What is spyware on an iPhone?
Spyware on an iPhone is a type of malicious software that runs in the background, collects personal data — text messages, call logs, photos, location, microphone recordings, and camera recordings — and sends it to a third party without your consent.
Apple’s iOS is more tightly controlled than Android. Every App Store app goes through a review process, apps are sandboxed from each other, and Apple regularly issues security updates. These protections make mass iPhone spyware infections rare, but not impossible.
Spyware can still reach an iPhone through targeted attacks, phishing campaigns, physical access to the device, or zero-click exploits. Zero-click exploits are particularly stealthy because they require no interaction from you. Jailbreaking also removes key iOS protections, which makes it easier for spyware to install and run.
If you’re reading this article because your mobile phone feels sluggish, has poor battery life, or overheats, the most likely explanation is a hardware or software issue. Older iPhones slow down. Batteries degrade. Background app activity can spike. However, it’s still worth ruling out spyware, and the steps below will help you do exactly that.
Common types of iPhone spyware
Not all iPhone spyware works the same way. Understanding the main categories helps you recognize what you might be dealing with and where the risk actually comes from.
- Commercial spyware (stalkerware) includes apps built to monitor someone’s location, messages, call logs, and browsing activity. Developers often market these tools as iPhone parental controls or employee monitoring software, but they’re frequently misused for covert surveillance.
- Advanced mercenary spyware is built for state-level surveillance rather than consumer use. Sophisticated spyware, such as Pegasus, Predator, and Graphite, exploits zero-day vulnerabilities — security flaws Apple hasn’t yet patched — to gain deep, undetected access to a target’s iPhone.
DID YOU KNOW?
In March 2026, Google TAG, Lookout, and iVerify disclosed two iOS exploit chains — DarkSword and Coruna. Attackers used these exploit chains to compromise targeted iPhones and deliver spyware payloads, including GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER.1
- Adware-based spyware collects your browsing habits and serves intrusive ads. It typically arrives through drive-by downloads on malicious websites or poorly vetted apps.
- Malicious configuration profiles require an attacker to have either physical access to your device or a convincing enough ruse to get you to install a rogue profile yourself. Once installed, the profile can intercept your network traffic, redirect your browsing, or give the attacker partial remote access to your device.
How spyware gets on an iPhone
Spyware reaches iPhones through a range of methods, from low-tech social manipulation to sophisticated exploit chains that require no interaction from your end. Knowing the delivery routes helps you understand which risks apply to you.
Phishing and social engineering
Phishing is one of the most common entry points for spyware attacks. Attackers send fake emails, SMS messages, or direct messages in social and messaging apps that look like they’re from Apple, a bank, a delivery company, or a trusted contact.
Their goal is to get you to click a malicious link, install a rogue configuration profile, or enter credentials on a fake page. If you’ve ever clicked on a phishing link by mistake, you’ll know how convincing these messages can look.
Spyware doesn’t always install right away. Sometimes the link leads to a site that exploits an unpatched browser flaw and installs spyware without any further action from you.
Jailbreaking
Jailbreaking removes Apple’s built-in security restrictions, which allows the device to run apps and code that wouldn’t normally pass Apple’s checks. A jailbroken iPhone loses its protections for app isolation, code signing, and system access, which makes it far easier for malware to gain deep system access. Someone with physical access to an unlocked jailbroken device can also install stalkerware without your knowledge.
One-click exploits
One-click exploits require a single action from you — such as tapping a link, opening a document, or previewing an attachment — to trigger an exploit chain. You may not need to approve permissions or enter credentials. If the exploit works, one tap can be enough to install spyware and give attackers access to your device.
