Why rebooting your phone daily is your best defense against zero-click attacks

Why you should treat your phone, like a computer, according to this cybersecurity expert

ZDNET

In the last decade, spyware tools have been repeatedly found on the phones of journalists, activists, and politicians, including US officials, raising concerns over the unprecedented proliferation of spyware technologies and, subsequently, the lack of protections within the tech space amid growing threats.

Also: Google releases responsible AI report while removing its anti-weapons pledge

Last Friday, Meta’s WhatsApp revealed that it had discovered a hacking campaign targeting about 90 users, mostly journalists and civil society members across two dozen countries. According to a WhatsApp spokesperson, the Israeli spyware company Paragon Solutions — now acquired by Florida-based private equity firm AE Industrial Partners — was behind the attack.

What is a zero-click capability? 

Graphite, Paragon’s spyware, was found to have infiltrated WhatsApp groups by simply sending users a malicious PDF attachment. Without users’ knowledge, it can access and read messages on encrypted applications like WhatsApp and Signal.

This is also known as a zero-click attack, which means that targets do not have to take any actions for their devices to become compromised. In contrast, phishing or one-click attacks require user interaction with a malicious link or attachment. Once a phone is infected with a zero-click capability, the operator of the attack can secretly gain total access to the phone by exploiting a security vulnerability.

Also: How to turn on Private DNS Mode on Android – and why it’s a must for security

In an interview with ZDNET, Rocky Cole, co-founder of mobile threat protection company iVerify, said that “in the case of graphite, via WhatsApp, some kind of payload, like a PDF or an image, [was sent to the victims’ devices] and the underlying processes that receive and handle those packages have vulnerabilities that the attackers exploit [to] infect the phone.”

While public reporting does not specify “whether graphite can engage in privilege escalation [vulnerability] and operate outside WhatsApp or even move into the iOS kernel itself, we do know from our own detections and other work with customers, that privilege escalation via WhatsApp in order to gain kernel access is indeed possible,” Cole said.

iVerify has uncovered instances where “a number of WhatsApp crashes on [mobile] devices [they’re] monitoring with iVerify” have appeared to be malicious in nature, leading the iVerify team to believe that the malicious attacks are “potentially more widespread” than just the 90 people reported to have been infected by graphite.

While the WhatsApp attack was predominantly launched against members of civil society, mobile spyware is an emerging threat against everyone because mobile exploitation is more widespread than one might think, Cole said. Moreover, “the result is an emerging ecosystem around mobile spyware development and an increasing number of VC-backed mobile spyware companies are ‘under pressure to become profitable enterprises,'” he said.

This ultimately “creates marketing competition” for spyware merchants and “lowers barriers” that would deter these mobile exploitation attacks.

Also: The top 10 brands exploited in phishing attacks – and how to protect yourself

Just a month ago, WhatsApp won a lawsuit against NSO after a federal judge in California found that NSO was exploiting a security vulnerability within the messaging app to deliver Pegasus. The infamous NSO Group — known for infecting the phones of journalists, activists, and Palestinian rights organizations — has used similar zero-click capabilities through their Israeli-made Pegasus spyware, a commercial spyware and phone hacking tool.

Historically, the NSO Group has avoided selling to US-based clients and has also been banned by the US Commerce Department under the Biden administration for allegedly supplying spyware to authoritarian governments. However, “shifting political dynamics [under the Trump administration] raises the possibility that spyware may become more prevalent in the United States” — exacerbating mobile exploitation.

“And the world is totally unprepared to deal with that,” Cole said.

Best practices for protecting your device

Cole advises people to treat their phone like a computer. This means that, just as one would apply “a body of best practices that exist to protect traditional endpoints like laptops, from exploitation and compromise — those same standards and practices should just be applied to phones.” This includes rebooting your phone daily because “a lot of these exploits exist in memory only. They’re not files, and if you reboot your phone, in theory, you should be able to wipe the malware as well,” he said.

Also: Why you should power off your phone once a week – according to the NSA

However, Cole further notes that if it’s a zero-click capability like graphite or Pegasus, you can easily be reinfected, which is why it’s recommended to use a mobile security tool to know if you’ve been targeted. The iVerify mobile threat scanner for advanced mobile compromise costs just $1 and is easy to use. To learn how to download and test the app for yourself, see our guide on how to detect infamous NSO spyware on your phone.

You can also try lockdown mode if you’re using an Apple device. According to Cole, “lockdown mode has the effect of reducing some functionality of internet-facing applications [which can] in some ways reduce the attack surface to some degree.”

The only way to truly defend yourself against zero-click capabilities is to fix the underlying vulnerabilities. As Cole emphasized, this means only Apple, Google, and the app developers can do that, “so as an end user, it’s critically important that when a new security patch is available, you apply it as soon as you possibly can.”



Source link

Visited 1 times, 1 visit(s) today

Related Article

Oppo Find N5 review – GSMArena.com tests

Introduction The Oppo Find N5 is here, and we couldn’t be more excited. This is the foldable that promises to be revolutionary, or failing that, at least majorly evolutionary for the entire form factor. Indeed, even at first glance, it is striking just how thin this phone is. Oppo has pulled out some true technical

vivo V50 in for review

vivo unveiled the V50 earlier this week at an event in New Delhi, India, making it vivo’s first big launch of 2025. The vivo V50 is yet to go on sale, but we’ve received the phone for review, so let’s take a quick look at what it has to offer before we put it through

vivo X200 Ultra to get a new Action Button

The vivo X200 Ultra is expected to launch in China in mid to late April alongside the X200s, as a recent rumor told us. Today a new intriguing detail about the X200 Ultra has surfaced on Weibo. Namely, that it will have a new Action Button, placed on the lower part of the right frame.

