Why rebooting your phone daily is your best defense against zero-click attacks

Why you should treat your phone, like a computer, according to this cybersecurity expert

ZDNET

In the last decade, spyware tools have been repeatedly found on the phones of journalists, activists, and politicians, including US officials, raising concerns over the unprecedented proliferation of spyware technologies and, subsequently, the lack of protections within the tech space amid growing threats.

Also: Google releases responsible AI report while removing its anti-weapons pledge

Last Friday, Meta’s WhatsApp revealed that it had discovered a hacking campaign targeting about 90 users, mostly journalists and civil society members across two dozen countries. According to a WhatsApp spokesperson, the Israeli spyware company Paragon Solutions — now acquired by Florida-based private equity firm AE Industrial Partners — was behind the attack.

What is a zero-click capability? 

Graphite, Paragon’s spyware, was found to have infiltrated WhatsApp groups by simply sending users a malicious PDF attachment. Without users’ knowledge, it can access and read messages on encrypted applications like WhatsApp and Signal.

This is also known as a zero-click attack, which means that targets do not have to take any actions for their devices to become compromised. In contrast, phishing or one-click attacks require user interaction with a malicious link or attachment. Once a phone is infected with a zero-click capability, the operator of the attack can secretly gain total access to the phone by exploiting a security vulnerability.

Also: How to turn on Private DNS Mode on Android – and why it’s a must for security

In an interview with ZDNET, Rocky Cole, co-founder of mobile threat protection company iVerify, said that “in the case of graphite, via WhatsApp, some kind of payload, like a PDF or an image, [was sent to the victims’ devices] and the underlying processes that receive and handle those packages have vulnerabilities that the attackers exploit [to] infect the phone.”

While public reporting does not specify “whether graphite can engage in privilege escalation [vulnerability] and operate outside WhatsApp or even move into the iOS kernel itself, we do know from our own detections and other work with customers, that privilege escalation via WhatsApp in order to gain kernel access is indeed possible,” Cole said.

iVerify has uncovered instances where “a number of WhatsApp crashes on [mobile] devices [they’re] monitoring with iVerify” have appeared to be malicious in nature, leading the iVerify team to believe that the malicious attacks are “potentially more widespread” than just the 90 people reported to have been infected by graphite.

While the WhatsApp attack was predominantly launched against members of civil society, mobile spyware is an emerging threat against everyone because mobile exploitation is more widespread than one might think, Cole said. Moreover, “the result is an emerging ecosystem around mobile spyware development and an increasing number of VC-backed mobile spyware companies are ‘under pressure to become profitable enterprises,'” he said.

This ultimately “creates marketing competition” for spyware merchants and “lowers barriers” that would deter these mobile exploitation attacks.

Also: The top 10 brands exploited in phishing attacks – and how to protect yourself

Just a month ago, WhatsApp won a lawsuit against NSO after a federal judge in California found that NSO was exploiting a security vulnerability within the messaging app to deliver Pegasus. The infamous NSO Group — known for infecting the phones of journalists, activists, and Palestinian rights organizations — has used similar zero-click capabilities through their Israeli-made Pegasus spyware, a commercial spyware and phone hacking tool.

Historically, the NSO Group has avoided selling to US-based clients and has also been banned by the US Commerce Department under the Biden administration for allegedly supplying spyware to authoritarian governments. However, “shifting political dynamics [under the Trump administration] raises the possibility that spyware may become more prevalent in the United States” — exacerbating mobile exploitation.

“And the world is totally unprepared to deal with that,” Cole said.

Best practices for protecting your device

Cole advises people to treat their phone like a computer. This means that, just as one would apply “a body of best practices that exist to protect traditional endpoints like laptops, from exploitation and compromise — those same standards and practices should just be applied to phones.” This includes rebooting your phone daily because “a lot of these exploits exist in memory only. They’re not files, and if you reboot your phone, in theory, you should be able to wipe the malware as well,” he said.

Also: Why you should power off your phone once a week – according to the NSA

However, Cole further notes that if it’s a zero-click capability like graphite or Pegasus, you can easily be reinfected, which is why it’s recommended to use a mobile security tool to know if you’ve been targeted. The iVerify mobile threat scanner for advanced mobile compromise costs just $1 and is easy to use. To learn how to download and test the app for yourself, see our guide on how to detect infamous NSO spyware on your phone.

You can also try lockdown mode if you’re using an Apple device. According to Cole, “lockdown mode has the effect of reducing some functionality of internet-facing applications [which can] in some ways reduce the attack surface to some degree.”

The only way to truly defend yourself against zero-click capabilities is to fix the underlying vulnerabilities. As Cole emphasized, this means only Apple, Google, and the app developers can do that, “so as an end user, it’s critically important that when a new security patch is available, you apply it as soon as you possibly can.”