Zero-click exploits
Zero-click exploits are among the most dangerous spyware delivery methods because they can compromise a device without a tap, link click, or file download. Pegasus spyware, developed by NSO Group, has been used in zero-click attacks against iPhones, including iMessage-related exploit chains. NSO Group tools have also been linked to network-based attacks that can infect a device without visible interaction from the target.2
Predator spyware, linked to Cytrox and the Intellexa alliance, has also been delivered through network injection. In one documented case, a target’s mobile connection was redirected without warning to a malicious site designed to install Predator.3
Zero-click mercenary spyware usually targets a narrow group of high-value individuals, including journalists, activists, politicians, human rights defenders, and diplomats. In 2025, the Italian government confirmed that its intelligence services used Graphite, spyware developed by Paragon Solutions, against civil society figures.4
Watering-hole and drive-by attacks
Watering-hole attacks work by compromising websites that the target already trusts. An attacker injects exploit code into a legitimate page — a government portal, a news site, or a community forum — and waits for the target to visit. For example, in March 2026, Google Threat Intelligence Group disclosed the DarkSword exploit chain, which used the watering-hole method. Visitors to compromised Ukrainian websites were at risk of spyware infection without knowing it.5
Drive-by attacks use a similar infection method, but they don’t depend on a specific trusted website. Instead, attackers spread links to malicious pages and wait for unsuspecting users to land on them. In both cases, the device can be compromised without the target clicking a suspicious pop-up, opening a file, or approving a download. These attacks weaken the usual “don’t click suspicious links” advice because a risky page may appear legitimate or come from a source the target already trusts.
Physical access and stalkerware
Someone with physical access to an unlocked iPhone can install commercial monitoring apps or add malicious configuration profiles before handing the device back. Stalkerware apps often hide their icons or disguise themselves as harmless tools after installation, while sending location data, messages, and call logs to whoever installed them.
Installing spyware on another person’s device without their knowledge or consent is illegal in most jurisdictions. It’s also a serious violation of privacy, regardless of whether the installer is a partner, parent, or employer.
Potential signs of spyware on an iPhone
The signs below are useful for detecting commercial stalkerware and less sophisticated infections. Mercenary spyware like Pegasus or Predator may show no visible signs. In those cases, the steps in this section won’t be enough on their own. If you want to know how to tell if your iPhone is hacked, this section is a good starting point.
IMPORTANT
Before going through the list below, two caveats are worth stating upfront:
- 1.None of these signs are exclusive to spyware. Battery drain, overheating, sluggish performance, and high data usage are common symptoms of an aging device, a demanding app, a weak signal, or a software bug. Most of the time, one of those causes is more likely.
- 2.If spyware has deep access to the device, the iPhone may no longer show reliable warning signs. Sophisticated spyware may bypass the orange and green privacy indicators, so the dots may not appear even when the microphone or camera is active. The same spyware may also interfere with battery readings, data usage figures, and other security indicators.
Unusual battery drain or overheating
Spyware can increase background activity by collecting data, tracking location, or sending information from the device. That extra activity can drain the battery and make the iPhone feel warm during light use. If you notice these symptoms and can’t link them to a specific app, recent update, poor signal, or a change in usage, spyware is worth ruling out.
Unexpected data usage spikes
Spyware may send collected data to a remote server. The transfer can increase mobile data usage, especially if the spyware sends large files or uploads data often. On an iPhone, go to “Settings” and open “Cellular,” “Mobile service,” or “Mobile network,” depending on your region. Look for unusual spikes or apps you rarely use that appear near the top of the data usage list.
Unusual network behavior
Beyond high data usage, look for subtle network signals. These may include outbound connections to unfamiliar domains detected through a network monitoring tool, router log, VPN report, or DNS log. DNS — the system your device uses to turn website names into IP addresses — may also show warning signs, such as failed lookups, unexpected DNS servers, or requests to unfamiliar domains.
These signs are more technical than a simple data usage spike. Basic stalkerware apps are less likely to hide them when the monitoring happens outside the phone, such as on a router or separate network tool.
Still, Wi-Fi failures and DNS issues often have ordinary causes, including router problems, VPN settings, ad blockers, DNS filters, or software bugs. Treat unusual network behavior as a warning sign only when it appears alongside other indicators covered in this section.
