iPhone Flaw Exploited by Pegasus Spyware Said to Be Simultaneously Abused by Second Israeli Spy Firm

QuaDream is a smaller Israeli firm that also develops smartphone hacking tools intended for government clients.

Advertisement
By Reuters | Updated: 4 February 2022 12:38 IST
Highlights
  • NSO Group and QuaDream used ForcedEntry exploits on iPhone handsets
  • Apple sued NSO Group over ForcedEntry in November
  • Apple fixed the underlying flaws in September 2021

ForcedEntry is viewed as "one of the most technically sophisticated exploits" ever discovered

Photo Credit: Reuters

A flaw in Apple's software exploited by Israeli surveillance firm NSO Group to break into iPhones in 2021 was simultaneously abused by a competing company, according to five people familiar with the matter. QuaDream, the sources said, is a smaller and lower profile Israeli firm that also develops smartphone hacking tools intended for government clients.

The two rival businesses gained the same ability last year to remotely break into iPhone handsets, according to the five sources, meaning that both firms could compromise Apple phones without an owner needing to open a malicious link. That two firms employed the same sophisticated hacking technique – known as a “zero-click” – shows that phones are more vulnerable to powerful digital spying tools than the industry will admit, one expert said.

"People want to believe they're secure, and phone companies want you to believe they're secure. What we've learned is, they're not," said Dave Aitel, a partner at Cordyceps Systems, a cybersecurity firm.

Advertisement

Experts analyzing intrusions engineered by NSO Group and QuaDream since last year believe the two companies used very similar software exploits, known as ForcedEntry, to hijack iPhones.

Advertisement

An exploit is computer code designed to leverage a set of specific software vulnerabilities, giving a hacker unauthorized access to data.

The analysts believed NSO and QuaDream's exploits were similar because they leveraged many of the same vulnerabilities hidden deep inside Apple's instant messaging platform and used a comparable approach to plant malicious software on targeted devices, according to three of the sources.

Advertisement

Bill Marczak, a security researcher with digital watchdog Citizen Lab who has been studying both companies' hacking tools, told Reuters that QuaDream's zero-click capability seemed "on par" with NSO's.

Reuters made repeated attempts to reach QuaDream for comment, sending messages to executives and business partners. A Reuters journalist last week visited QuaDream's office, in the Tel Aviv suburb of Ramat Gan, but no one answered the door. Israeli lawyer Vibeke Dank, whose email was listed on QuaDream's corporate registration form, also did not return repeated messages.

Advertisement

An Apple spokesman declined to comment on QuaDream or say what if any action they planned to take with regard to the company.

ForcedEntry is viewed as "one of the most technically sophisticated exploits" ever captured by security researchers.

So similar were the two versions of ForcedEntry that when Apple fixed the underlying flaws in September 2021 it rendered both NSO and QuaDream's spy software ineffective, according to two people familiar with the matter.

In a written statement, an NSO spokeswoman said the company "did not cooperate" with QuaDream but that "the cyber intelligence industry continues to grow rapidly globally."

Apple sued NSO Group over ForcedEntry in November, claiming that NSO had violated Apple's user terms and services agreement. The case is still in its early stages.

In its lawsuit, Apple said that it "continuously and successfully fends off a variety of hacking attempts." NSO has denied any wrongdoing.

Spyware companies have long argued they sell high-powered technology to help governments thwart national security threats. But human rights groups and journalists have repeatedly documented the use of spyware to attack civil society, undermine political opposition, and interfere with elections.

Apple notified thousands of ForcedEntry targets in November, making elected officials, journalists, and human rights workers around the world realize they had been placed under surveillance.

In Uganda, for example, NSO's ForcedEntry was used to spy on U.S. diplomats, Reuters reported.

In addition to the Apple lawsuit, Meta's WhatsApp is also litigating over the alleged abuse of its platform. In November, NSO was put on a trade blacklist by the U.S. Commerce Department over human rights concerns.

