VORANT. Threat Intelligence Sign in Get the full feed

ANSSI tracks Apple spyware threat notifications

elevated threat government-nationalmedianon-profit

CERT-FR catalogs Apple's ongoing mercenary spyware notification campaigns (Pegasus, Predator, Graphite, Triangulation) targeting high-profile individuals since 2021.

CERT-FR (ANSSI) has published an advisory consolidating Apple's threat notification campaigns, which alert iCloud users when their devices may have been targeted by state-sponsored or commercial spyware such as Pegasus, Predator, Graphite, or Triangulation. These tools are described as highly sophisticated, frequently leveraging zero-click or zero-day exploits, and are used to target journalists, lawyers, activists, politicians, senior officials, and executives in strategic sectors. Apple notifies affected users via iMessage and email from threat-notifications[at]email.apple.com or threat-notifications[at]apple.com, as well as an in-account alert, though the delay between compromise attempt and notification can span several months.

The advisory lists known notification waves tracked by CERT-FR from March 2025 through August 2026 (dates as published), noting the list is not exhaustive and only reflects campaigns known to the French CERT. It provides guidance for recipients of such notifications: contact CERT-FR promptly, preserve the notification email, and avoid resetting or modifying the device to preserve forensic evidence.

Mitigation recommendations include prompt patching and enabling automatic updates, using Apple's Lockdown Mode, separating personal and professional device use, regular reboots, strong unique passcodes, two-factor authentication, avoiding sideloaded apps and suspicious links, and for organizations, issuing dedicated managed devices and excluding personal electronics from sensitive meetings. The advisory serves primarily as an informational tracking resource rather than reporting a new incident.

Mentioned in this report

Malware GraphitePegasusPredatorTriangulation

Source reporting: https://www.cert.ssi.gouv.fr/cti/CERTFR-2025-CTI-010

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free