Strange app behavior and poor iPhone performance
Unexplained app crashes, spontaneous reboots, or an iPhone that performs noticeably slower than usual can indicate spyware activity. Watch for pop-ups outside Safari or another app you recognize, websites that redirect to pages you didn’t request, and notifications from apps you don’t remember installing.
Still, crashes, redirects, and slow performance often have ordinary explanations. Low storage, an aging battery, a buggy app, or a software update can affect performance. Malicious ads and browser notification spam can also cause pop-ups or unwanted redirects.
Camera or microphone activating unexpectedly
iOS displays an orange dot when an app accesses the microphone and a green dot when an app accesses the camera. If you see either indicator when you’re not on a call or using an app that needs those sensors, check which app triggered it.
On iPhones with Face ID, swipe down from the top-right corner to open Control Center. On iPhones with a “Home” button, swipe up from the bottom edge. Control Center shows the most recent app to access the microphone or camera.
Advanced spyware like Predator has been documented to bypass these indicators, which means their absence doesn’t confirm your device is free of spyware. If your iPhone microphone or iPhone camera turns on by itself and you can’t identify the cause, investigate further using the steps below.
Unfamiliar apps or configuration profiles
Apps you don’t remember installing are a serious warning sign, especially if they appear out of nowhere or on a device a partner, family member, or employer shouldn’t be able to access. Unknown profiles under “Settings” > “General” > “VPN & device management” are less obvious but just as important.
A malicious configuration profile can change network settings, install certificates, configure a VPN, or enroll your iPhone in device management. Those changes may allow someone to secretly monitor, redirect, or filter parts of your traffic without your knowledge and without placing an app icon on your home screen. A profile may also not appear in battery and data usage logs the way a normal app would.
How to check for spyware on an iPhone
If the signs above concern you, work through the checks below methodically. Start with the simplest checks and move to the more technical options only if the earlier steps don’t resolve your concern.
Check for unfamiliar apps
Go through your home screen and App Library. Look for apps you don’t remember installing. If you find an unfamiliar app, check the App Store, Apple Support, or Google to find out what the app does before deleting it — some unfamiliar apps are legitimate system apps Apple installs with iOS updates.
Review configuration profiles
Go to “Settings” > “General” > “VPN & device management” to check for installed configuration profiles. If this section doesn’t appear in your “Settings,” no profiles are installed.
Check app permissions
Go to “Settings” > “Privacy & security” and review which apps have access to your camera, microphone, location, contacts, and photos.
Monitor battery and data usage
Go to “Settings” > “Battery” to see which apps use the most battery power. Go to “Settings” and open “Cellular,” “Mobile service,” or “Mobile network” to review data usage by app. Pay close attention to unfamiliar or rarely used apps that appear high on either list.
Use iOS Safety Check
Safety Check (“Settings” > “Privacy & security” > “Safety check”) lets you review and reset who has access to your information across apps, people, and devices signed in to your Apple Account. It doesn’t detect spyware directly, but it shows permissions and data-sharing settings you may no longer be aware of. Use “Emergency reset” to stop all sharing at once.
Check for Apple threat notifications
Apple sends threat notifications to users it believes have been targeted by mercenary spyware. Apple has sent these notifications to users in over 150 countries since the program launched in 2021. The notification appears as an alert on the iPhone Lock Screen and in “Settings,” as a banner at the top of account.apple.com after you sign in, and as an email to the addresses associated with your Apple Account.6
A genuine Apple threat notification will never ask you to click a link, open a file, install an app or profile, or provide your Apple Account password or verification code. Attackers send phishing messages designed to mimic these notifications. If a message requests credentials or asks you to install an app or profile, it isn’t from Apple.
PRO TIP
Need step-by-step checks with screenshots? Read our guide on how to check your iPhone for viruses and malware.
How to detect hidden spyware on an iPhone
The checks above cover the basic spyware detection methods. If you still suspect spyware, use the methods below to check for more signs of hidden compromise.
