“Mercenary spyware” is the term security researchers use for high-end, for-hire surveillance tools sold to governments and deployed against specific people. While everyday malware typically chases big numbers, this kind of spyware goes after value: journalists, opposition figures, lawyers, activists, diplomats, executives, and people connected to them. If you use an iPhone, iPad, or Mac, it’s worth knowing what these campaigns look like and what practical steps can reduce your exposure—without assuming you’re automatically in the crosshairs.
What mercenary spyware is (and what it isn’t)
Mercenary spyware is usually built to quietly extract messages, call data, photos, location history, microphone recordings, and more, often by abusing vulnerabilities in the operating system or commonly used apps. Some variants have been associated in public reporting and research with “zero-click” techniques, where the target doesn’t need to tap a link or install an app for the compromise to happen. The details vary by campaign, but the common thread is stealth and persistence.
It’s different from “stalkerware” used in domestic abuse situations and different from generic phishing kits. It’s also not the same thing as standard advertising trackers. The tools and infrastructure are expensive, and operators typically focus on a narrow set of targets rather than the general public.
Why Apple users are in the mix
Apple devices are popular with high-risk communities and everyday users alike, which makes them appealing to attackers who want reach and credibility. iOS and macOS have strong security defaults, but no platform is invulnerable—especially when an adversary is willing to pay for rare exploits or chain multiple weaknesses together.
Apple has also been unusually public about responding: it regularly ships security updates, has a bug bounty program, and has sent threat notifications to some users it believes were targeted by sophisticated attacks. None of that guarantees safety, but it does mean there are concrete actions you can take that measurably improve your security posture.
How targeting typically happens
Many operations still rely on social engineering somewhere in the chain, even if the end goal is advanced spyware. That can look like convincing messages over SMS, iMessage, email, or social apps that create urgency—“account locked,” “invoice attached,” “court notice,” “delivery failed,” or “breaking news.” If the target bites, the attacker tries to harvest credentials, install a profile, or push them into an interaction that enables deeper compromise.
More sophisticated campaigns may attempt silent exploitation, but those tend to be reserved for people who are already assessed as high-value. Either way, attackers often gather background details first—your role, travel plans, contacts, and devices—so they can tailor lures and choose the best moment to strike.
Signs you might be a higher-risk target
Most people won’t be singled out by mercenary spyware operators. Risk goes up when your work or relationships intersect with sensitive issues: government policy, national security, corruption investigations, human rights work, litigation against powerful entities, or competitive corporate intelligence. Being connected to a likely target can matter too, since attackers sometimes go after colleagues, family members, or advisers as a back door.
Travel can raise stakes, especially to regions where device searches are common or where there’s a record of aggressive surveillance. Public visibility can also increase risk—publishing investigations, speaking at events, or being involved in contentious local politics can make you more interesting to a well-funded adversary.
Practical steps that actually help
Start with the basics that block a lot of real-world attacks: keep iOS/iPadOS/macOS updated, turn on automatic updates, and remove apps you don’t use. Use strong device passcodes (not 4 digits), enable Face ID/Touch ID, and protect your Apple ID with two-factor authentication. If you haven’t reviewed trusted devices and account recovery options lately, do that now.
Then focus on reducing your attack surface. Be skeptical of unexpected links and attachments even when they look like they’re from someone you know, and verify through a second channel when something feels off. Lock down iMessage and FaceTime contact settings where possible, limit who can add you to group chats, and consider using a password manager so phishing for credentials is less effective.
If you believe you’re in a higher-risk category, Apple’s Lockdown Mode can meaningfully reduce exposure by restricting certain features commonly abused in targeted attacks. It can break some workflows, so it’s best for people who prioritize safety over convenience. Also consider separating identities: a dedicated device for sensitive work, fewer apps, minimal cloud sync, and a tighter circle for communications.
What to do if you’re concerned you’ve been targeted
If you receive an official threat notification from a platform provider, treat it seriously—don’t dismiss it as spam, but also don’t click random links claiming to “verify” it. Go directly to your device settings and account pages through normal navigation, not via a message link. If you’re in a sensitive role, notify your organization’s security team or a trusted incident response contact.
For personal users without a security team, start with immediate hygiene: update everything, change critical passwords (email, Apple ID, financial accounts) using a clean device if possible, and review account logins and forwarding rules. Preserve evidence by taking screenshots of suspicious messages and noting dates/times. If you’re a journalist, activist, or human rights defender, consider reaching out to reputable digital security helplines or organizations that support at-risk communities.
Targeted spyware is unsettling because it’s designed to be quiet and selective. The good news is you don’t have to guess perfectly whether you’re a target to improve your security: staying updated, tightening account protections, and reducing risky interactions cuts off many common paths. If your role or situation makes you higher risk, a few extra safeguards—especially stricter device settings and better verification habits—can go a long way.