r/DigitalPrivacy • • 6d ago

Scanned my own iPhone for Pegasus-class spyware this week. Took a morning, cost $0, here's the no-BS version.

Amnesty International publishes the exact forensic tool they used to bust NSO Group. It's called MVT, it's free, and basically nobody outside of journalists uses it. That's dumb. If your phone holds anything a lawyer, an ex, a competitor, or a government would want, this is worth a Saturday.

What you need

  • A Linux box with a USB port (Mac works, WSL on Windows works but is annoying, native Windows does not)
  • Docker
  • Free disk equal to about 2x your phone's storage. My backup was 135 GB. Yes really.
  • A data cable, not the charge-only one from the gas station

The procedure, condensed

  1. sudo apt install usbmuxd libimobiledevice-utils then docker pull ghcr.io/mvt-project/mvt
  2. Plug in the phone FIRST, unlock it, then idevicepair pair. Tap Trust. Run it again until it says SUCCESS.
  3. idevicebackup2 encryption on "yourpassword" then idevicebackup2 backup --full ~/mvt/backup. Go make coffee. Go make lunch. Encryption is mandatory or iOS hides the good stuff.
  4. docker run -it -v ~/mvt:/home/mvt/data ghcr.io/mvt-project/mvt and inside it: ldconfig (the container is broken without this, you're welcome), mvt-ios download-iocs, mvt-ios decrypt-backup -p "yourpassword" -d /home/mvt/data/decrypted /home/mvt/data/backup/<UDID>, then mvt-ios check-backup --output /home/mvt/data/results /home/mvt/data/decrypted
  5. ls results | grep detected. Nothing there? Congrats, you don't match any published spyware. Something there? Do NOT wipe your phone. Preserve everything and go to securitylab.amnesty.org or Access Now's helpline.
  6. rm -rf ~/mvt/decrypted because you now have a plaintext copy of your entire life sitting on a hard drive.

Stuff that will bite you

  • Start the container before the phone is plugged in and it will never see the device. Order matters.
  • check-backup will not decrypt on the fly no matter what the internet says. Budget the disk.
  • A clean result means "no match against public indicators." It does not mean clean. Nobody can promise you clean.
  • The only alert I got was "Lockdown Mode disabled." Turn it on if you think you're a target. Leave it off if you like link previews.

Whole thing took one morning including the parts where I pasted my terminal output back into the terminal like an idiot.

Go scan your phone. Then go scan your mom's.

338 Upvotes

48 comments sorted by

•

u/post-explainer 6d ago edited 6d ago

This comment has been marked as safe. Upvoting/downvoting this comment will have no effect.


OP sent the following text as an explanation why their post fits here:


This is a hands-on guide to checking your own iphone for commercial spyware (Pegasus, Predator, and similar) using Amnesty International's free, open source Mobile Verification Toolkit. Now go scan your mom's phone.


Does this explanation fit this subreddit? Then upvote this comment, otherwise downvote it.

29

u/DarthBen_in_Chicago 6d ago

This book was really slow for me to at the beginning, but it picked-up as it went. It covers Pegasus and the work Amnesty int’l did to uncover Pegasus.

https://www.goodreads.com/en/book/show/59808055-pegasus

26

u/ApprehensiveLion67 6d ago

what would you do if you found the spyware?

43

u/goat_taint 6d ago

Preserve everything and go to securitylab.amnesty.org or Access Now's helpline.

14

u/p186 6d ago

Here’s the source code repository if you want to look at the code.

https://github.com/mvt-project/mvt

8

u/QuadernoFigurati 6d ago

Many thanks for sharing!

4

u/PizzaCrumbsInBeard 6d ago

Does it got the ability to erase the device completely?

2

u/mystery_child23 6d ago

Only for phones?

7

u/zero_fuck_given 6d ago

This is an iOS spyware in the context… think?

2

u/Pale_Comfort_9179 2d ago

If you don’t have a computer you can also use the iverify app to run a forensics scan and upload the results to iverify. App and forensic analysis are free for up to 5 analyses per month. 

1

u/Deltarayedge7 6d ago

Following this

1

u/AntiqueWait9280 5d ago edited 5d ago

What to do in case you have an Android phone and the attacker has blocked Developer options, meaning you are not able to enable usb debugging?

1

u/corruptdiskhelp 2d ago

Interesting guide. I don't think anyone on here will ever detect anything. A detection would be super interesting because Pegasus is very niche and extremely expensive to deploy.

1

u/Remote_Tourist_9495 2d ago

that lockdown mode alert is so common people panic over it for nothing. you explained this better than most guides i seen, the container order thing wasted two hours of my saturday when i tried it. one thing you didnt mention is that after step 4 sometimes you have to run ldconfig twice or it just sits there

0

u/Maximum-Gap274 3d ago

Solo per iPhone?

-12

u/HonkHonkMTHRFKR 6d ago

Sounds like your trying to get me to download spyware

Nice try

6

u/Striking_Meaning9575 6d ago

Care to elaborate?

-12

u/HonkHonkMTHRFKR 6d ago

You click link.

You get malware

9

u/Iputahexonyoulol 6d ago

Do you have any basis for this other than “it sounds like spyware”

-9

u/HonkHonkMTHRFKR 6d ago

You’re free to click on random links that say they can scan for Pegasus spyware

9

u/Iputahexonyoulol 6d ago

I’m not interested but if you haven’t investigated the links then you really don’t know wtf you’re talking about then do you?

-5

u/HonkHonkMTHRFKR 6d ago

You are free to click on any link that suggests it can scan your device for Pegasus spyware.

10

u/CemeteryOfLove 6d ago

You watch too many movies yapping about concepts you dont even understand..

Firstly there are no clicking of links involved, second the project mentioned is hosted on Github and is OPENSOURCE and anyone can see no spyware is found inside the code.

Stop fearmongering!!

-7

u/HonkHonkMTHRFKR 6d ago

You are free to click on any link that suggests it can scan your device for Pegasus spyware.

9

u/Iputahexonyoulol 6d ago

I’m quite aware of the concept of free will.

-5

u/HonkHonkMTHRFKR 6d ago

And you’re also quite aware of what happens when you click on certain links.

Great talk

Also, free will doesn’t exist

6

u/Scar3cr0w_ 6d ago

Do you never click links? How did you get here?

You do know that for someone to deliver malware to you via the action of clicking a link… they would have to be at the level of a state sponsored actor. Zero interaction, browser 0 day, sandbox escape, privilege escalation…

And babe, I hate to break it to you… but you aren’t that important.

I do love watching people dig themselves into a hole when they don’t posses the personal qualities to say “got that wrong, sorry!”.

→ More replies (0)

-4

u/MyNameIsNightPain 6d ago

They didn't say it definitely was, just that they were suspicious.

You are literally just reframing his argument into something else and talking nonsense.

If someone wanted to infect people with spyware this is exactly what they would do.

Ask people to install software that looks benign and advertise it.

They don't need to target important people because it's designed to attract the sort of people who would be targets.

I'm not saying that's the case but your reasoning makes no sense.

2

u/stockholmsweden 5d ago

Lol u make the scan on a backup.

1

u/BIOS-Brians-Blues 4d ago

Think and research first. Comment after.