Update — the non-negotiable baseline
Every named chain in this archive was patched on the date given. The Serbia case (Citizen Lab + SHARE, 2 September 2026) is a direct lesson: a high-confidence infection window of December 2025–January 2026 on a phone that was patched in iOS 18.4.1. An un-updated phone stays exposed to known, patched chains for as long as it stays un-updated.
Apple Lockdown Mode
Lockdown Mode reduces attack surface by blocking most message attachment types and complex web features. BLASTPASS (September 2023) showed it is not a guarantee — that chain affected Lockdown Mode targets — but it has blocked some later chains in Citizen Lab reporting. It is recommended for high-risk users: journalists, activists, lawyers, officials, and relatives of targets.
Apple threat notifications
Apple sends high-confidence mercenary-spyware warnings to accounts it assesses as targeted. These are not proof of infection by themselves. A recipient who needs forensic evidence should not factory-reset before a forensic image is made.
Forensic checks: MVT and iVerify
Amnesty's Mobile Verification Toolkit (MVT) parses a device backup for indicators of compromise and is the public method used by researchers. iVerify and similar commercial scanners are optional tools, not guarantees. A critical caveat: absence of indicators is not proof of cleanliness, because zero-click implants can self-delete and logs rotate.
If you are notified
- Update the device immediately.
- Enable Lockdown Mode.
- Contact a trusted digital-security lab (Access Now helpline; local groups such as SHARE).
- Preserve the device if legal evidence matters — do not wipe it.
- Keep iOS and Android fully updated. Historical chains died on the patch day; the Serbia case shows un-updated phones remain exposed months after a patch (iOS 18.4.1 patch vs December 2025 infection).
- Enable Apple Lockdown Mode if you are a high-risk user. It reduces attack surface — blocks most message attachment types and complex web features. BLASTPASS showed it is not magic, but it has blocked some later chains in Citizen Lab reporting.
- Take Apple threat notifications seriously. They are high-confidence mercenary-spyware warnings — but not proof of infection by themselves.
- If you need forensic evidence, do not factory-reset before a forensic image is made.
- Talk to a trusted digital-security lab. Citizen Lab does not take every case; Access Now helpline and local groups such as SHARE are public routes.
- Do not rely on ordinary antivirus as a sole control.
- Do not rely on 'click nothing' as a sole control — zero-click needs no click.
- Do not assume Signal or WhatsApp encryption stops a post-decrypt implant.
- Do not treat absence of indicators as proof of cleanliness — zero-click implants can self-delete and logs rotate.
- Do not wipe a high-risk phone before consulting a forensic lab if the device may be evidence.

