What Is a Zero-Click Attack? Why You Don't Have to Click Anything to Get Hacked

Key Takeaways
Every cybersecurity lesson you've ever been taught starts the same way: don't click on suspicious links. Don't open strange attachments. Don't download files from people you don't know. It's good advice, but it's no longer enough.
A new breed of cyberattack doesn't need you to click a single thing. No link. No attachment. No download prompt. Your phone or computer can be completely compromised while you're doing absolutely nothing, maybe even while you sleep.
They're called zero-click attacks, and they're one of the most dangerous and misunderstood threats in cybersecurity today.
What is a zero-click attack?
A zero-click attack (also called a zero-click exploit or interaction-less attack) is a type of cyberattack that infects a device or steals data without requiring any action from the victim. There's no phishing email to fall for. No fake login page to get tricked by. No suspicious app to accidentally install.
The attacker exploits a hidden vulnerability, a flaw in the software that processes data you receive automatically, and that's all they need to get in.
Think of it this way: most attacks need you to open a door for them. A zero-click attack finds a window you didn't even know was unlocked, and slips in without making a sound.
How do zero-click attacks actually work?
To understand zero-click attacks, you need to understand how your devices handle data they receive passively, meaning, without you doing anything.
When someone sends you a message, your phone doesn't wait for you to open it before doing some work. It processes the message format, renders a preview, loads a thumbnail, parses metadata. All of this happens in the background, automatically. Zero-click attacks target the code that does this background processing.
Here's a simplified breakdown of how a zero-click attack unfolds:
- Attacker identifies a vulnerability, a bug in an app or operating system that processes incoming data (messages, images, calls, emails) without user input.
- Attacker sends a specially crafted payload, this could be a malformed image, a corrupted video file, a manipulated voicemail packet, or even a blank iMessage. The payload is built to trigger the vulnerability.
- The target device processes the payload automatically, your phone receives the data and the vulnerable code runs in the background.
- The exploit executes, the bug is triggered, and the attacker gains access. Malware is installed. Data is exfiltrated. And you never saw a thing.
The entire attack can happen in milliseconds. No notification. No warning. No trace, at least not one a regular user would ever notice.
What makes zero-click attacks so dangerous?
No user error required
Most cyberattacks depend on human mistakes. Phishing works because people get fooled. Malicious downloads work because someone clicked. Zero-click attacks remove that variable entirely. Even the most tech-savvy, security-conscious person on the planet can be a victim because their behavior plays no role in the attack's success.
They're extremely hard to detect
Zero-click exploits are built to operate silently. They leave minimal traces. The malware they install is often sophisticated enough to hide itself from standard security scans. Many victims only discover they've been targeted weeks, months, or even years later, if at all.
They often target trusted apps
The apps that process data in the background tend to be the ones we trust most: iMessage, WhatsApp, your email client, your phone's camera roll parser. Attackers specifically target these apps because they have broad system access and are always running.
Vulnerabilities are rare, and extremely valuable
Because zero-click exploits require a genuine software flaw, they're significantly harder to find and develop than ordinary malware. This makes them extraordinarily valuable. Security researchers have found that a single working zero-click exploit for a major platform can sell on the dark web for millions of dollars, which means they're typically used by well-funded threat actors: nation-state hackers, sophisticated criminal organizations, and surveillance-as-a-service companies.
Real-world zero-click attacks that actually happened
Zero-click attacks aren't theoretical. They've been used against real people, some of them ordinary civilians.
Pegasus spyware and iMessage (2021)
The most infamous zero-click attack in history involved Pegasus, a surveillance tool developed by Israeli firm NSO Group. In 2021, researchers at the Citizen Lab discovered a zero-click exploit they named FORCEDENTRY, a flaw in Apple's iMessage that allowed Pegasus to be installed on iPhones without the target receiving any visible message or notification.
