HeadFlash

Topic · 16 stories

Spyware: mobile surveillance tools and news

Updated · Edited by Marcin Rybak

In short

Spyware is software that secretly monitors a device and sends data from it to someone else, from commercial government tools like Pegasus to stalkerware and infostealers. In 2026 Amnesty and Citizen Lab documented Pegasus in Morocco, Serbia and against a member of the European Parliament, and iVerify found a new DarkSword variant, P7, hitting unpatched iPhones. Advanced spyware is rarely visible to the user, so updates and protection modes matter most.

What is spyware and what does it do

Spyware is software that secretly monitors a device and sends data from it, such as messages, location, passwords, screen content and sometimes microphone audio, to someone else. It gets onto a device through a malicious link, a fake app, a malicious ad or an exploit, then runs hidden. The name covers very different tools: commercial systems for governments such as NSO Group’s Pegasus, nation-state malware, Android trojans, infostealers, and stalkerware, which is used to track a partner or relative. What they share is concealment from the device’s owner.

The topic came back in 2026 from several sides at once. Amnesty and Citizen Lab documented Pegasus in Morocco, Serbia and against a member of the European Parliament, iVerify described a new DarkSword variant hitting unpatched iPhones, and agencies from three countries warned about an Iranian spying tool for Windows. Much of this arrives through phishing or exploits, including zero-day vulnerabilities.

Types of spyware: Pegasus, state malware, trojans, infostealers and stalkerware

The main types are commercial spyware, state malware, Android trojans, infostealers and stalkerware.

Type Who uses it How it reaches the device 2026 example
Commercial spyware state agencies, NSO clients zero-click exploit or phishing link Pegasus
State malware intelligence services targeting dissidents social engineering over WhatsApp and Telegram, fake apps CHOSEN BRICK
Android trojans and RATs criminals APKs from outside the store, fake apps ToxicPanda 2.0, SpyNote with WindRelay
Infostealers criminals ClickFix, malicious ads, fake sites Dolphin X, ClickLock
Stalkerware an abusive or controlling person installation hidden from the victim no prominent case in the 2026 stories

What is Pegasus and who uses it

Pegasus is the best-known commercial spyware, made by Israel’s NSO Group and sold to state clients. Amnesty’s analysis says it can intercept cloud data, remotely switch on the microphone and camera, and track location, and that its infection vectors evolved from early BlackBerry attacks to iOS zero-click exploits such as FORCEDENTRY. Amnesty Security Lab showed that NSO itself builds and operates Pegasus infrastructure, including the PATN anonymization network, and that a White Services team registers separate attack accounts for each client, which lets attacks be attributed. That contradicts NSO’s earlier denials, because test data from NSO’s internal dashboards matches the Pegasus Project list.

2026 cases:

  • Morocco. An Amnesty report documents that Morocco surveilled civil society for years with Pegasus between 2017 and 2021, possibly continuing afterwards. The investigation was led by journalist Hicham Mansouri, whose own device was infected, together with Forbidden Stories and 39 journalists from 14 outlets. Morocco’s government denies it.
  • Serbia. Citizen Lab and Amnesty confirmed on 2 September that Serbia used Pegasus with an iMessage zero-click exploit against at least 14 people in the student movement, civil society and the opposition. Apple patched the flaw in iOS 18.4.1. Phones also carried NoviSpy, installed when police or services seized devices using Cellebrite; in one case private messages were read out on pro-government TV. It is the third documented campaign against Serbian civil society in under three years.
  • European Parliament. Citizen Lab revealed that former MEP Stelios Kouloglou was repeatedly infected with Pegasus while serving on the PEGA committee, in October 2022 and March 2023, through the PWNYOURHOME zero-click exploit in HomeKit, patched in iOS 16.3.1. Citizen Lab did not name the culprit but noted the operator must have held a licence to operate in multiple EU countries.
  • Legal fight. Meta filed on 8 June to hold NSO in contempt of court. The case dates to 2019, when Pegasus compromised over 1,400 devices via WhatsApp. In December 2024 a court found NSO liable under the Computer Fraud and Abuse Act, ordered about $4 million and issued a permanent injunction. Meta says NSO now runs spear-phishing campaigns based on social engineering rather than WhatsApp flaws.

What new spyware appeared in 2026

The newest cases are P7 DarkSword on iPhones, CHOSEN BRICK on Windows, and ToxicPanda 2.0 and WindRelay on Android.

