{"id":8521,"date":"2023-12-11T12:00:00","date_gmt":"2023-12-11T10:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/?p=8521"},"modified":"2026-06-14T19:34:18","modified_gmt":"2026-06-14T16:34:18","slug":"silent-but-deadly-the-rise-of-zero-click-attacks","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2023\/12\/11\/silent-but-deadly-the-rise-of-zero-click-attacks\/","title":{"rendered":"Silent but deadly: The rise of zero-click attacks"},"content":{"rendered":"<p>In a world of instant communication and accelerated by the ever-spreading notion that if you are not connected or available, you might be the odd one out, messaging has, in many ways, become a crucial form of communication and personal connection, especially for the <a href=\"https:\/\/chitchatagency.com\/the-rise-of-messaging-how-gen-z-and-millennials-prefer-to-communicate\/\">younger generations<\/a>.<\/p>\n<p>In this context, cybercriminals may find greater ease in succeeding with their schemes, as messaging someone is straightforward, and human error can facilitate the rest. However, sometimes, not even human error is needed. We&#8217;re delving into the realm of zero-click attacks, which, as the name implies, might signal an end to the era of blatantly obvious phishing messages with their humorous grammar errors. But is this truly the case?<\/p>\n<h2>Wait, I didn\u2019t do anything<\/h2>\n<p>What are zero-click attacks? Unlike your <a href=\"https:\/\/www.welivesecurity.com\/2020\/12\/23\/7-ways-malware-can-get-your-device\/\">traditional exploitation opportunities<\/a> of tricking users into providing access by opening an infected attachment or clicking on a rogue link, this attack does not require that kind of interaction.<\/p>\n<p>Most zero-click attacks rely on <a href=\"https:\/\/www.theregister.com\/2019\/05\/14\/whatsapp_zero_day\/\">vulnerabilities in applications<\/a>, especially those meant for messaging, SMS, or even email apps. Consequently, if a particular app has an unpatched vulnerability, the attacker can tamper with its data stream. That can be an image or a text you\u2019re about to send. Within this media, they can hide manipulated data that exploits a vulnerability to execute malicious code without your knowledge.<\/p>\n<p>This lack of interaction means that it is harder to track malicious activity, making it easier for threat actors to evade detection; enabling the installation of <a href=\"https:\/\/www.welivesecurity.com\/2017\/02\/17\/8-things-know-spyware\/\">spyware<\/a>, <a href=\"https:\/\/www.welivesecurity.com\/2019\/06\/25\/stopping-stalkerware-change\/\">stalkerware<\/a>, or other forms of malware; and allowing criminals to track, monitor, and harvest data off of an infected device.<\/p>\n<p>For example, in 2019, it was <a href=\"https:\/\/www.dw.com\/en\/whatsapp-attacked-by-advanced-spyware-via-missed-calls\/a-48726819\">discovered that WhatsApp<\/a>, a popular messaging app, was vulnerable to a particular zero-click attack, wherein a missed call could exploit a vulnerability inside the app\u2019s code. This way, attackers were able to compromise the device the app was on to infect it with spyware. Thankfully, the developers managed to patch this one, but the case shows that even a missed call was able to trigger an infection.<\/p>\n<h2>Is there any protection against zero-click attacks?<\/h2>\n<p>More and more companies are now focusing on dealing with zero-clicks. For example, Samsung mobile phones now offer a solution that pre-emptively secures users by limiting exposure to invisible threats disguised as image attachments, called <a href=\"https:\/\/news.samsung.com\/za\/samsung-message-guard-protects-you-from-new-and-invisible-threats\">Samsung Message Guard<\/a>, a part of its <a href=\"https:\/\/www.samsungknox.com\/en\">Knox<\/a> security platform.<\/p>\n<p>SMG checks files bit by bit and processes them in a controlled environment, a sandbox essentially to quarantine images from the rest of the operating system, akin to a function that many modern antivirus solutions have.<\/p>\n<p>It joins the ranks of security solutions such as <a href=\"https:\/\/9to5mac.com\/2021\/01\/28\/apple-adopts-new-blastdoor-security-system-on-ios-14-to-reinforce-imessage-integrity\/\">Apple\u2019s BlastDoor<\/a>, which checks data within iMessage similarly, preventing message and OS interaction by sandboxing the iMessage app so that threats have a harder time reaching outside the service. This solution came after experts uncovered a weakness in iMessage that was used to install <a href=\"https:\/\/www.bloomberg.com\/news\/features\/2023-01-24\/nso-group-s-pegasus-spyware-focus-of-us-eu-investigations\">mercenary spyware<\/a> against individuals, mostly politicians and activists, to read their texts, listen to calls, collect passwords, track their locations, and access their microphones, cameras, and more \u2013 a rather insidious piece of malware, all without any semblance of user interaction.<\/p>\n<p>However, caution is still to be exercised even with anti-zero-click solutions, as there can still be vulnerabilities that threat actors can <a href=\"https:\/\/thehackernews.com\/2023\/04\/nso-group-used-3-zero-click-iphone.html\">exploit<\/a> to gain access to your device. This is especially true for phones with outdated software, as they are less likely to have patched vulnerabilities.<\/p>\n<h2>Starting from ground zero<\/h2>\n<p>While zero-click attacks require nearly no interaction and tend to target high-profile individuals or anyone with some public visibility, there are still a few basic cybersecurity tips that can be useful to avoid these kind of attacks:<\/p>\n<ul>\n<li>Keep your devices and apps updated, especially as soon as security updates are available.<\/li>\n<li>Purchase phones from brands that have a great track record of providing updates (at least include regular security updates and for at least three years).<\/li>\n<li>Try to stick to official app stores, like Google Play or Apple\u2019s App Store, as these audit any new releases and thus are more likely to be safe.<\/li>\n<li>If you are not using an app, delete it, and watch out for <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/badbazaar-espionage-tool-targets-android-users-trojanized-signal-telegram-apps\/\">malicious app copycats<\/a>.<\/li>\n<li>Back up your device regularly to recover your data in case you need to reset your device.<\/li>\n<li>Bump up your security with a <a href=\"https:\/\/www.eset.com\/int\/home\/mobile-security-android\/\">mobile antivirus<\/a> solution.<\/li>\n<li>In general, practice <a href=\"https:\/\/www.welivesecurity.com\/2018\/10\/05\/make-cyber-habit-five-simple-steps-staying-safe-online\/\">cybersecurity hygiene<\/a>.<\/li>\n<\/ul>\n<blockquote>\n<p>An insightful <a href=\"https:\/\/www.welivesecurity.com\/2016\/04\/05\/vulnerabilities-exploits-and-patches\/\">interview<\/a> on vulnerabilities.<\/p>\n<p>More on <a href=\"https:\/\/www.privacyaffairs.com\/zero-click-explois\/\">zero-click exploits<\/a>.<\/p>\n<\/blockquote>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/en\/mobile-security\/silent-but-deadly-the-rise-of-zero-click-attacks\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A security compromise so stealthy that it doesn\u2019t even require your interaction? Yes, zero-click attacks require no action from you \u2013 but this doesn\u2019t mean you\u2019re left vulnerable.<\/p>\n","protected":false},"author":5,"featured_media":8522,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2905],"tags":[],"class_list":["post-8521","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devices"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8521","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8521"}],"version-history":[{"count":1,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8521\/revisions"}],"predecessor-version":[{"id":9151,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8521\/revisions\/9151"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8522"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8521"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8521"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8521"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}