What are Pegasus and Trident Spyware?

You may have seen recent Indian news about Israeli spyware called Pegasus, and about Trident. India’s opposition party accused Prime Minister Sri Narendra Modi of misusing this spyware. As per the news, more than 1,000 phone numbers in India were among nearly 50,000 selected worldwide as possibly of interest to clients of the Israel-based NSO Group, the maker of Pegasus spyware.

We’re not going to get into the politics here. This is about spyware itself, and how it works.

Spyware in plain terms

Spyware is software built to quietly collect information about a person or organization without their knowledge or consent. It can get onto a computer or mobile device in a few ways, including malicious software downloads, compromised websites, or infected email attachments.

Once it’s installed, spyware can do a lot. It may collect and send sensitive personal information, including login credentials and financial data. It can track someone’s internet activity and location, and it can also show unwanted pop-up advertisements.

Spyware is often hard to detect and remove, mostly because it’s designed to sit quietly in the background and avoid being noticed. Protection isn’t always simple either, since it can arrive through sources that look legitimate, like email attachments or downloads from trusted websites. A reputable antivirus program helps. So does being careful before downloading software or opening attachments from unknown sources.

Usually, planting spyware on someone’s device needs physical access. But more advanced spyware, like “Pegasus,” can be injected through exploited vulnerabilities in the device system or through phishing techniques. Normal spyware can often be found by common spyware scanners. The more advanced kind is different, because it gets mixed into system files and stays hidden.

Trident vulnerabilities

Every system has some weak points. Apple iOS previously had a “Zero Day” vulnerability. These security drawbacks or vulnerabilities are called “Trident”. Pegasus spyware uses these Trident vulnerabilities to infect the target device. The damage can be serious, including data loss, and it can access messages, call logs, audio, emails, logs, and private app data, including data from end-to-end encrypted applications.

Pegasus spyware

Pegasus is spyware developed and sold by the Israeli cyber intelligence company NSO Group. It’s a highly sophisticated piece of malware made to infect and take control of a target’s smartphone or another mobile device. Once installed, Pegasus can intercept text messages, phone calls, and emails. It can turn on the device’s microphone and camera to record audio and video, and it can track the device’s location.

Pegasus is usually delivered to a target’s device through a phishing attack or another social engineering method. It can also avoid detection by security software. It has been used to target journalists, human rights activists, and other high-profile individuals in a number of countries around the world.

The controversy around Pegasus comes from its use by governments and other organizations for surveillance, and for targeting people for political or other reasons. Pegasus and spyware like it have raised serious privacy concerns, along with worries about how easily these tools can be abused.

Pegasus is a spyware program and spying tool owned by NSO Group. It is an Israeli technology firm. The tool allows remote surveillance of smartphones, secretly opens the contents of a target’s mobile phone, and turns that phone into a listening device. Lookout and Citizen Lab uncovered an active, targeted mobile spyware threat called Pegasus.

After those findings, Lookout worked with Apple’s security team to patch all three Trident iOS vulnerabilities in Apple’s 9.3.5 update.

Who attackers usually target

High-value targets are the usual focus for this spyware. That includes political activists, military personnel, company CEOs, corporate individuals, media workers, and opposition members.

As TechCrunch writes, “Apple zero-days mark a new era of mobile hacking.” Pegasus is the most sophisticated attack we’ve seen on any endpoint because it takes advantage of 1. how integrated mobile devices are in our lives, and 2. the combination of features available only on mobile devices, including always-connected access, voice communications, camera, email, messaging, GPS, passwords, and contact lists. It also includes information that could be answers to your security questions, like birthdays, addresses, and children’s information.

The latest exploit?

India’s main opposition Congress party has accused Prime Minister Narendra Modi of “treason” and compromising national security after revelations that dozens of Indians were potential targets of snooping by Israeli-made spyware. In this scandal, lots of names are released by the media groups. The list includes opposition leader Mr. Rahul Gandhi. Still, it isn’t clear whether his phone was hacked or not.

Common people don’t need to worry too much about Pegasus and Trident vulnerability, since targeting someone with these advanced systems costs a lot. Spying on everyone is outside its budget. But if you fall into one of those target categories, it’s better to get your phone checked by a security expert.

Staying safer

For now, this Pegasus & Trident scam is related only to Apple and WhatsApp exploits, which are now fixed. In the future, the best way to stay safer from this kind of spyware is to be very careful before handing your device to someone. Don’t open links or files from untrustworthy senders. And don’t install unknown random applications on your device.

Leave a Comment

Related Posts