Source link

Visited 1 times, 1 visit(s) today

Related Article

Samsung US brings back free storage upgrades for the Galaxy S25 series

Free storage upgrades are the usual perk that Samsung offers during pre-orders. Those are long behind the S25 series, but Samsung US decided to bring them back. The Samsung Galaxy S25 Ultra with 512GB storage costs $1,300 – that’s the MSRP of the 256GB model. Similarly, the 1TB model is $1,420, which is how much

Huawei Mate XT Ultimate in for review

We’ve had a few run-ins with the tri-folding Huawei Mate XT Ultimate but finally arrived at the office and we can now do a proper review on it. The unit’s here just a few days after it became a globally available phone – yes, you can buy one, in theory, but it’s expensive at €3,500

iPhone 16e appears on Geekbench with 8GB RAM

Apple kicked off pre-orders for its brand-new iPhone 16e today and the device was coincidentally spotted in a pair of certifications. The 16e appeared on Geekbench with the iPhone 17,5 alias, managing 2,706 single-core and 7,942 multi-core scores. The binned A18 chip inside the 16e delivers a 17% drop in single-core performance compared to the

Honor brings old Manchester United photos back to life with AI upscaling

The Honor Magic7 Pro comes with a suite of AI features, including Photo Upscale, which brings older photos back to life. In partnership with Qualcomm, the company demoed the feat in a promo celebrating the 115th anniversary of Old Trafford, the home of English football club Manchester United. The Before and After difference was revealed

Honor 400 series display specs leak, a slightly smaller size is coming

The Honor 400 series is allegedly coming around the middle of the year, which incidentally is also when the Honor Magic V4 should become official. Earlier this month, a leak told us what to expect from the Honor 400 devices in terms of chipsets, and today a new leak out of China brings more details

YouTube Premium Lite is making a comeback

Back in 2021, YouTube launched its €6.99 per month Premium Lite subscription plan across several European markets. That tier included ad-free viewing while omitting access to YouTube Music and background playback on mobile or offline downloads found in the standard tier Premium subscription. YouTube eventually retired the plan in 2023 but a new report from

Redmi K80 Ultra’s battery grows

Last we heard anything about it, the Redmi K80 Ultra was going to sport a battery capacity of at least 6,500 mAh. But that was in January. Today we have a new rumor out of China that narrows it down further. The K80 Ultra’s battery will be 7,400 mAh or 7,500 mAh, undoubtedly thanks to

Apple iPhone 16e pre-orders are now open

On Wednesday Apple introduced the iPhone 16e, which is its new entry level smartphone. Two days after the launch, the smartphone goes on pre-order in 59 countries and regions, including Australia, Canada, China, France, Germany, India, Japan, Malaysia, Mexico, South Korea, Türkiye, the UAE, the UK, and the US. The iPhone 16e has a binned

Canalys: Europe smartphone market grows after four years in decline

The smartphone market in Europe grew by 5% in 2024, following four consecutive years of decline. The announcement came from Canalys, which revealed the market saw just over 136 million devices shipped, with 30% of them being premium devices, priced $800 and above. Samsung remained a leader in 2024, but Apple recorded impressive Q4 2024

Nothing Phone (3a) and Phone (3a) Pro’s official renders surface

Nothing will launch the Phone (3a) and Phone (3a) Pro on March 4, and their official renders have surfaced online, giving us our best look yet at the two smartphones. Nothing Phone (3a) • Nothing Phone (3a) Pro The Nothing Phone (3a) and Phone (3a) Pro have displays on the front with

Apple says its C1 modem isn’t to blame for the iPhone 16e’s lack of MagSafe

The iPhone 16e became official yesterday, and it doesn’t have MagSafe. Some people have apparently claimed that the omission of MagSafe had something to do with Apple’s new in-house developed modem, the C1, which has made its debut with the iPhone 16e. That should sound far-fetched by default, and now Apple has confirmed that nothing

Amazon Appstore for Android will cease to exist in August

The Amazon Appstore for Android will be killed off on August 20, the company has officially announced today. Starting on that day, you will no longer have access to it on your Android device. It’s unclear what exactly will happen – will the app simply stop working or will it throw a notice that the

All iPhone 17 models to use Apple’s in-house Wi-Fi chip

Apple launched the iPhone 16e yesterday, and the device features Apple’s first ever self-developed 5G modem, replacing the Qualcomm modems in other iPhones. Apple will allegedly continue this trend of developing important connectivity chips in-house, and a new report today claims that the entire iPhone 17 family, coming this fall, will feature Apple’s first self-developed

Your Android phone could have stalkerware — here’s how to remove it

Consumer-grade spyware apps that covertly and continually monitor your private messages, photos, phone calls, and real-time location are an ongoing problem for Android users. This guide can help you identify and remove common surveillance apps from your Android phone, including TheTruthSpy, Cocospy and Spyic, among others. Consumer-grade spyware apps are frequently sold under the guise

Honor Magic V4’s launch timeframe leaks

Earlier today, Oppo made the Find N5 official as the new world’s thinnest single-folding / bi-fold foldable smartphone (the Huawei Mate XT is still thinner when unfolded, but that one folds twice or is “tri-fold” as they say). The Find N5 took the crown from the Honor Magic V3, but of course that device came

Oppo Find N5 review – GSMArena.com tests

Introduction The Oppo Find N5 is here, and we couldn’t be more excited. This is the foldable that promises to be revolutionary, or failing that, at least majorly evolutionary for the entire form factor. Indeed, even at first glance, it is striking just how thin this phone is. Oppo has pulled out some true technical

0
Would love your thoughts, please comment.x
()
x