Oppo Watch X2 announced as a rebadged OnePlus Watch 3

Oppo held its big launch event for the Find N5 today and there was a second device that got announced on stage – the Oppo Watch X2. If it looks familiar, that’s because the Watch X2 is nothing more than a rebadged OnePlus Watch 3 which launched earlier this week. Oppo Watch X2

Sony Xperia 1 VII to get Exmor T sensors for all cameras

Sony is anticipated to enhance the camera experience on the Xperia 1 VII greatly. Sources indicated it will incorporate the Exmor T sensor across all three rear cameras, an upgrade from last year’s model, which featured this sensor only on the primary camera feature. The Exmor T is the latest stacked CMOS sensor by Sony

The Golden Era of Mobile Gaming Has Arrived: The REDMAGIC Golden Saga Edition

Gaming isn’t just about playing—it’s about living the experience. It’s about transcending the boundaries of what’s possible. And REDMAGIC, the leader in mobile gaming technology, has taken this philosophy to the next level with the Golden Saga Limited Edition. The Golden Saga Edition takes the already impressive REDMAGIC 10 Pro and adds a layer of

Oppo Find N5 debuts as the slimmest foldable yet

The race to launch the slimmest foldable continues and Oppo just got in the lead. We’ve seen plenty of phones that employed innovative designs and reorganized internal structures to reach bar phone territory and the Oppo Find N5 is the slimmest offering to date. Coming in as the highly anticipated successor to the Find N3,

Here are the official Apple iPhone 16e cases

Apple introduced the iPhone 16e yesterday and launched a new line of official cases alongside it. These cases come in five colors: Lake Green, Fuchsia, Winter Blue, White, and Black, and they are made from silicone. Apple iPhone 16e cases None of the cases include MagSafe since the iPhone 16e lacks

vivo Y29 gets a 4G version with a bigger battery

The vivo Y29 was announced in the final days of 2024 with a 5G chipset and a 5,500 mAh battery. Now the phone gets a second version with an LTE-only chip and a bigger cell that’s already on sale Bangladesh. The vivo Y29 4G keeps the 6.68″ LCD with a 720p resolution and 120 Hz

iPhone 16e has a binned A18 chip

The brand-new iPhone 16e is the fourth and least expensive member of the iPhone 16 series. Reaching the $599/€699/£599 starting price required some resourcefulness and it’s now confirmed that the A18 chip inside the 16e is not on par with the one used in the regular iPhone 16. As per the official specs from Apple,

Tecno expands Universal Tone, confirms Camon 40 series launch date

Universal Tone is Tecno’s proprietary tech that aims to ensure a correct representation of people from all skin tones in the photos taken by its cameras. Now the company announced it is improving the it with an expanded color card. The first phones to implement the richer set are the Camon 40 series, set to

Mobile Phone Rental Market Projected To Witness Massive Growth,

Mobile Phone Rental Market The Mobile Phone Rental Market is estimated to reach approximately USD 9.45 billion by 2025 and is projected to grow significantly, reaching around USD 18.32 billion by 2032. The “Mobile Phone Rental Market Report” is the result of extensive research and analysis conducted by our team of experienced market researchers through

This is when iOS 18.4 is coming with new Apple Intelligence features

The next batch of Apple Intelligence features will arrive as part of the update to iOS 18.4 and iPadOS 18.4. Today, Apple has updated its official pages for iOS 18 and iPadOS 18, and revealed when the 18.4 versions are dropping. It’s going to happen in early April. At that point, Apple Intelligence will add

Google brings Circle to Search to Chrome and the Google app on iOS

Google is bringing Circle to Search to Chrome and the Google app on iOS, but it isn’t calling it that for whatever reason. Instead, it’s “Search Screen with Google Lens”. This will show up as an option in the three-dot menu in both Chrome for iOS and the Google app for iOS. Once you select

Samsung Galaxy S25 Edge’s back panel will be different

Samsung teased the Galaxy S25 Edge at its Unpacked event last month, and various rumors have claimed the device would launch around April. Ahead of that, today a new report tells us what to expect from it in terms of materials used. The frame will be aluminum, apparently, which isn’t that much of a surprise,

Nothing Phone (3a) Pro runs Geekbench, reveals its chipset

Nothing is launching the Phone (3a) series on March 4, and according to past rumors we’re getting two devices – the Phone (3a) and Phone (3a) Pro. The latter has now been spotted in the Geekbench online database, with the model number A059P (the non-Pro is the A059, hence the “P” suffix stands for “Pro”

Inside a school without cell phones as Minneota Legislature considers ban

Minnesota Congressional leaders on both sides of the aisle are in agreement on at least one issue: cell phones in schools. U.S. Reps. Pete Stauber (R) and Kelly Morrison (DFL) are co-authors of a bipartisan bill to study the impacts of using phones in class and provide schools with secure containers for phones. “We’re all

0
Would love your thoughts, please comment.x
()
x