4 ms·
I turned off imessage. I seem to be under attack lately. 3-4 times a day random links sent from gmail addresses or unknown phone numbers to imsg with sketchy
by eyeball 5y ago
I turned off imessage.
I seem to be under attack lately.
3-4 times a day random links sent from gmail addresses or unknown phone numbers to imsg with sketchy looking links in them.
- cyckl 5y agoI’m also getting these—no idea what the exploits actually are or how they work. Am I theoretically already exploited?
- gruez 5y agoNot really. 1. There's no reason why a threat actor would have to send you 3-4 messages per day. Of the exploits I've seen, they only need to send one. Sending 3-4 messages per day just unnecessarily increases the risk of getting caught (ie. the target getting suspicious and asking on hacker news whether they're getting hacked) 2. There's no reason why the message has to contain sketchy links. They could very well disguise messages as ads/notifications for well known businesses, political organizations, or from random people who got the wrong phone number. 3. There's no reason why the attacker can't erase any trace of the initial message after your device is infected, so unless you're staring at your phone 24/7 it's very easy to miss the message.
- dannyw 5y agoDisagree with all 3 points. If I am sneaking a payload in, and I have different exploits for different OS versions, I would exactly disguise it as spam. Pretending to be a busines, or a random person with wrong number, and then DELETING IT is a noteable indicator of compromise. I know this isn't how Pegasus works, but I'm sure there are more exploit kits being sold in the world. Some may not be as sophisticated, and may rely on spraying and praying with different exploits.
- gruez 5y ago>If I am sneaking a payload in, and I have different exploits for different OS versions, I would exactly disguise it as spam. Right, but the point is that GP seems to have been tipped off by the "sketchy links", rather than the spam itself, and that there are far better ways to compose your spam texts than ones with sketchy links. >Pretending to be a busines, or a random person with wrong number, and then DELETING IT is a noteable indicator of compromise. It depends on the nature of the exploit. I was operating under the assumption that "0 click" means the exploit gets run as soon as the phone receives it, which would allow for the exploit to clean up after itself without alerting the owner, unless the owner was staring at the phone the exact moment the message came in.
- dylan604 5y agoCan you war-dial attack with these? Seems like it would be super easy for a script kiddie to just start at 111-111-1111, send message, increment by 1, repeat. Maybe narrow it down to valid area codes and what not, but seems like a super low budget thing to do.
- zsmi 5y agoSure. https://calleridreputation.com/blog/robotexts-are-replacing-robocalls-as-sms-spam-increases/ https://calleridreputation.com/blog/robotexts-are-replacing-... "Robotech spammers are also targeting group messages by using automated programs to send thousands, even millions of group texts to random phone numbers with the hopes that somebody will take the prey and respond." Also, some users give random apps access to their address book for whatever reason then there is a whole list of known good emails and numbers to spam.
- dylan604 5y ago>Also, some users give random apps access to their address book for whatever reason "There's a sucker/fool born every minute." --PT Barnum And there are businesses of all types where that is their sole business model.
- rmorey 5y agoWell, send from what? Every iMessage comes from an account with an Apple ID, so I presume stolen credentials would be the only way to really do this, adding to the cost.
- dylan604 5y agoIf you know the email address that is used for the Apple ID, you can send it a message without being in messages. You can also send a text to a phone number via email based on the carrier and knowing how to structure the address. So, it's not impossible to do this at all. No stolen credentials necessary.
- 5y ago
- WelcomeShorty 5y agoSo enlighten us: how did you turn off iMessage?
- neilalexander 5y ago“Settings” -> “Messages” -> Toggle “iMessage” to off. Couldn’t be simpler.