Protecting Against Spyware
Spyware is software that infects your device to spy on you and steal your data without your knowledge or consent. Phones are most often targeted because they record detailed location data, multi-factor authentication (2FA) codes, and a great deal of other personal information, but laptops and other devices can be targeted as well.
Spyware can extract your private messages (even on encrypted messenger apps like Signal), access your 2FA codes, monitor your conversations, track your location in real time, and even turn on your camera or microphone without your awareness. All this data gets sent back to whoever controls the spyware. It's like they are looking over your shoulder as you use your phone.
Spyware is made and sold by private companies to governments. It gets used not just against criminals but also against activists, journalists, and lawyers. Most recently, ICE has purchased access to spyware tools.
The two most well-known mobile spyware programs are Pegasus (from NSO Group) and Graphite (from Paragon Solutions). Both companies were founded by executives who used to work for Unit 8200, Israel's equivalent of the NSA in the US. But newer spyware is being discovered all the time, and spyware is one corner of the larger world of "malware" and "stalkerware," which are also used by oppressive governments and by abusive intimate partners to silence people.
How likely am I to be the target of spyware?
While governments claim to use spyware only against criminals, there are many documented cases of it being deployed against political activists, journalists, and lawyers by governments:
- High-profile organizers and activists (In Catalonia)
- Human rights lawyers (In Mexico)
- Investigative journalists (See Forbidden Stories and Amnesty International)
- We have also seen cases where families of targets have had devices infected with spyware. (See Citizen Lab)
Spyware like Pegasus and Graphite costs governments tens or hundreds of thousands of dollars to deploy. Therefore, the vast majority of activists will NOT be targeted with spyware and would benefit more from protecting against other threats.
We suggest folks start with our Security Essentials Checklist and then come back to this guide. That guide will help you protect against cheaper-to-deploy surveillance technologies like location tracking or phone-cracking software police can use after they seize your device.
As repressive politicians continue to push the US towards authoritarianism, we should expect sophisticated spyware to be used more broadly against activists.
The good news: the steps you need to take to help protect yourself from spyware and stalkerware will also help you protect against other kinds of attacks that are more likely to affect you, so they are good to complete regardless.
Don't panic: It's easy to read about these advanced hacking tools and get very concerned. Most activists will not be targeted with spyware. The authoritarians want us to believe that they are all powerful and can see everything we do. With a few simple steps we can make it very costly, and politically risky, for them to surveil us.
Baseline protections
This section is for anyone doing activism or advocacy work.
Complete our Digital Security Essentials checklist
This guide covers other important doxxing protection steps like passwords, app location permissions, and software updates.
If you're concerned about doxxing, it's a good idea to complete the steps outlined in our Digital Security Essentials checklist →
Many of these will protect you against someone trying to access your accounts or devices if you're the target of doxxing.
These items from the Essentials checklist are especially important:
- Turn off location tracking for most apps
- Install the latest software updates for your laptop, phone, and apps
- Use a password manager
- Change your existing passwords if they are weak or reused across multiple sites.
- Enable two-factor authentication on your important accounts
- Don't click on suspicious links
Keep your phone (and laptop) updated to the latest operating system version
Protects you from hackers, spyware, and the phone hacking tools the cops use.
Every time a new operating system update comes out, it is fixing security holes. Each update you haven't installed represents a longer list of ways the cops can hack into your device. Think of it as a big building with more and more doors left unlocked.
If your operating system is not up-to-date, many of the other recommendations in this guide will not protect your data.
Start with your phone. If you're doing something higher risk, make sure to update all your devices.
How to run updates
Because security updates are so important, we designed a tool to walk you through the process.
How to run updates manually
If you prefer to run updates manually, here is how to do it for each device:
Enable Lockdown Mode (iPhone) or Advanced Protection (Google & Android)
Spyware is an advanced type of attack, exploiting sophisticated vulnerabilities on our devices. In response, Apple and Google have introduced an advanced security mode that offers enhanced protection against spyware.
On iPhones, it's called Lockdown Mode and on Android, it's called Advanced Protection Program. (You can also enable Advanced Protection Program on just your Google Account even if you don't have an Android phone.)
We have no reports of anyone getting infected with spyware who had Apple's Lockdown Mode enabled. Android's Advanced Protection is more recent and its effectiveness has yet to be tested.
