Protecting Against Spyware
Spyware is software that can infect your device to spy on you and steal your data without a target's knowledge or consent. Phones are most often targeted because they offer location data, but laptops and other devices can be targeted as well.
Spyware can extract your private messages (even on encrypted messenger apps like Signal), monitor your conversations, track your location in real time, and even turn on your camera and microphone without you being aware. All this data gets sent back to whoever controls the spyware.
Spyware is made and sold by private companies to governments and other clients. It's used heavily in authoritarian countries, but has been deployed by other countries like Spain and Canada. Now, ICE has purchased access to spyware tools.
The two most well-known spyware programs are Pegasus (from NSO Group) and Graphite (from Paragon Solutions), but newer spyware is being discovered all the time. Both companies were founded by executives who used to work for Unit 8200, Israel's equivalent of the NSA in the US.
How likely am I to be the target of spyware?
So far we have observed spyware being deployed against high-profile targets:
- High-profile organizers and activists
- Human rights lawyers
- Investigative journalists
- We have also seen cases where families of targets have had devices infected with spyware.
It costs millions or tens of thousands of dollars to deploy most spyware. It usually only available to nation states with nearly unlimited budgets. Therefore, our assessment is that the vast majority of activists and organizers will NOT be targeted with spyware and would benefit more from protecting against other threats.
We suggest folks start with our Security Essentials Checklist and then come back to this guide. That guide will help you protect against cheaper-to-deploy surveillance technologies like location tracking or phone-cracking software they can use after they seize your device.
There are other less costly methods that authorities resort to in order to surveil, subvert, and sabotage social movements. However, as the US continues to slide into authoritarianism, we can expect spyware to be used more broadly against activists.
The good news: the steps you need to take to help protect yourself from spyware will also help you protect against other kinds of attacks that are more likely, so they are good to complete regardless.
Don't panic: It's easy to read about these advanced hacking tools and get very concerned. Most activists will not be targeted with spyware. The authoritarians want us to believe that they are all powerful and can see everything we do. The truth is they can't see everything and we can make it more costly for them to surveil us.
Baseline protections
This section is for anyone doing activism or advocacy work.
Complete our Digital Security Essentials checklist
This guide covers other important doxxing protection steps like passwords, app location permissions, and software updates.
If you're concerned about doxxing, it's a good idea to complete the steps outlined in our Digital Security Essentials checklist →
Many of these will protect you against someone trying to access your accounts or devices if you're the target of doxxing.
These items from the Essentials checklist are especially important:
- Turn off location tracking for most apps
- Install the latest software updates for your laptop, phone, and apps
- Use a password manager
- Change your existing passwords if they are weak or reused across multiple sites.
- Enable two-factor authentication on your important accounts
- Don't click on suspicious links
Keep your phone (and laptop) updated to the latest operating system version
Protects you from hackers, spyware, and the phone hacking tools the cops use.
Every time a new operating system update comes out, it is fixing security holes. Each update you haven't installed represents a longer list of ways the cops can hack into your device. Think of it as as a big building with more and more doors left unlocked.
If your operating system is not up-to-date, many of the other recommendations in this guide will not protect your data.
Start with your phone. If you're doing something higher risk, make sure to update all your devices.
How to run updates
Because security updates are so important, we designed a tool to walk you through the process.
How to run updates manually
If you prefer to run updates manually, here is how to do it for each device:
Enable Lockdown Mode (iPhone) or Advanced Protection (Google & Android)
Mercenary spyware is an extremely advanced attack, exploiting sophisticated vulnerabilities on our devices. In response, Apple and Google have introduced an advanced security mode that offers enhanced protection against spyware.
On iPhones, it's called Lockdown Mode and on Android, it's called Advanced Protection Program. (You can also enable Advanced Protection Program on just your Google Account even if you don't have an Android phone.)
We have no reports of anyone getting infected with spyware who had Apple's Lockdown Mode enabled. Android's Advanced Protection is more recent and its effectiveness has yet to be tested.
Usability trade-offs: Both features come with some functionality sacrifices. See the full list of trade-offs. If you encounter issues that don't work for your needs, you can always disable the feature later.
How to enable Lockdown Mode for iPhones
This feature is available for iOS version 16 and above.
How to enable Advanced Protection on Android
Note: The location of this setting may vary between Android devices, so we recommend searching for 'Advanced Protection' in the Settings search bar.
This feature is available for Android 16 and above.
Enable iCloud Advanced Data Protection (iPhone) or Google Advanced Protection Program
Apple, Google, and other services offer additional security features to protect against targeted attacks on your accounts and data. These protect your online accounts with each company, not your device itself.
Apple's Advanced Data Protection enables end-to-end encryption for most of your content.
How to enable advanced protection on your email/cloud accounts
Protect your data:
- iCloud Advanced Data Protection - Enables end-to-end encryption for almost all data stored in iCloud, protecting your information against government court orders. Make sure you save the recovery key somewhere very safe (like a password manager).
Protect your account:
- Google's Advanced Protection Program - Helps protect your account from phishing and unauthorized access.
- Microsoft's Account Guard
- Proton Sentinel
Don't click suspicious links
You can protect yourself against spyware by being cautious about what you click on
Spyware often arrives through a text or email with a link custom-designed to feel impossible-to-ignore specifically for you. These aren't random spam - they're personalized attacks that exploit what matters most to you.
How to catch and respond to suspicious links
When in doubt: Do not click the link!