- Look for signs of jailbreaking. If you bought a second-hand iPhone, check for apps like Cydia or Sileo, which are third-party app stores associated with jailbroken devices. Also check whether core apps like Safari or Camera are missing or restricted. Their absence doesn’t prove the phone is jailbroken, but the restriction may point to unusual system changes that need further investigation.
- Check for unusual background activity. Review screen time data (“Settings” > “Screen time”) to see which apps are active and for how long. Then review battery usage by app (“Settings” > “Battery”) to spot apps that consume unusual amounts of system resources. These screens mostly show app-level activity. Advanced spyware may not appear in these views.
- Use USSD codes to check carrier-level forwarding. Dial #21# to check unconditional call forwarding and #62# to check forwarding when your phone is unreachable.
PRO TIP
USSD codes only show carrier-level forwarding settings. A listed number may be your voicemail service, and a clean result doesn’t mean your device is free of spyware. These codes can’t detect spyware itself.
- Use third-party detection tools. The iVerify Basic app can check for indicators of compromise and signs of infection. iVerify’s research team analyzed the Coruna exploit framework, and iVerify says it discovered DarkSword with Google TAG in March 2026, which gives its consumer tool added credibility.7,8
Keep in mind that no consumer app can definitively confirm or rule out mercenary spyware. These tools can help surface signs of compromise, but they’re not a substitute for expert forensic analysis in Pegasus-class cases. Good iPhone security starts with the basics, but understanding the limits of detection tools is just as important as using them.
How to detect advanced iPhone spyware, such as Pegasus and DarkSword
Mercenary spyware and advanced iOS exploit chains — including Pegasus, Predator, Graphite, DarkSword, and Coruna — operate beyond the reach of most consumer detection tools. These threats are built to evade detection and may use capabilities once associated mainly with state-backed or commercial surveillance actors. The following detection methods won’t give you certainty, but they represent the best options available to journalists, activists, and people at elevated risk.
- Check Apple threat notifications. If you receive a notification, follow the instructions provided in it.
- Use Mobile Verification Toolkit (MVT). MVT is an open-source forensic tool developed by Amnesty International’s Security Lab. It analyzes iPhone backups and forensic files against indicators of compromise (IOCs) for Pegasus and other known spyware activity.
Amnesty released MVT as part of the Pegasus Project investigation. MVT usually requires a computer running macOS or Linux, an encrypted iTunes or Finder backup of your iPhone, and familiarity with the command line. It isn’t a tool for most users, but for people at elevated risk, it’s one of the most credible public forensic options available. However, a clean MVT result doesn’t prove your iPhone is free of spyware. It only means the tool didn’t find known traces of compromise.
How to get rid of spyware on an iPhone
If you have reason to believe you’ve been targeted by mercenary spyware, read the “Get expert help” section below before resetting or changing your device. A factory reset destroys the forensic evidence that researchers need to identify the attack and may use to determine who carried it out.
If you’re dealing with suspected stalkerware, malicious profiles, phishing-based spyware, or another non-mercenary threat, work through the following steps in order.
Disconnect from the internet
Enable airplane mode. Airplane mode cuts off active data exfiltration and command-and-control communication while you work through the remaining steps. Start here before moving to the next step.
Restart your iPhone
A full restart clears most memory-resident exploits — spyware that runs in RAM rather than permanent storage. However, restarting your device also destroys some forensic evidence.
Update iOS
Install the latest iOS version. Go to “Settings” > “General” > “Software update.” Spyware often depends on specific vulnerabilities — closing them can stop the exploit chain from working again and reduce the attacker’s access.
Coruna targeted iPhones running iOS 13 through 17.2.1, while DarkSword was observed targeting newer iOS 18 versions, including iOS 18.4 through 18.6.2. Apple addressed the vulnerabilities used in these reported attacks through later iOS updates. Apple also released additional iOS 15 and iOS 16 security updates on March 11, 2026, to protect older devices that couldn’t update to iOS 26.