DarkSword P7. iVerify found the variant in August 2026 while analyzing the infected phone of a financial-institution employee. P7 supports iOS 18.7 (the earlier version supported iOS 18.6), spreads through malicious ads in watering-hole attacks so victims need not be individually chosen, extracts Keychain data on the device, targets crypto wallets and checks its command server every 15 seconds. The new variant affects unpatched iPhones. It is not a new iOS flaw but a new version of malware deployed after a successful DarkSword infection.

CHOSEN BRICK. The NCSC, FBI and AIVD issued a joint warning about an Iranian spying tool used against dissidents, activists and journalists in the US, UK and Netherlands. The attack starts with a WhatsApp or Telegram message from a supposed trusted contact or tech support; the file poses as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player or KeePass. The malware runs only on Windows, survives restarts, adds Microsoft Defender exclusions and gives each victim a separate Telegram bot. It steals contacts, mailboxes, messages, the screen and microphone audio. One lure was a fake MRI result sent after gaining trust; victims in three countries go back to at least 2025. More in state-sponsored hacking.

Android. Zimperium described ToxicPanda 2.0, which uses VPN permissions to block Google Play and Play Protect and then asks for Accessibility Service permissions. It supports 167 commands, overlays fake login screens on 349 banking and crypto apps in 16 countries and collects PINs from over 140 apps. Group-IB described WindRelay, used with the SpyNote RAT to steal card data over NFC: a fraudster posing as a bank employee got the victim to sideload SpyNote, and the whole operation took 13 minutes. The samples mostly targeted Czechia, Slovakia and Slovenia.

Is an infostealer also spyware

In practice yes: an infostealer is spyware aimed at passwords and sessions, used for profit rather than intelligence. Anthropic’s warning that infostealers hijacked Claude sessions and drained users’ limits showed how. The malware can copy an already authenticated browser session, so the attacker needs neither the password nor a second factor. Anthropic logs affected users out, removes saved payment methods and refunds unauthorized charges. See Claude.

More 2026 examples:

For the wider picture see malware and infostealers.

How to check for spyware on iPhone and Android, and how to prevent it

Advanced spyware such as Pegasus usually cannot be found by the user: it takes forensic analysis or a warning from the system maker. Apple sends threat notifications to users who may have been individually targeted by mercenary spyware. According to Apple’s support page (as of 10 October 2026), these are high-confidence alerts, sent since 2021 in over 150 countries. They appear on the lock screen and in Settings, by email and as a banner on account.apple.com. A real notification never asks you to click a link, open a file or install an app. Apple suggests getting expert help, for example from Access Now’s Digital Security Helpline.

What reduces the risk:

  • Updates. The exploits in Serbia and in the PEGA case were patched in iOS 18.4.1 and 16.3.1, and P7 DarkSword works on unpatched iPhones.
  • Lockdown Mode on iOS. Apple describes it as an option for the very few people who may be personally targeted by sophisticated attacks. It blocks most message attachment types, links and link previews, some complex web technologies, FaceTime calls from people you have not called, and configuration profiles. Turn it on under Settings, Privacy & Security, Lockdown Mode. Experts recommend it together with Advanced Protection on Android.
  • Google Advanced Protection. According to Google’s page (as of 10 October 2026) it requires a passkey or security key and restricts app installs to trusted stores.
  • No APKs from outside Google Play. Experts advise this after the WindRelay attack, along with caution toward apps requesting NFC access.
  • Stalkerware. The Coalition Against Stalkerware (as of 10 October 2026) advises removing it only if that is safe, because removal can alert the abuser and delete evidence, and asking for help from a device the abuser never had access to.

What it means for you

  • Update iOS and Android as soon as patches ship. Every iPhone exploit described here had a fix.
  • Do not install files from WhatsApp or Telegram links, even from a friend, and do not paste commands from fake CAPTCHA checks.
  • If you are a journalist, activist or politician, turn on Lockdown Mode or Advanced Protection and treat an Apple threat notification seriously.
  • If you suspect an infostealer, sign out of all sessions, change passwords from a clean device and check payment methods on your accounts.

Still open: who stood behind the attack on the MEP and in which EU countries, whether Morocco’s attacks continued after 2021, and whether the court will find NSO in contempt in Meta’s case.