Usability trade-offs: Both features come with some functionality sacrifices. See the full list of trade-offs. If you encounter issues that don't work for your needs, you can always disable the feature later.
How to enable Lockdown Mode for iPhones
This feature is available for iOS version 16 and above.
How to enable Advanced Protection on Android
Note: The location of this setting may vary between Android devices, so we recommend searching for 'Advanced Protection' in the Settings search bar.
This feature is available for Android 16 and above.
Enable iCloud Advanced Data Protection (iPhone) or Google Advanced Protection Program
Apple, Google, and other services offer additional security features to protect against targeted attacks on your accounts and data. These protect your online accounts with each company, not your device itself.
Apple's Advanced Data Protection enables end-to-end encryption for most of your content.
How to enable advanced protection on your email/cloud accounts
Protect your data:
- iCloud Advanced Data Protection - Enables end-to-end encryption for almost all data stored in iCloud, protecting your information against government court orders. Make sure you save the recovery key somewhere very safe (like a password manager).
Protect your account:
- Google's Advanced Protection Program - Helps protect your account from phishing and unauthorized access.
- Microsoft's Account Guard
- Proton Sentinel
Don't click suspicious links
You can protect yourself against spyware by being cautious about what you click on
Spyware often arrives through a text or email with a link custom-designed to feel impossible to ignore, specifically for you. These aren't random spam - they're personalized attacks that exploit what matters most to you.
How to catch and respond to suspicious links
When in doubt: Do not click the link!
- Instead, contact the sender (whether a business or a friend) through a different method (call them, use a different app) to verify they actually sent it. Taking 2 minutes to verify is always better than clicking and compromising your device.
- If it is a shortened URL like bit.ly or tinyurl.com, you can use ExpandURL.net to view the destination page, but this provides no guarantee that the page isn't spyware. It just helps you view the true URL so you can make a better assessment of whether you trust it.
- To check whether a link has already been flagged as malicious, you can paste it into a phishing and malware database like VirusTotal (owned by Google/Alphabet). Only submit links that are public and non-personal, because VirusTotal is a public repository that anyone can search.
Red flags to watch for:
- Messages from numbers you don't recognize: We all get messages from services that aren't in our contact book often, so it can take work to discern whether this is a legitimate message or not. If it's someone not in your contact book, approach it with more caution.
- Urgency or fear: "Your account will be locked," "Urgent security alert," "Family emergency"
- Unfamiliar domain name: Spyware texts often come from weird domains like
adsmetrics[.]co - Too personal: References your activism, recent events you attended, or people you know - designed to bypass your critical thinking
- Unexpected messages: A contact sends a link with no context, unusual phrasing, or at a strange time (their account may be compromised)
- Shortened URLs:
bit.ly,tinyurl.com, or other link shorteners that hide the real destination - Slight misspellings in the URL:
goog1e.cominstead ofgoogle.com
Spyware messages can be highly targeted. Here are some real-world examples of how Pegasus Spyware has been deployed:
"Dear Carmen my brother died in an accident, I’m devastated, I send you the information about the funeral, I hope you can come: [spyware link]" (source)
USEMBASSY.GOV/ WE DETECTED A PROBLEM WITH YOUR VISA PLEASE GO PROMPTLY TO THE EMBASSY. SEE DETAILS [spyware link] (source)
LX 1955 BCN-ZRH 26Jun2020 - Click on the link to receive your mobile boarding pass [spyware link] (source)
Be aware: Some spyware is deployed using exploits that don't require you clicking a link at all ("zero click exploits"). These might show up as missed calls on WhatsApp, for example.
Enhanced protections
This section is for you if you are in a leadership role or you are doing activism that is more likely to be targeted by the state or your opposition.
Remove as many apps as you can from your phone/device
If you want to make it tougher for a thief to get into your home, one easy step is to cut down on the number of doors. On your device, each app acts as a "door" to the outside world, exposing you to increased risk of attack. If the app has a bug or vulnerability, it can make your whole device vulnerable.
How to remove apps
- Scan through all the apps on your phone and computer.
- Decide if you truly need it. Many apps can just as easily be accessed via their website instead. It is usually a little more inconvenient, but you get more privacy and security as a result.
- Uninstall it if at all possible. If you're not sure, try uninstalling it for a week and see if you can manage without it. You can always reinstall later.