Unlike NSO, QuaDream has kept a lower profile despite serving some of the same government clients. The company has no website touting its business and employees have been told to keep any reference to their employer off social media, according to a person familiar with the company.

REIGN

QuaDream was founded in 2016 by Ilan Dabelstein, a former Israeli military official, and by two former NSO employees, Guy Geva and Nimrod Reznik, according to Israeli corporate records and two people familiar with the business. Reuters could not reach the three executives for comment.

Like NSO's Pegasus spyware, QuaDream's flagship product - called REIGN - could take control of a smartphone, scooping up instant messages from services such as WhatsApp, Telegram, and Signal, as well as emails, photos, texts and contacts, according to two product brochures from 2019 and 2020 which were reviewed by Reuters.

REIGN's “Premium Collection” capabilities included the "real time call recordings", "camera activation - front and back" and "microphone activation", one brochure said.

Prices appeared to vary. One QuaDream system, which would have given customers the ability to launch 50 smartphone break-ins per year, was being offered for $2.2 million (roughly Rs. 16 crore) exclusive of maintenance costs, according to the 2019 brochure. Two people familiar with the software's sales said the price for REIGN was typically higher.

Over the years, QuaDream and NSO Group employed some of the same engineering talent, according to three people familiar with the matter. Two of those sources said the companies did not collaborate on their iPhone hacks, coming up with their own ways to take advantage of vulnerabilities.

Several of QuaDream's buyers have also overlapped with NSO's, four of the sources said, including Saudi Arabia and Mexico - both of whom have been accused of misusing spy software to target political opponents.

One of QuaDream's first clients was the Singaporean government, two of the sources said, and documentation reviewed by Reuters shows the company's surveillance technology was pitched to the Indonesian government as well. Reuters couldn't determine if Indonesia became a client.

Mexican, Singaporean, Indonesian and Saudi officials did not return messages seeking comment about QuaDream.

© Thomson Reuters 2021


Why is 5G taking so long? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Freedom Sale Slashes Prices of Phones, Tablets, and More Products
  2. These Smartphones Will Be Discounted During Flipkart Republic Day Sale
  3. These OnePlus, Samsung Phones Will Be on Sale During Amazon's Next Sale
  4. iPhone 17 Pro, iPhone Air Will Go Sale at These Prices During Amazon's Sale
  5. Vivo X200T Confirmed to Launch in India Soon: See Expected Specs
  6. Vivo Y500i With a 7,200mAh Battery, 50-Megapixel Camera Launched
  7. Amazon Great Republic Day Sale 2026: iQOO Smartphone Deals Revealed
  8. Here Are Some of the Best Smartphones With Snapdragon 7 Gen 4 SoC
  9. Nothing Will Open Its First Flagship Store in India Soon
  10. Google Adds AI-Powered 'Business Agent' Feature to Search for Shoppers
  1. Forza Horizon 5 Is Said to Have Sold Over 5 Million Copies on PS5
  2. Realme Neo 8 Display Details Teased; TENAA Listing Reveals Key Specifications
  3. iPhone 17 Pro, iPhone 17 Pro Max, iPhone Air Discounts Revealed Ahead of Amazon Great Republic Day Sale 2026
  4. Google’s AI Overviews Giving Incorrect Medical Advice as OpenAI, Anthropic Push for Healthcare: Report
  5. WhatsApp Might Soon Let Parents Control Who Minors Interact With
  6. Nothing Announces Plans to Open Its First Flagship Store in India Soon
  7. After OpenAI, Now Anthropic Introduces Claude for Healthcare AI Tools
  8. Honor Magic 8 RSR Porsche Design Launch Date, Colourways Announced; Set to Arrive Alongside Magic 8 Pro Air
  9. Mahasenha Volume 1 OTT Release Date: When and Where to Watch This Mystical Thriller Online?
  10. Kirkkan OTT Release Date Confirmed: When and Where to Watch it Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.