Key facts

  • iVerify disclosed P7 DarkSword, a variant of malware deployed after a DarkSword exploit-chain infection. It supports iOS 18.7, spreads through malicious ads and targets unpatched iPhones. (source)
  • An Amnesty report documents Moroccan authorities using Pegasus against civil society from 2017 to 2021, with possible continuation afterwards. Morocco's government denies the accusations. (source)
  • The NCSC, FBI and AIVD warned of Iran's CHOSEN BRICK malware for Windows, used against dissidents and journalists, including a fake MRI result as a lure. (source)
  • Serbia used Pegasus with an iMessage zero-click exploit against at least 14 people in the student movement and civil society. Apple patched the flaw in iOS 18.4.1. (source)
  • Anthropic warned that infostealer malware hijacked active Claude sessions. It logs affected users out, removes saved payment methods and refunds unauthorized charges. (source)
  • The ToxicPanda 2.0 Android banking trojan blocks Google Play via VPN permissions, supports 167 commands and overlays fake screens on 349 apps in 16 countries. (source)
  • Amnesty Security Lab showed NSO Group builds and operates Pegasus infrastructure itself, including the PATN anonymization network and a White Services team that lets attacks be attributed to clients. (source)
  • Meta asked a court on 8 June to hold NSO in contempt, alleging it violated a permanent injunction on targeting WhatsApp users issued after a December 2024 ruling. (source)

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. New DarkSword Variant P7 Targets Unpatched iPhones via Malicious Ads Security
  2. Amnesty documents Morocco’s Pegasus campaign against civil society Security
  3. US, UK and Dutch agencies warn on Iranian CHOSEN BRICK spyware Security
  4. Iran-Linked Hackers Use CHOSEN BRICK Malware Against Dissidents Security
  5. Serbia Used Pegasus Zero-Click Exploit on Student Activists; Apple Patches iOS 18.4.1 Security
  6. Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions to Drain Usage Security
  7. New WordlistLoader Malware Uses Plain English Words to Hide Amatera Infostealer Security
  8. ToxicPanda 2.0 Android Trojan Uses Fake VPN Prompt to Disable Google Play Protect Security
  9. Hackers Hide Malware Commands in FTP Server Banners Security
  10. ToxicPanda Android Malware Evolves to Block Google Play With VPN Permissions Security
Show older (6 stories)
  1. Android NFC relay malware WindRelay combined with SpyNote drains victims in 13-minute calls Security
  2. ClickLock Mac Malware Locks Apps Until Users Give In Security
  3. Dolphin X Infostealer Targets Over 300 Apps and Uses AI to Profile Victims Security
  4. Inside Pegasus: Amnesty Reveals Evolution of NSO’s Spyware System Privacy
  5. Pegasus Spyware Infects MEP Investigating Spyware Security
  6. Meta Files Contempt Complaint Against NSO Group for Violating Court Order Privacy

FAQ

What is spyware?

Spyware is software that secretly monitors a device and sends data from it, such as messages, location, passwords or screen content, to someone else. It ranges from commercial government tools like Pegasus to nation-state malware, Android trojans, infostealers and stalkerware.

How does spyware work?

Spyware gets onto a device through a malicious link, a fake app, a malicious ad or an exploit, then runs hidden and sends data out. Pegasus can read cloud data, turn on the microphone and camera remotely, and track location, and DarkSword P7 pulls Keychain data and checks its server every 15 seconds.

How to check for spyware on an iPhone?

There is no reliable self-check for advanced spyware. Apple sends threat notifications to users who may have been individually targeted by mercenary spyware, by lock screen alert, email and a banner on account.apple.com (as of 10 October 2026). Verify by signing in to account.apple.com yourself, never through a link.

How to detect spyware on an Android phone?

Look for hidden apps and apps installed outside the official store, the main signs of stalkerware according to the Coalition Against Stalkerware. Banking trojans like ToxicPanda 2.0 ask for VPN and Accessibility permissions. Advanced tools may leave no visible sign, so keep the system updated.

How to remove spyware?

It depends on the type. For stalkerware, the Coalition Against Stalkerware says a new phone is best and a factory reset is almost as effective, but only if it is safe, because removal can alert the abuser and delete evidence. For ClickLock on a Mac, Group-IB advises a forced shutdown, Safe Mode and contacting Apple Support.

How to prevent spyware?

Update your operating system right away, because the Serbian Pegasus exploit was fixed in iOS 18.4.1 and DarkSword P7 targets unpatched iPhones. Avoid APK files from outside Google Play, never paste commands from fake CAPTCHA pages, and consider Lockdown Mode on iPhone or Advanced Protection on Android if you are at higher risk.