Skip to content

The real reason iPhone users get targeted by more expensive attacks than Android users

iPhone security iOS lockdown mode

Android phones get hit by malware far more often than iPhones. That statistic gets repeated constantly, and it is true. But it tells only half the story.

The other half is quieter and more expensive. iPhone owners, in far smaller numbers, are increasingly the specific target of some of the most sophisticated commercial spyware that exists. Not because iOS is weak. Because of who tends to own an iPhone and what an attacker gets in return for the effort.

Understanding iPhone targeted attacks means knowing that volume and value are two different threat models, and iPhone sits closer to the second one than most owners realize.

TL;DR: Android absorbs more mass malware because its open install model and device fragmentation make broad campaigns cheap to run. iPhone absorbs fewer attacks overall but a disproportionate share of expensive, targeted spyware like Pegasus, because iPhone ownership correlates with journalists, executives, and officials whose data is worth a six-figure exploit. Apple’s threat notification system and Lockdown Mode exist specifically because of this asymmetry.

Why the economics point at iPhone specifically?

Commercial spyware is not cheap to build or deploy. A single zero-click iOS exploit chain has reportedly sold for well over a million dollars on the private market, and that price reflects how hard modern iOS is to break into blind, with no tap or click from the target required.

That price only makes sense against a target worth more than the exploit itself. A government tracking a journalist, a state monitoring a dissident, a corporate rival wanting a competitor’s boardroom messages.

iPhone’s user base skews toward exactly the people who fit that profile: executives, officials, lawyers, reporters, all groups that disproportionately carry iPhones in markets where NSO Group’s Pegasus and similar tools like Predator have been documented.

Citizen Lab at the University of Toronto has tracked Pegasus infections across more than 45 countries since 2016, hitting journalists, human rights lawyers, opposition politicians, and business executives specifically, not random consumers. That is not a coincidence of who happens to own an iPhone. It is the entire targeting logic behind why these tools exist.

The scale is bigger than the old narrative suggested

For years, the assumption was that Pegasus-style spyware touched a tiny, rarefied group of the most famous journalists and dissidents on earth.

A December 2024 threat hunting scan by iVerify found seven new Pegasus infections across a batch of roughly 2,500 opted-in devices, spanning iOS versions 14 through 16.6. That is a far higher infection rate than earlier public reporting implied.

Researchers behind the scan noted it suggests state actors are casting a wider net within typically targeted professions than previously assumed, not just picking off a handful of the most famous names.

Amnesty International’s Security Lab has documented the exploit chains behind these campaigns evolving continuously since 2016, moving through several distinct zero-click delivery methods as Apple patched each one.

Pegasus malware explained

I do not carry the kind of profile that would make me a Pegasus target, and neither do most people reading this. But the shift matters because it moves the threat model from famous international journalist down to mid-tier local reporter, in-house counsel, and regional government staffer. The pool of plausible targets got wider even as the tool stayed just as expensive.

Threat categoryTypical targetTypical platformCost to attacker
Commodity malwareGeneral public, largest reachable numberAndroid, mainly sideloaded appsLow
Phishing and scam linksGeneral publicBoth platformsLow
Zero-click spyware (Pegasus, Predator)Journalists, officials, executives, lawyersiPhone and Android, more iPhone reportingVery high
Targeted phishing against high-value individualsExecutives, public figuresBoth platformsModerate

Apple already built the response, and most iPhone owners have never touched it

Apple has sent threat notifications to people in more than 150 countries since 2021 whenever it detects patterns consistent with mercenary spyware targeting, according to its own security documentation.

Getting one of these notifications is treated as a strong signal to do a forensic check, not something Apple sends casually.

The company also shipped Lockdown Mode in iOS 16 specifically for this threat category. It restricts message attachment previews, disables certain web rendering technologies, and blocks unknown accessories from connecting over a wired connection, all aimed at shrinking the attack surface a zero-click exploit needs to work.

Access Lockdown mode in the iPhone Privacy settings. Here are the complete steps.

  1. Open the iPhone Settings app > Privacy and Security
  2. Scroll to Lockdown Mode and tap on it. [It remains off by default]
  3. Tap on Turn On Lockdown Mode.
    iPhone lockdown mode

I dug into how this compares against Android’s own protections in a rundown of iPhone security features Android still lacks, and Lockdown Mode is the clearest example of a feature built for a threat model most users will never personally face, shipped to every compatible device anyway.

Android is not immune; it just gets targeted differently

None of this means Android phones are safe from the same category of tool. Pegasus and its counterpart Chrysaor have infected Android devices too.

Researchers at Corrata noted that by 2025 and 2026, newer iOS exploit chains had been published publicly enough that attackers no longer needed NSO-level resources to mount a campaign against an unpatched phone.

This shift is worth sitting with. Sophisticated spyware used to require nation-state budgets. Some of that capability is now cheap enough that a broader set of actors can use it, on both platforms.

The reason Android does not dominate the same headlines is not that Android is architecturally immune. It is that most of Android’s attack volume comes from a completely different, cheaper category: commodity malware distributed through sideloaded apps and fake install prompts, aimed at the largest possible number of ordinary users rather than a specific named target.

My own Android phone has warned me before sideloading enough times that I know exactly what that commodity threat model feels like day-to-day. A screen I tap through, not a targeted campaign built around who I am.

That is genuinely a different kind of risk than a zero-click exploit built to surveil one specific person’s WhatsApp messages. Whether that math changes further, given how much exploit code has leaked into wider circulation, is not fully settled.

If you want a broader read on how the two platforms compare on ordinary, everyday risk rather than nation-state spyware, the current Android vs iOS security landscape covers the update policy and sideloading side of that picture.

What this actually means if you are not a journalist or executive

For the overwhelming majority of iPhone owners, none of this changes daily behavior. You are not the target these tools were built for, and no realistic threat model for a typical consumer includes a six-figure zero-click exploit.

What it does mean is that the flat statement iPhone is safer stops being useful once you ask safer against what. Against mass market malware and drive-by app store scams, iPhone’s closed review process still does real work.

Against a resourced actor specifically interested in your phone, the calculus flips, and iPhone’s popularity among high-value targets is itself part of the threat surface.

If your job puts you anywhere near journalism, law, activism, or a position with access to sensitive information, checking Apple’s own guidance on threat notifications and Lockdown Mode is worth the ten minutes, regardless of which phone you carry, because the tools tracking this threat category do not stay confined to one operating system for long.

Leave a Reply

Your email address will not be published. Required fields are marked *