Abhigya Mahajan
Pegasus is a malware classified as spyware that is designed to gain access to devices without the knowledge of users, collect personal data, and relay it back to whoever it is that’s utilizing the program to spy. It has progressed from spear-phishing, a strategy in which an aggressor lures the target into clicking on a malicious interface sent via content message or email, to a more advanced strategy of attack known as zero-click attacks. This modern shape of assault has made the computer program one of the foremost perilous spyware that debilitates individual’s security. Concurring to an investigative report by a consortium of media outlets, thousands of activists, journalists and political leaders across the world were targeted by clients of an Israeli spyware maker NSO Group. Over 300 Indians counting two serving ministers in the Present Government, three opposition leaders, journalists, human rights activists, and businessmen are said to a part of the leaked list of possible targets. At the heart of the hack is a powerful spyware called Pegasus, which uses zero day vulnerability in the operating systems (OS) to enter into a targeted individual’s phone. Utilizing this misuse, Pegasus can infect both iOS and Android mobile phones, and turn them into surveillance gadgets. A zero-click attack helps spyware like Pegasus gain control over a device without human interaction or human error. So all awareness about how to dodge a phishing attack or which links not to click are pointless if the target is the system itself. Most of these attacks exploit software which receive data even before it can determine whether what is coming in is reliable or not, like an email client.
Given their nature, zero-click attacks are difficult to detect and even more difficult to prevent. Detection becomes even more difficult in encrypted environments where the data packets being sent or received are not visible. Although the majority of people are unlikely to be targeted by this type of attack, there are still simple steps you can take to reduce your potential exposure – not only to Pegasus, but also to other malicious attacks. One thing users can do is ensure that all operating systems and software are up to date so that they have patches for at least the vulnerabilities that have been discovered. It would also make sense not to side load any apps and to only download from Google Play or Apple’s App Store. If you are paranoid, one way to go is to stop using apps altogether and switch to the browser to check emails or social media, even on the phone. Yes, this is inconvenient, but it is more secure, according to experts. Only open links from known and trusted contacts and sources when using your device. If you use Android, don’t rely on notifications for new versions of the operating system. Check for the latest version yourself, as your device’s manufacturer may not be providing updates. Although it may sound obvious, you should restrict physical access to your phone. Enable pin, finger, or face-locking on the device to accomplish this. The website of the eSafety Commissioner contains a number of videos that explain how to configure your device securely. Avoid using public or free WiFi services, including those provided by hotels, especially when accessing sensitive information. When you need to use such networks, using a VPN is a good solution. Encrypt your device’s data and, if available, enable remote-wipe features. If your device is lost or stolen, you will have some peace of mind that your data will be safe.
On the other hand, with countries resorting to digital warfare and hackers targeting business organizations and government processes, India must raise awareness that no individual or institution is immune. While the government and business may be better suited to develop their own programmes, it is civil society that must bring this into the fold. Cyber security initiatives such as the National Cyber Coordination Centre (NCCC), the National Critical Information Infrastructure Protection Centre (NCIIPC), and the Computer Emergency Response Team (CERT) must be strengthened and evaluated. Courses on cyber security must be included in educational institutions such as central universities, private universities, industry associations, and Industrial Training Institutes (ITIs). Given the growing dominance of mobile and telecommunications, both National Cyber Security Policy and National Telecom Policy will need to effectively collaborate to create a comprehensive policy for 2030. There is a need to create opportunities for software development in order to protect cyber security and digital communications. The Indian government may consider incorporating cyber security architecture into its Make in India programme. In addition, suitable hardware based on a unique Indian pattern that can serve localized needs is required. Given the future of technology under Industrial Revolution 4.0, India requires a strong cyber security framework based on the 4D principles i.e. Deter, Detect, Destroy and Document to counteract any cyber challenges.
(The author is a Lecturer in UIET, University of Jammu).