Examples of apps that have been used by spyware in the past:
Turn off link previews on Signal and WhatsApp
When you include a link in a message, it often generates a "link preview." Even though you can't see it, your device is visiting that webpage to extract the correct preview image. If the webpage is malicious, a sophisticated attacker can identify your location or in extreme cases, implant spyware on your phone.
How to disable link previews
- Signal:
- WhatsApp:
Cover the front camera
If you were infected by spyware already, it can perform live surveillance on your device, accessing the camera and microphone. To limit what spies can see, it's a good idea to cover at least your front camera.
How to cover your front camera
- Get a sticker that has enough stickiness to be reusable. Or consider this sticker pack from SLNT.
- Put it on your phone and your laptop
- Move it off temporarily when you need the front camera, then remember to move it back.
Consider getting a secondary or burner phone for activist work
If it fits your workflow, consider setting up a second phone or computer just for your higher-risk work.
Check our Secondary Phone Checklist for more on this.
If you do this, make sure you still take security precautions on all devices. Even though only one device has sensitive communications/data on it, both devices could be a target for spyware since they reveal your location and other personal information an attacker might want. You might consider getting a phone that supports GrapheneOS. It is security-focused and privacy-focused version of Android that runs on Google Pixel phones.
Reboot your device regularly
Most spyware attempts to hide its tracks by not writing any files to your device. Because of that, rebooting your device will likely cause the spyware to be removed for the moment. That said, if you are still a target, they will likely try to reinfect your phone immediately. Some of the infections require you to click on a link (or take some other kind of action), but some occur without any user interaction. So while rebooting your phone frequently can help make things more difficult for your attackers, it isn't a guarantee that you're free from spyware.
Testing Devices
If you use an iPhone, you can run a spyware analysis using iMazing. It is free (don't click any of the "buy" buttons). Technical users can also run the Mobile Verification Toolkit (MVT) for detailed consensual device forensics.
However, detecting spyware on a device is not a trivial task and you shouldn't rely on just anyone to test your phone. Civil society members globally have turned to these institutions to help test their phones and run detailed analysis with the support of experts:
- Citizen Lab - the leading experts on spyware analysis
- Access Now
- Amnesty Security Lab
- Constitutional Communications - helping get spyware analysis to more people in activist communities
- Electronic Frontier Foundation - for people in the US
Each organization will have its own vetting process, and it might take some time for them to respond to your request while they verify everything on their end.
How to notice if you might be infected
Spyware generally presents no noticeable symptoms and infects silently. However, some common complaints from spyware targets over the years have included:
- Rapid drainage of the phone battery
- Suspicious behavior from certain apps
- Abnormal data usage
- Receipt of suspicious links or attachments
If you notice any of these symptoms, it does not necessarily mean that your device has been hacked with spyware. We recommend contacting one of the organizations linked above to get your device tested.
Spyware is highly advanced malware that a regular antivirus will not detect. We recommend contacting expert, trusted organizations for support with determining whether your device exhibits signs of (past or present) compromise.
Apple and WhatsApp now regularly notify users they suspect their devices have been targeted with mercenary spyware. Here's more on Apple's threat notifications and WhatsApp's threat notification.
Learn more
- Citizen Lab has traced Pegasus operations to 45 countries
- Forensic Architecture has mapped the human cost of those operations on their site, Digital Violence
Related: History of how the US government has compromised internet security:
- Microsoft handed the NSA access to encrypted messages - The Guardian, 2013
- Revealed: how US and UK spy agencies defeat internet privacy and security - The Guardian, 2013
- N.S.A. Able to Foil Basic Safeguards of Privacy on Web - The New York Times, 2013
- NSA infected 50,000 computer networks with malicious software - NRC, 2013
- Secret contract tied NSA and security industry pioneer - Reuters, 2013
- N.S.A. Devises Radio Pathway Into Computers - The New York Times, 2014
- How the NSA Plans to Infect 'Millions' of Computers with Malware - The Intercept, 2014
- Prying Eyes: Inside the NSA's War on Internet Security - Der Spiegel, 2014
- New Discovery Around Juniper Backdoor Raises More Questions About the Company - Wired, 2016
- The NSA Leak Is Real, Snowden Documents Confirm - The Intercept, 2016
Have Questions?
Let us know if you have questions or feedback so we can make these guides as useful as possible.