You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

How to check and remove Pegasus Spyware from iPhone?

Please don't say iPhones are immune.

What's the best advice for checking iPhones for malware and removal options besides a factory restore (which I do every year).

And can iCloud store the malware so it can be reinstalled inadverently?


[Re-Titled by Moderator]

iPhone 12 Pro Max

Posted on Jul 19, 2021 5:49 AM

Reply
Question marked as Top-ranking reply

Posted on Jul 19, 2021 5:57 AM

If you sincerely believe your have it, force your phone into recovery mode and restore iOS using your computer. Do not restore a backup. Start from scratch.


7 replies

Jul 22, 2021 6:20 AM in response to Mate7000

Mate7000 wrote:

This is not about you are too important or not, it is about the vulnerability, the exploit which is available to install just by calling a number, if Pegasus can do, I am sure there would be many more to exploit this vulnerability. The point is if apple is not willing to fix then admit it publicly that our phones are just ordinary as others, the marketing gimmick of being the most secure phone should be stopped.


Log your feedback with Apple > https://www.apple.com/feedback/


In the interim, install iOS 14.7 and iPadOS 14.7.

Jul 20, 2021 1:42 PM in response to Dancin_Brook

I’d add to Mr Hoffman’s excellent analysis that preliminary information says that phones with US phone numbers cannot be infected by Pegasus, although there has been no information on why not.


Also, unless you fall into one of the target categories (journalist, government official, political activist, etc) the probability that you are targeted is close to zero (unless you live in Mexico). Remember that Pegasus is very expensive, in the hundreds of thousands of dollars. Are you really worth spying on that much?


The released information shows that up to 50,000 phones out of the over 3 billion smartphones in the world have been targeted. Based on that the probability of being a target is 0.002%, or 1 in 60,000. Your risk of getting COVID-19 is much higher that that, and is really what you should be concerned about.



Jul 19, 2021 7:07 AM in response to Dancin_Brook

Indications of compromise have not been published for the Pegasus malware, though press reports can be inferred to indicate that current apps and current software were not breached; this based on those reportedly targeted but not breached. The press reports of the Pegasus malware also indicated that infections were not persistent, but were re-introduced (as no-click exploits) as needed.


Patch to current, maintain current devices, restart.


Some information on how iPhone and iPad has been targeted have been published, and I’d expect Apple will be hardening those areas. Apple’s recently deployed “blast door” is relevant here, and I expect additional efforts will be made by Apple.


If you are a target of those with the budget for Pegasus or what other products we don’t yet know about, you will want to get explicit help with your security. This can include a number of techniques to reduce the value of your devices to those employing Pegasus, and to isolate sensitive information. The vast majority reading of those here are not targets. Criminals, political dissidents, investigative journalists, those with access to sensitive data or with access to substantial finances, are targets. As are their closest associates.


There will be increased advertising efforts toward for add-on apps that are seemingly little better than data collection packages, and for other add-on apps that cannot scan your devices for compromises, and the on-going efforts to phish our credentials and other information from us will continue apace, of course.


There was and is and will be no perfect security, and those with the budgets will continue to seek to compromise our devices, whether iPhone, iPad, macOS, Windows, Linux, or otherwise. We are already on an update treadmill with security and with security-related protocols including SSL/TLS connection security, and that treadmill will only continue.


Persistence past a reload has not been reported, and is rarely reported in other cases. Unfortunately, the no-click infections render reloading less than useful.


In short, there’s little any of us can do technically (for now), pending further information on Pegasus and/or fixes from Apple, beyond those of us that are targets partitioning our data and our activities and our device-equipped travels. This past robust and unique passwords, two-factor authentication, SSL/TLS/HTTPS everywhere, data hygiene, keeping current both with hardware and software, keeping sketchy apps off our devices, and with what Apple has previously published:


https://manuals.info.apple.com/MANUALS/1000/MA1976/en_US/device-and-data-access-when-personal-safety-is-at-risk.pdf


Same recommendations as before Pegasus became the centerpiece.


There will be much more happening here over the next weeks and months too, from Apple and elsewhere, as well as more information arising from press sources. And there will be the inevitable barrage of advertising around “security” apps, various of which are seemingly centrally data-harvesting or self-propagating advertising efforts.


I’ll likely publish a user tip with this and other info, as more info becomes available.

Jul 22, 2021 4:44 AM in response to Lawrence Finch

This is not about you are too important or not, it is about the vulnerability, the exploit which is available to install just by calling a number, if Pegasus can do, I am sure there would be many more to exploit this vulnerability. The point is if apple is not willing to fix then admit it publicly that our phones are just ordinary as others, the marketing gimmick of being the most secure phone should be stopped.

How to check and remove Pegasus Spyware from iPhone?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.