- Instead, contact the sender (whether a business or a friend) through a different method (call them, use a different app) to verify they actually sent it. Taking 2 minutes to verify is always better than clicking and compromising your device.
- If it is a shortened URL like bit.ly or tinyurl.com, you can use ExpandURL.net to view the destination page, but this provides no guarantee that the page isn't Spyware. It just helps you view the true URL so you can make a better assessment of whether you trust it.
Red flags to watch for:
- Messages from numbers you don't recognize: We all get messages from services that aren't in our contact book often, so it can take work to discern whether this is a legitimate message or not. If it's someone not in your contact book, approach it with more caution.
- Urgency or fear: "Your account will be locked," "Urgent security alert," "Family emergency"
- Unfamiliar domain name: Spyware texts often come from weird domains like
adsmetrics[.]co - Too personal: References your activism, recent events you attended, or people you know - designed to bypass your critical thinking
- Unexpected messages: A contact sends a link with no context, unusual phrasing, or at a strange time (their account may be compromised)
- Shortened URLs:
bit.ly,tinyurl.com, or other link shorteners that hide the real destination - Slight misspellings in the URL:
goog1e.cominstead ofgoogle.com
Spyware messages can be highly targeted. Here are some real-world examples of how Pegasus Spyware has been deployed:
"Dear Carmen my brother died in an accident, I’m devastated, I send you the information about the funeral, I hope you can come: [spyware link]" (source)
USEMBASSY.GOV/ WE DETECTED A PROBLEM WITH YOUR VISA PLEASE GO PROMPTLY TO THE EMBASSY. SEE DETAILS [spyware link] (source)
LX 1955 BCN-ZRH 26Jun2020 - Click on the link to receive your mobile boarding pass [spyware link] (source)
Be aware: Some spyware is deployed using exploits that don't require you clicking a link at all ("zero click exploits"). These might show up as missed calls on WhatsApp, for example.
Enhanced protections
This section is for you if you are in a leadership role or you are doing activism that is more likely be targeted by the state or your opposition.
Remove as many apps as you can from your phone/device
If you want to make it tougher for a thief to get into your home, one easy step is to cut down on the number of doors. On your device, each app acts as a "door" to the outside world, exposing you to increased risk of attack. If the app has a bug or vulnerability, it makes your whole device vulnerable.
How to remove apps
- Scan through all the apps on your phone and computer.
- Decide if you truly need it. Many apps can just as easily be accessed via their website instead. It is usually a little more inconvenient, but you get more privacy and security as a result.
- Uninstall it if at all possible. If you're not sure, try uninstalling it for a week and see if you can manage without it. You can always reinstall later.
Examples of apps that have been used by spyware in the past:
Turn off link previews on Signal and WhatsApp
When you include a link in a message, it often generates a "link preview." Even though you can't see it, your device is visiting that webpage to extract the correct preview image. If the webpage is malicious, a sophisticated attacker can identify your location or in extreme cases, implant spyware on your phone.
How to disable link previews
- Signal:
- WhatsApp:
Cover the front camera
If you were infected by spyware already, it can perform live surveillance on your device, accessing the camera and microphone. To limit what spies can see, it's a good idea to cover at least your front camera.
How to cover your front camera
- Get a sticker that has enough stickiness to be reusable. Or consider this sticker pack from SLNT.
- Put it on your phone and your laptop
- Move it off temporarily when you need the front camera, then remember to move it back.
Consider getting a secondary or burner phone for activist work
If it fits your workflow, consider setting up a second phone just for your higher-risk work.
Check our Secondary Phone Checklist for more on this.
If you do this, make sure you still take security precautions on all devices. Even though only one device has sensitive communications/data on it, both devices could be a target for spyware since they reveal your location and other personal information an attacker might want.
Reboot your device regularly
We can't be certain whether spyware can survive a reboot (i.e. a restart), as this varies depending on the type of spyware and its license. However, restarting is a costless action that may complicate the efforts of the surveilling party to continue spying on you.
If reboots do indeed disrupt the spyware, the actor attempting to spy on your device would need to reinfect your phone.
Testing Devices
If you can use an iPhone, you can run a spyware analysis using iMazing. It is free (don't click any of the "buy" buttons).
Detecting spyware on a device is not a trivial task and you shouldn't rely on just anyone to test your phone. Civil society globally have turned to these three institutions to help in testing their phones:
- Citizen Lab - the leading experts on spyware analysis
- Access Now
- Amnesty Security Lab
- Constitutional Communications - helping get spyware analysis to more people in activist communities
- Electronic Frontier Foundation - for people in the US
Each organization will have its own vetting process, and it might take some time for them to respond to your request while they verify everything on their end.
How to notice if you might be infected
Spyware generally presents no noticeable symptoms and infects silently. However, some common complaints from spyware targets over the years have included:
- Rapid drainage of the phone battery
- Suspicious behavior from certain apps
- Abnormal data usage
- Receipt of suspicious links or attachments
If you notice any of these symptoms, it does not necessarily mean that your device has been hacked with spyware. We recommend contacting one of the organizations linked above to get your device tested.
Spyware is highly advanced malware that a regular antivirus will not detect. We recommend contacting expert, trusted organizations for support with determining whether your device exhibits signs of (past or present) compromise.
Apple and WhatsApp now regularly notify users they suspect their devices have been targeted with mercenary spyware. Here's more on Apple's threat notifications and WhatsApp's threat notification.
Have Questions?
Let us know if you have questions or feedback so we can make these guides as useful as possible.