Remove unknown configuration profiles
Go to “Settings” > “General” > “VPN & device management,” and delete profiles you didn’t install yourself unless your employer or school requires them.
Delete suspicious apps
Long-press apps you don’t recognize, tap “Remove app,” then select “Delete app.” Work through your full App Library, not just the home screen.
Clear browser data
Go to “Settings” > “Apps” > “Safari” > “Clear history and website data.” Clearing your browser data can remove cached scripts, cookies, and site data linked to browser-based attacks. If suspicious Safari extensions, redirects, or browser data reappear after deletion, treat that as a sign of a device-level infection. You can also clear other app caches on your iPhone to remove stored data that spyware may have accessed.
Reset all settings
If spyware persists after the steps above, go to “Settings” > “General” > “Transfer or reset iPhone” > “Reset” > “Reset all settings.” A settings reset returns every system setting to its default state, which can remove persistent settings or network changes without erasing your iPhone. Try a settings reset before using a factory reset as a last resort.
Factory reset your iPhone
A full iPhone factory reset is the most reliable consumer-level way to remove confirmed spyware. Before you start, back up photos, contacts, and documents — but use a backup made before infection symptoms began. Restoring from a recent backup can bring back malicious profiles, apps, or settings. The safest approach is to set up the iPhone as new and reinstall apps from the App Store rather than from a backup.
To factory reset your iPhone, go to “Settings” > “General” > “Transfer or reset iPhone” > “Erase all content and settings.”
PRO TIP
Our guide on how to remove malware from your iPhone covers the full factory reset process step by step.
Get expert help
If you have reason to believe you’ve been targeted by mercenary spyware, civil society organizations with forensic expertise offer free help:
- The Access Now Digital Security Helpline offers free, 24/7 emergency security support for at-risk users.
- The Amnesty International Security Lab offers free digital forensic analysis for human rights defenders, activists, journalists, and other civil society members.
- The Citizen Lab at the University of Toronto conducts forensic research into targeted surveillance and has investigated spyware attacks against journalists, activists, politicians, and civil society groups.
These organizations can provide expert guidance, forensic analysis, referrals, and remediation support that consumer-grade tools can’t provide. Contact them before resetting your device — a factory reset destroys the forensic evidence they may need.
How to protect your iPhone from spyware
The best time to protect your iPhone from spyware is before your device is compromised. These habits reduce your exposure to stalkerware, phishing, malicious profiles, and advanced spyware attacks.
Keep iOS and apps updated
Install iOS updates and app updates as soon as they’re available. Starting with iOS 26.1, Apple uses Background Security Improvements to deliver lightweight security patches between full software updates.
Restart your iPhone regularly
Many advanced exploits are memory resident, which means they run in RAM and can disappear after a reboot. A restart won’t detect spyware or remove persistent infections, but it can disrupt some active surveillance sessions. If the spyware lacks persistence, attackers may need to reinfect the device to regain access.
Download apps only from the App Store
Apple reviews every app before it appears in the App Store. Avoid installing apps from third-party websites or unofficial app stores — apps distributed outside the App Store bypass Apple’s review process and can carry spyware or other malicious code.
Be careful with links and trusted websites
Don’t tap links in unsolicited emails, texts, or direct messages. If a message seems unusual — even from someone you know — treat it with caution. One-click exploits require only a single tap to trigger spyware installation.
This advice can’t be used against watering-hole attacks, where the compromised page is a legitimate site you already trust. Against watering-hole attacks, keeping iOS updated is the most reliable defense available.
Don’t jailbreak your iPhone
Jailbreaking removes the security protections that keep unauthorized code off your device. Without those protections, attackers can install stalkerware and other malicious apps without your knowledge. The customization benefits aren’t worth the security risk.
Use strong passwords and two-factor authentication
Secure your Apple Account with a strong, unique password and enable two-factor authentication. If an attacker gains access to your Apple Account, they may be able to access your iCloud data, backups, photos, or device location. Change your iPhone passcode periodically — particularly if a partner, family member, or employer has had physical access to your device.
