Skip to main content

PEGASUS



PEGASUS

Developed by Israeli Cyber Warfare vendor NSO groups, Pegasus spyware was designed to be installed on phones without actually being in knowledge of target. Pegasus attack has been the most sophisticated smartphone attack till date in cyber-attacks history.
Recently the spyware has targeted 1400 civil right activists, lawyers and journalists across the globe including in India. Pegasus at a time can attack 50 phones in just one go. It is used by many governments to combat in terror related activities.


HOW IT WORKS?
Pegasus used or rather reverse engineered the messaging app Whatsapp and developed a program that copied Whatsapp network traffic to target devices.

Zero Day Attacks
The spyware exploit vulnerable software. They require no interactions from users instead they attack the target in form of calling from unknown numbers and the no. disappeared from the call logs, leaving no records of missed calls.

Spear Phishing Attacks
Attackers create tailor made messages that are sent to specific targets. These messages convey a sense of urgency and contain a link or a document these prompts to be from local news or embassy, opening it leads to installation of spyware on phones.



THE VULNERABILITES IT CREATES
It generally generates 3 types of vulnerabilities in its targeted devices:
  1. CVE-2016-4655: Information leak in Kernel – A kernel base mapping vulnerability that leaks information to the attacker allowing them to calculate the kernel’s location in memory.
  2. CVE-2016-4656: Kernel Memory corruption leads to Jailbreak – 32 and 64 bit iOS kernel-level vulnerabilities that allow the attacker to secretly jailbreak the device and install surveillance software - details in reference.
  3. CVE-2016-4657: Memory corruption in the Webkit – vulnerability in the Safari WebKit that allows the attacker to compromise the device when the user clicks on a link.



HOW IT THREATENS YOUR PRIVACY
It includes reading of text, messages tracking calls, collecting passwords of the target device. It can also remotely activate your camera and microphones to surveil the target and their surroundings.

Interesting to know they survive reboots and themselves factory reset operating systems. They can only be detected by tech experts.
Measures one must take if they believe they have been targeted
·       Stop using device.
·       Log out all accounts unlink from all devices.
·       From different device change all your passwords.
·       Seek digital security advice.



Comments

Popular posts from this blog

Unhackable Internet

  W hy it matters?   The internet is increasingly vulnerable to hacking; a quantum one would be unhackable. Quantum Computing    A quantum internet could be used to send unhackable messages, improve the accuracy of GPS, and enable cloud-based quantum computing. For more than twenty years, dreams of creating such a the quantum network have remained out of reach in large part because of the difficulty to send quantum signals across large distances without loss.   Now, Harvard and MIT researchers have found a way to correct for signal loss with a prototype quantum node that can catch, store and entangle bits of quantum information. The research is the missing link towards a practical quantum internet and a major step forward in the development of long-distance quantum networks.   The U.S Department of Energy (DoE) explains how a quantum link will make it happen through two quantum phenomenon: the first is quantum entanglement, where two-particle ...

Impact of Social Media on Business

Watch out for that bird! Imagine you are skydiving, you are visiting one of the most beautiful countries in the world and you want to share that experience with your loved ones and friends. Why not send a postcard? Oh wait, you’re already back from the trip by the time that postcard has reached, or it got lost in the mail. If only there was an alternative. This isn’t 1990. You have a platter of platforms to share your adventure. Webster’s dictionary defines social media as-“ forms of electronic communication (such as websites for social networking and microblogging) through which users create online communities to share information, ideas, personal messages, and other content (such as videos).”In simple words, social media, are various public platforms where people can share their views, stories, etc. with the help of various mediums. Starting with websites such as MySpace, Orkut, and Facebook, etc. it is now estimated that there are about 200 social media websites in ...

Pegasus Spyware: Flying Through The Air

 Hundreds of millions of people can't imagine life without their smartphones. Almost every aspect of their daily lives, from the most mundane to the most intimate, is within easy reach and hearing distance of their smartphones. Only few people realize that their phones may be used as surveillance devices, with someone hundreds of miles away secretly extracting their messages, photographs, and location while also activating their microphone and recording them in real time. Such capabilities are present in Pegasus, a spyware produced by NSO Group, an Israeli maker of mass surveillance weapons. What is Pegasus? Pegasus is a hacking software – or spyware – that is developed, marketed and licensed to governments around the world by the Israeli company NSO Group. It has the capability to infect billions of phones using either iOS or Android operating systems. The spyware is named after Pegasus, the white winged horse from Greek mythology. It is named so because it "flies through the...