
Global Surge in Mercenary Spyware: Apple Issues Urgent Alerts to Targets Across 110 Countries
Apple has intensified its security efforts, issuing urgent notifications to users in 110 countries regarding potential mercenary spyware infections. These sophisticated, state-sponsored-grade attacks continue to target high-profile individuals, including journalists and diplomats.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Apple Threat Intelligence
- Read Time:
- 4 min
Executive Summary
As of September 2026, the global landscape for mobile surveillance has reached a critical inflection point. Apple has confirmed a massive, ongoing campaign involving mercenary spyware, resulting in threat notifications being sent to users across 110 countries. This development underscores the escalating capabilities of private exploit brokers who provide nation-state-grade surveillance tools to various actors, bypassing traditional security perimeters.
Threat Analysis
Mercenary spyware represents a unique threat vector where private entities develop and sell zero-click exploits to government and non-government actors. Unlike traditional malware, these tools are designed for surgical precision, targeting specific individuals such as activists, journalists, and political figures. The recent surge in notifications suggests that exploit brokers have successfully weaponized new chains of vulnerabilities, likely targeting the latest iterations of iOS. The anonymity provided by these brokers allows the ultimate end-users to maintain plausible deniability while conducting invasive surveillance.
Technical Details
Recent intelligence indicates that these campaigns often utilize zero-click exploit chains that require no user interaction to execute. Once the payload is delivered—often via compromised messaging services or malicious links—the spyware gains kernel-level access to the device. This allows for the exfiltration of encrypted communications, real-time location tracking, and the activation of microphones and cameras. The sophistication of these tools, such as those seen in the 'Coruna' exploit kit, demonstrates a modular approach, allowing attackers to swap exploit chains dynamically to evade detection by Apple’s internal security telemetry.
Attribution Assessment
Attribution remains complex due to the 'middleman' nature of the mercenary spyware market. While Apple does not publicly attribute these attacks to specific nation-states to prevent attackers from refining their evasion techniques, the profile of the targets—diplomats, human rights defenders, and political dissidents—strongly aligns with the interests of authoritarian regimes and state-sponsored intelligence agencies. The involvement of private firms, similar to the NSO Group or the recently sanctioned entities like Emennet Pasargad, remains the primary mechanism for the proliferation of these capabilities.
Implications
The widespread nature of these alerts indicates that the barrier to entry for high-end cyber espionage has significantly lowered. As private companies continue to commoditize zero-day vulnerabilities, the risk to civil society and democratic institutions increases. The ability to compromise devices remotely without user interaction renders standard security hygiene insufficient, necessitating a shift toward hardware-level security and advanced behavioral analytics.
Recommendations
- Enable Lockdown Mode: Users identified as high-risk should immediately enable Apple’s 'Lockdown Mode' to restrict device functionality and reduce the attack surface.
- Verify Notifications: Ensure all threat alerts are received via official channels (threat-notifications@email.apple.com) and avoid clicking any links in suspicious messages.
- Device Hygiene: Regularly update iOS to the latest version to ensure all known security patches are applied.
- Operational Security: High-risk individuals should consider using secondary, hardened devices for sensitive communications and avoid storing sensitive data on primary mobile handsets.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Escalating Pegasus Deployments: New Zero-Click Campaigns Target Civil Society in Serbia

Global Surge in Mercenary Spyware Alerts: Apple Warns Users Across 110 Countries

