Dominic Jainy is a distinguished IT professional whose expertise spans artificial intelligence, machine learning, and the intricate world of blockchain technology. With a career dedicated to securing digital ecosystems, he provides profound insights into how emerging technologies are being leveraged both as shields and as weapons in the modern era. In our discussion today, we explore the startling reality of mercenary spyware, a topic that has recently dominated headlines following Apple’s urgent alerts to iPhone users across 110 countries. We delve into the sophisticated nature of these state-sponsored attacks, the expanding demographic of high-value targets, and the high-stakes battle between mobile security protocols and million-dollar exploits designed to remain invisible.
Since mercenary spyware often relies on zero-click exploits via messaging apps, how does this bypass traditional security and what makes it so difficult to defend against?
Zero-click exploits are terrifyingly efficient because they remove the human element of error, meaning a user does not have to open a link or download an attachment for their device to be compromised. These attacks typically arrive as a message through iMessage or WhatsApp, often disguised as a simple image file that exploits deep-seated software flaws within the operating system. Because these mercenary tools cost millions of dollars to develop and maintain, their creators ensure they have a very short shelf life, making them incredibly difficult to detect and even harder to prevent before they strike. Apple’s investigations aim for high confidence, but even they admit that absolute certainty is elusive given how these adversaries orchestrate their attacks to leave as little trace as possible.
Apple recently issued warnings to users in 110 countries, but the scope seems to be growing; what should high-value professionals understand about their risk profile today?
While activists and journalists were the primary focus in the past, the economic landscape of mercenary spyware has shifted toward targeting corporate executives, negotiators, and individuals with privileged digital access. As of 2026, Apple has identified and notified targeted individuals in over 150 countries in total, which highlights the global scale of this precision tooling. If you receive a notification from the official Apple Threat Notifications email—threat-notifications@email.apple.com—it should be treated as a major security incident from the very first minute. Professionals must understand that their device is being targeted because of who they are or what they do, and the best immediate response is to enable Lockdown Mode and preserve the hardware for expert help rather than attempting a simple wipe.
There is a lot of confidence in end-to-end encrypted apps like Signal and WhatsApp, yet this spyware seems to render them useless; how is that technically possible?
The power of spyware like the NSO Group’s Pegasus lies in its ability to compromise the entire operating system, effectively getting behind the encryption of apps like Signal or WhatsApp. Even though the messages are encrypted while traveling across the internet, the spyware captures the data directly on the device—either as you type it or as it is displayed on your screen. This means the attacker can hear your conversations through the microphone and see everything you do on your screen in real-time, completely bypassing the security of the app itself. It turns a secure communication device into a total surveillance tool, taking advantage of software flaws to gain root access to every piece of information stored on the iPhone.
Given that Apple’s data shows no known compromise of devices running Lockdown Mode, how should at-risk users balance convenience with these extreme security measures?
For the vast majority of users, the risk of being targeted by a million-dollar mercenary attack is low, but the availability of Lockdown Mode provides a critical safety net for those in high-stakes roles. This mode makes it almost impossible for malware to hit your device by stripping away non-essential features that attackers use as entry points. Beyond using this specialized mode, the most vital action any user can take is to apply Apple iOS updates the second they become available to patch any known vulnerabilities that adversaries might exploit. If a user suspects they are already compromised, they should know that while turning the iPhone on and off can sometimes disrupt the spyware, the only guaranteed way to remove it is to replace the device entirely.
What is your forecast for the future of mobile security and the ongoing battle against mercenary spyware?
From 2026 to 2028, I forecast that the cost of these exploits will only increase as mobile operating systems become more hardened, potentially reaching tens of millions of dollars per successful zero-day. We will likely see a more aggressive push toward hardware-based isolation, where the most sensitive parts of the phone’s communication stack are physically separated from the rest of the software. Apple’s threat notification system is already a massive step forward, having reached users in over 150 countries, and I expect these alerts to become more integrated with real-time behavioral analysis to catch spyware in the act. Ultimately, the battle will move from reacting to infections toward building devices that are fundamentally resilient to the very concept of a zero-click bypass, making state-sponsored surveillance an increasingly expensive and difficult endeavor.
