Trident Spyware Explained: How Pegasus Reached iPhones in 2016 and How Zero-Click Attacks Work Now
Discover how the Trident spyware exploit compromises iPhones using zero-click vulnerabilities. Learn about Pegasus, how the attack works, who's at risk, and how to protect your device.
Quick answer: Trident was a chain of three iOS zero-day flaws (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657) used in 2016 to install NSO Group Pegasus spyware after a user tapped a link. Apple fixed them in iOS 9.3.5. Trident needed one tap, so it was not truly zero-click; later Pegasus attacks such as FORCEDENTRY needed no interaction.
Key takeaways
- Trident used three flaws: a WebKit bug for code execution, a kernel information leak and a kernel memory corruption flaw.
- It was reported in August 2016 by Citizen Lab and Lookout and fixed in iOS 9.3.5.
- Trident needed the victim to open a link, so it was a one-click attack. Zero-click attacks like FORCEDENTRY came later.
- Keep iOS updated, restart regularly and consider Lockdown Mode if you are at high risk.
- If you suspect targeting, contact a digital security helpline or CERT-In rather than relying on a scanning app.
What was Trident spyware?
Trident is the name given to a chain of three previously unknown iOS vulnerabilities. In August 2016, researchers at Citizen Lab and Lookout analysed a link sent by text message to a human rights activist. The link led to a page that exploited the chain and installed Pegasus, a commercial surveillance product made by NSO Group. Apple released iOS 9.3.5 to fix the flaws.
How did the Trident exploit chain work?
The three flaws were used in sequence. The earlier version of this page listed them in a different order and called the attack zero-click, so we corrected both.
| Order | CVE | Flaw | Role |
|---|---|---|---|
| 1 | CVE-2016-4657 | Memory corruption in WebKit (Safari) | Code execution when the link is opened |
| 2 | CVE-2016-4655 | Kernel information leak | Reveals memory layout to defeat protection |
| 3 | CVE-2016-4656 | Kernel memory corruption | Runs code in the kernel and removes restrictions |
Check each entry on the National Vulnerability Database for the official description and Apple advisory references. The step to remember: a browser bug gets code running, then two kernel bugs break out of the sandbox.
Was Trident a zero-click attack?
No. The victim had to tap a link, so it was a one-click attack. A zero-click attack needs no action. The best-known later example is FORCEDENTRY (CVE-2021-30860), found by Citizen Lab in 2021 and delivered through iMessage processing. Apple has since added protections such as BlastDoor for message parsing and an optional Lockdown Mode, introduced with iOS 16. Check Apple documentation for the current feature set.
What can Pegasus do after infection?
Public analyses describe access to messages, calls, contacts, location and, with permissions it gains, the microphone and camera, as well as data from messaging apps. Capabilities vary by version. Rely on Citizen Lab and vendor reports rather than marketing claims. For a broader view of the threat type, read what spyware attacks are and how to prevent them, common malware types and a related surveillance tool, China Massistant.
Who is targeted?
Reports link Pegasus to attacks on journalists, activists, lawyers and officials. Most people are not likely targets, but the defences below cost little and help everyone.
How do you protect your iPhone?
- Install iOS updates promptly. Trident was fixed within days of discovery. Unpatched devices are the main risk.
- Do not open unexpected links, even from known contacts, if the message looks odd.
- Restart the phone regularly. It can disrupt some non-persistent implants.
- Use Lockdown Mode if you are at higher risk. It limits features that attackers use.
- Use a strong passcode and turn on Apple ID two-factor authentication.
- Do not jailbreak a phone you depend on.
How can you check for compromise?
Consumer scanning apps have limits, because iOS does not let apps inspect other apps. Forensic checks use a backup or device logs. Amnesty International has published an open-source tool called MVT, Mobile Verification Toolkit, which checks backups against known indicators (see the project on GitHub). A clean result does not prove safety, because the indicators list covers only known cases. If you think you are a target, contact a digital security helpline, and report to CERT-In where it is a crime.
Can similar spyware hit Android?
Yes. Commercial spyware has been reported on Android as well. The advice is the same: update the system and apps, avoid unknown links, and use built-in protections.
Next steps
Next steps: to learn defence in depth, see our Cyber Security course, and read what spyware attacks are and how to prevent them.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0