The exploit worked by sending a malformed PDF disguised as a GIF file. iMessage processed it automatically, the vulnerability was triggered, and Pegasus was silently installed. The spyware could then read messages, activate the camera and microphone, track location, and exfiltrate virtually any data on the device. Among the confirmed targets: journalists, human rights activists, and political dissidents. Apple issued an emergency patch in September 2021.
WhatsApp VoIP vulnerability (2019)
In 2019, a critical vulnerability was discovered in WhatsApp's VoIP calling feature. Attackers could install spyware on a victim's phone simply by calling them, even if the victim never answered. The call would trigger a buffer overflow vulnerability, allowing malicious code to execute. The call often didn't even appear in the call log afterward. WhatsApp patched the flaw and urged all users to update immediately.
Operation Triangulation (2023)
In 2023, Kaspersky researchers uncovered Operation Triangulation, a sophisticated zero-click campaign that targeted iPhones via iMessage. The malware, delivered without user interaction, collected microphone audio, photos, and geolocation data, then ran silently in the background before deleting itself to avoid detection. Kaspersky confirmed that devices used by its own employees had been targeted.
Samsung and Android exploits
Zero-click attacks aren't limited to Apple devices. Android devices, particularly those running Samsung's messaging stack, have also been targeted. Security researchers have documented zero-click exploits affecting how Android processes image files and MMS messages, exploiting vulnerabilities in media-handling libraries that run automatically.
Who is most at risk?
Historically, zero-click attacks have been used primarily against high-value targets:
- Journalists and activists covering sensitive topics
- Politicians and government officials
- Corporate executives with access to proprietary data
- Legal professionals handling confidential cases
However, the threat is evolving. As surveillance tools become more commoditized and as criminal groups gain access to more sophisticated exploit kits, zero-click attacks are increasingly being deployed against ordinary individuals, particularly for financial fraud, stalkerware campaigns, and corporate espionage targeting small businesses.
The uncomfortable truth: you don't have to be a public figure to be targeted. You just have to have something worth stealing.
What data can a zero-click attack steal?
Once a zero-click exploit installs spyware on your device, the attacker can potentially access:
- Messages, including encrypted ones (read from the screen level, before encryption)
- Camera and microphone, real-time surveillance
- Location data, precise GPS tracking
- Passwords and credentials, including banking apps
- Files and documents, photos, notes, business files
- Call logs and contacts
- Browsing history
- Financial account access
The scope of what can be stolen depends on what permissions the exploited app has. Since core messaging and media apps tend to have broad system access, the damage can be total.
Can you tell if you've been hit by a zero-click attack?
In most cases, no, not without specialized forensic tools. Zero-click malware is purpose-built to be invisible. However, some warning signs can appear:
- Unusual battery drain, spyware running in the background consumes power
- Device running hot without obvious reason
- Unexplained data usage, malware exfiltrating data uses your connection
- Apps behaving strangely or crashing unexpectedly
- Sluggish performance on a device that used to run smoothly
- Unfamiliar apps appearing without you installing them
None of these signs alone confirm a zero-click compromise. But a combination of them, especially on a newer device, warrants investigation.
How to protect yourself from zero-click attacks
There's no single action that makes you completely immune. But there are meaningful steps you can take to dramatically reduce your risk.
Keep all software up to date. Most zero-click exploits target known vulnerabilities that have already been patched. The moment a security update is released, attackers start reverse-engineering the fix to target people who haven't updated yet. Keeping your OS, apps, and browser updated is your single most effective defense.
Reboot your device regularly. Many zero-click exploits install malware that lives in temporary memory (RAM) rather than persistent storage, meaning a simple restart wipes it. Cybersecurity experts recommend rebooting your smartphone at least once a week.
Enable Lockdown Mode on iPhone. Apple's Lockdown Mode, introduced in iOS 16, drastically reduces the attack surface by disabling features commonly exploited in zero-click attacks, including certain iMessage features, link previews, and incoming FaceTime calls from unknown contacts.
Limit app permissions. Apps that process data in the background should only have the permissions they genuinely need. Regularly audit which apps have access to your camera, microphone, contacts, and location.