Regularly review app permissions
Check which apps have access to your camera, microphone, location, contacts, and photos under “Settings” > “Privacy & security.” Revoke permissions for apps you don’t use or that have no clear reason to access them.
Enable lockdown mode
If you’re a journalist, activist, diplomat, or lawyer, enable lockdown mode under “Settings” > “Privacy & security” > “Lockdown mode.” Apple’s lockdown mode is an extreme protection setting designed for users at high risk of targeted attack. It blocks most message attachment types, rejects incoming FaceTime calls from people you haven’t called within the past 30 days, prevents the installation of configuration profiles, and restricts some web browsing technologies.
Apple has reportedly said it isn’t aware of a successful mercenary spyware attack against a device with lockdown mode enabled.9 Lockdown Mode limits everyday functionality and isn’t designed for general use, but for people at elevated risk, the tradeoff may be worth accepting.
Use digital security tools for safer browsing
NordVPN offers a digital security app with a VPN and scam and phishing protection. A VPN encrypts your internet traffic, which makes it harder for attackers to intercept data in transit or monitor your traffic on public Wi-Fi. If you’re connected to a NordVPN server, scam and phishing protection can block ads, trackers, and unsafe domains, including malware, scam, and phishing domains.
Keep in mind that a VPN doesn’t defend against zero-click attacks like Pegasus or watering-hole attacks like DarkSword. Those exploits target vulnerabilities in the device, browser, or operating system — not the network connection. For those threats, iOS updates and Lockdown Mode offer stronger protection. For everyday privacy on public Wi-Fi and reduced exposure to phishing sites, private browsing on an iPhone combined with NordVPN can lower your risk.
Online security starts with a click.
Get a VPN on your iPhone and browse with more confidence
Disclaimer: The trademarks referenced are for illustrative purposes only. NordVPN is not affiliated with, sponsored by, or endorsed by the owners of those trademarks.
FAQ
References
1 Google Threat Intelligence Group. (2026, March 18). The proliferation of DarkSword: iOS exploit chain adopted by multiple threat actors. Google Cloud Blog. https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain opens in a new tab
2 Amnesty International. (2021, July 18). Forensic methodology report: How to catch NSO Group’s Pegasus. https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/ opens in a new tab
3 Amnesty International Security Lab. (2023, October 5). Predator Files: Technical deep-dive into Intellexa Alliance’s surveillance products. Amnesty International. https://securitylab.amnesty.org/latest/2023/10/technical-deep-dive-into-intellexa-alliance-surveillance-products/ opens in a new tab
4 Access Now. (2025, June 6). No normalising spyware: Italy admits use, but not the full extent. https://www.accessnow.org/press-release/no-normalising-spyware-italy/ opens in a new tab
5 Google Threat Intelligence Group. (2026, March 18). The proliferation of DarkSword: iOS exploit chain adopted by multiple threat actors. Google Cloud Blog. https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain opens in a new tab
6 Apple. (2026, August 13). About Apple threat notifications and protecting against mercenary spyware. Apple Support. https://support.apple.com/en-us/102174 opens in a new tab
7 Frielingsdorf, M. (2026, March 3). Coruna: Inside the Nation-State-Grade iOS Exploit Kit We’ve Been Tracking. iVerify. https://iverify.io/blog/coruna-inside-the-nation-state-grade-ios-exploit-kit-we-ve-been-tracking opens in a new tab
8 Frielingsdorf, M. (2026, March 18). Inside DarkSword: A New iOS Exploit Kit Delivered Via Compromised Legitimate Websites. iVerify. https://iverify.io/blog/darksword-ios-exploit-kit-explained opens in a new tab
9 Franceschi-Bicchierai, L. (2026, March 27). Apple says no one using Lockdown Mode has been hacked with spyware. TechCrunch. https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/ opens in a new tab