{"id":88233,"date":"2019-11-02T13:11:18","date_gmt":"2019-11-02T07:41:18","guid":{"rendered":"https:\/\/blogs_admin.quickheal.com\/?p=88233"},"modified":"2019-11-02T13:31:21","modified_gmt":"2019-11-02T08:01:21","slug":"infamous-spyware-pegasus-nso-group-whatsapp-snooping-saga","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/infamous-spyware-pegasus-nso-group-whatsapp-snooping-saga\/","title":{"rendered":"The infamous Spyware &#8211; Pegasus, The NSO Group and The WhatsApp snooping saga"},"content":{"rendered":"<p>The Indian media is abuzz these days with several news and allegations around snooping on several Indian citizens through a spyware named Pegasus, allegedly delivered through WhatsApp. It\u2019s reported widely that Facebook Inc., the parent company of popular messaging app -WhatsApp, reached out to few users from India (and other countries as well) informing about a possible snooping incident carried out on them for a short period of couple of weeks in early 2019.<\/p>\n<p><strong><b>What is being reported?<\/b><\/strong><\/p>\n<p>WhatsApp recently confirmed that it had informed several Indian users that they (their Mobile Phones) had been targeted by a Spyware named Pegasus. The victims mainly include several journalists, activists, lawyers and senior government officials and are believed to have been put on surveillance for couple of weeks in April\/May, 2019. Pegasus is a Spyware for mobile operating systems like Android, iOS and others. Pegasus is developed by the Israeli firm, NSO Group. There are news about WhatsApp\u2019s parent company, Facebook, filing a lawsuit against Israel\u2019s NSO Group alleging that NSO\u2019s spyware Pegasus infected the phones of some users after it was delivered through the WhatsApp messaging platform.<\/p>\n<p><strong><b>What is Pegasus and how it infects your Phone?<\/b><\/strong><\/p>\n<p>Pegasus, the Spyware for Mobiles, isn\u2019t really new. It first surfaced in mid 2016, and was believed to be targeting only iOS users. It used to enter Mobile phones through a malicious link and had capabilities to read text messages, track calls, collect passwords, gather data from other apps and collect geo-location of the phone. Pegasus came in news several times after that, with new functionalities and ability to infect Android and other Mobile Operating Systems.<\/p>\n<p>In May 2019, Facebook patched a critical remote buffer overflow vulnerability in WhatsApp, tracked as <a href=\"https:\/\/www.facebook.com\/security\/advisories\/cve-2019-3568\"><u>CVE-2019-3568<\/u><\/a>. \u00a0It\u2019s a vulnerability in WhatsApp VOIP stack that could allow remote code execution via specially crafted series of RTCP packets sent to a target phone number. It has been <a href=\"https:\/\/techcrunch.com\/2019\/05\/13\/whatsapp-exploit-let-attackers-install-government-grade-spyware-on-phones\/\"><u>reported<\/u><\/a>\u00a0that, attackers exploited this vulnerability in WhatsApp to infect victim\u2019s Mobile Phones with the infamous spyware Pegasus. This bug in the Audio\/Video call feature of vulnerable WhatsApp versions allowed the caller(Attacker) to install Pegasus spyware on the victim\u2019s device, irrespective of whether the call was answered or not. Facebook was quick enough to patch this vulnerability and alert users to update their apps to latest version.<\/p>\n<p>Possibly, there can be different ways through which Pegasus can infect your mobile phones and it\u2019s not just limited to a malicious link or a malicious call to the users running vulnerable versions of WhatsApp app. User\u2019s should be always alert while clicking on links received through messages, emails or any Social Media platforms and should refrain from installing apps from Third-party App Stores.<\/p>\n<p><strong><b>Quick Heal&#8217;s Detection:<\/b><\/strong><\/p>\n<p>Quick Heal Total Security for Mobile successfully detects Pegasus Spyware through different detections named as Android.Pegasus.A , Android.Chrysaor.A , and AndroidELF.Pegasus.A.<\/p>\n<p>Although researchers at Quick Heal\u00a0Security Labs are constantly on the lookout for malicious activities happening against Mobile Devices, prevention is always better than cure. Our modern world has absolutely brought mobile devices at the forefront of how we conduct our day to day lives. Communication, e-commerce, entertainment, logistics, even office work is all being conducted today via mobile devices. Evidently then, any type of breach to mobile devices personally used will bring life to a standstill, create panic and cause extreme inconvenience. To avoid this unpleasant scenario, leverage on<em><i>\u00a0<\/i><\/em><a href=\"https:\/\/www.quickheal.co.in\/home-users\/quick-heal-total-security-for-android\"><em><u><i>Quick Heal Total Security for Android<\/i><\/u><\/em><\/a><em><i>\u00a0\u00a0<\/i><\/em>and protect your Android based smart devices from all the known as well as emerging cyber threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Indian media is abuzz these days with several news and allegations around snooping on several Indian citizens through a spyware named Pegasus, allegedly delivered through WhatsApp. It\u2019s reported widely that Facebook Inc., the parent company of popular messaging app -WhatsApp, reached out to few users from India (and other countries as well) informing about [&hellip;]<\/p>\n","protected":false},"author":55,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55,1653,24,354,1513],"tags":[],"class_list":["post-88233","post","type-post","status-publish","format-standard","hentry","category-android","category-antivirus","category-malware","category-mobile-security-2","category-whatsapp"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/88233"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=88233"}],"version-history":[{"count":3,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/88233\/revisions"}],"predecessor-version":[{"id":88236,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/88233\/revisions\/88236"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=88233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=88233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=88233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}