Add browser-level security protection. Your browser remains one of the largest attack surfaces on any device. Most attacks, unlike the zero-click exploits above, still rely on a malicious link, a compromised site, or a drive-by download. Guardio runs in your browser, blocking malicious websites, suspicious scripts, and drive-by download attempts before they reach you. It won't stop a zero-click exploit itself, since those bypass browsing entirely, but it closes off the far more common way devices actually get compromised.
Monitor for identity and data breaches. Even if a zero-click attack targets your device, the goal is almost always to steal your data and use it. Guardio's identity monitoring alerts you the moment your personal information appears in a known breach or on the dark web, giving you a chance to act before serious damage is done.
For businesses: treat every device as a target. Small and medium businesses are increasingly in the crosshairs of sophisticated attackers. Every employee device is a potential entry point. A business security solution that monitors endpoints, enforces update policies, and provides real-time threat detection is no longer optional.
The bottom line: the "just don't click" advice is outdated
The cybersecurity advice of the last decade, be careful what you click, don't open suspicious attachments, remains valid. But it's no longer sufficient on its own.
Zero-click attacks represent a real shift in how threats work. They don't require your participation. They don't need you to make a mistake. They exploit the invisible machinery running beneath every app, every message, every call.
The good news: awareness is the first step. Keeping your software updated, rebooting regularly, and layering your defenses with real-time browser security and identity monitoring puts you in a dramatically stronger position than the vast majority of potential targets.
Attackers look for the easiest path in. Make sure that path isn't through you.
Guardio monitors your browsing in real time, blocking malicious sites, flagging dangerous scripts, and alerting you to threats before they can do harm. Combined with identity breach monitoring, you get a layered defense that catches the most common threats at the browser level and keeps watch over your personal data around the clock, including the kind of exposure a zero-click exploit can cause after the fact.
Get a free security scan with Guardio today and stay protected.
FAQs
What is a zero-click attack in simple terms?
A zero-click attack is a hack where your device gets infected or your data gets stolen without you clicking a link, opening a file, or interacting with anything. Attackers exploit hidden software bugs that trigger automatically when your device processes incoming data, like messages, images, or calls. No action on your part is needed for the attack to succeed.
Can iPhones get zero-click attacks?
Yes, iPhones are among the most targeted devices. The FORCEDENTRY exploit (2021) and Operation Triangulation (2023) both used zero-click techniques to compromise iPhones via iMessage, without the target doing anything at all. Apple regularly patches these vulnerabilities, which is why keeping iOS updated is critical.
Are zero-click attacks common?
Zero-click attacks are less common than traditional phishing or malware attacks because they require rare, hard-to-find software vulnerabilities. However, their use is growing as exploit tools become more accessible to criminal groups, and ordinary individuals, not just high-profile targets, are increasingly at risk.
Can antivirus software stop a zero-click attack?
Traditional antivirus tools often struggle to detect zero-click attacks because the malware is built to be invisible and can erase itself after installation. The most effective defenses are keeping all software updated (which closes exploited vulnerabilities), rebooting devices regularly, and using layered protections like browser security extensions and identity monitoring.
What should I do if I think I've been hit by a zero-click attack?
If you suspect a zero-click compromise, reboot your device immediately (this can wipe memory-resident malware), update all software, run any available security scans, and change your most sensitive passwords from a different device. Monitor your financial accounts for unusual activity and consider contacting a cybersecurity professional if symptoms persist.
Do zero-click attacks target ordinary people?
Historically, zero-click attacks were reserved for high-value targets like journalists, executives, and government officials. As exploit tools become more accessible, ordinary individuals with financial accounts or sensitive data worth stealing are increasingly at risk, especially from criminal groups using more commoditized surveillance tools.
What data can a zero-click attack steal?
A zero-click attack can give attackers access to your messages (including encrypted ones, read before encryption), camera and microphone, precise GPS location, passwords and banking credentials, files and photos, call logs, browsing history, and financial accounts. The scope depends on the permissions held by the exploited app.








