60
Full article961 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The analysis offers a window into the level of spyware the embattled spyware firm offered clients around the world.

(Photo by Amir Levy/Getty Images)

When Apple announced Nov. 23 that it filed a lawsuit against Israeli spyware firm NSO Group, it claimed that the firm and its clients “devote the immense resources and capabilities of nation-states to conduct highly targeted cyberattacks.” An independent analysis published Wednesday backs that claim up.

Google Project Zero researchers Ian Beer and Samuel Groß took a deep dive into FORCEDENTRY, the malware developed by NSO Group that allowed adversaries to infect targeted Apple devices — without the owner’s knowledge — with NSO Group’s Pegasus spyware. The researchers concluded that it’s “one of the most technically sophisticated exploits” they’ve ever seen, rivaling “those previously thought to be accessible to only a handful of nation states.”

Previous iterations of the Pegasus software required the victim to click a link in an SMS message. But FORCEDENTRY was an example of NSO Group’s zero-click exploitation technology, where no interaction from the target was required.

“Short of not using a device, there is no way to prevent exploitation by a zero-click exploit,” the researchers wrote Wednesday. “It’s a weapon against which there is no defense.”

The analysis details how FORCEDENTRY exploited a since-patched vulnerability in Apple’s iMessage SMS service processing of GIF image files. A vulnerability in the way iMessage rendered GIFs, involving 1990s-era scanning and compression software, allowed for a malicious PDF to be loaded and opened without the target’s knowledge, giving an adversary access to data in other areas of the device.

“It’s pretty incredible,” the researchers wrote, “and at the same time, pretty terrifying.”

Two patches from Apple, one in September and the other in October, corrected the issues in that processing protocol that enabled this vulnerability, the researchers note.

“It’s really sophisticated stuff,” John Scott-Railton, senior researcher at Citizen Lab, told Wired, which first wrote about the Project Zero analysis. “And when it’s wielded by an all-gas, no-brakes autocrat, it’s totally terrifying.”

Citizen Lab, a human rights group based in Toronto, discovered FORCEDENTRY in September during an analysis of a Saudi activits’ phone. It turned the information over to Apple, and also provided a sample of FORCEDENTRY to the Project Zero researchers.

NSO Group’s malware has been under scrutiny for years as an enabling factor for authoritarian governments around the world to target human rights activists, journalists and political opponents. The U.S. government added the company to its sanctions list on Nov. 4, making it difficult for the company to interact with any U.S. business.

On Tuesday, a group of U.S. lawmakers asked the Treasury Department and State Department to sanction NSO Group, along with surveillance firms in the United Arab Emirates and in Europe.

The pressure has mounted to the point that the company is reportedly mulling a shutdown of its Pegasus unit and a possible sale.

NSO Group did not immediately respond to a request for comment, but has frequently denied wrongdoing and touted the benefits of its technology in combatting crime. Apple declined to comment.

More Scoops

This aerial photograph shows demonstrators and students as they gather in front of Serbia’s Constitutional Court building during a protest to demand accountability for the Novi Sad railway station tragedy, in Belgrade, on January 12, 2025. Thousands of Serbians protested in the capital Belgrade on January 12, 2025, against corruption and demanding justice for those killed in a train station roof collapse. The demonstrations have been ongoing for two months since a roof in a train station in the northern city of Novi Sad, which had recently undergone restoration work, collapsed on November 1, 2024, and killed 15 people. (Photo by TADIJA ANASTASIJEVIC / AFP via Getty Images)

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia…

Stelios Kouloglou arrives for a meeting with the police commissioner at the police headquarters on Dec. 3, 2019 in Valletta, Malta. (Photo by ANDREAS SOLARO / AFP) (Photo by ANDREAS SOLARO/AFP via Getty Images)

Someone infected a spyware probe overseer with spyware

This illustration photograph taken on November 27, 2024, shows the logo of US instant messaging software Whatsapp displayed on a smartphone’s screen, in Frankfurt am Main, western Germany. (Photo by Kirill KUDRYAVTSEV / AFP)

Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nso-group-spyware-forcedentry-nation-state-hackers/