In March 2021, researchers at the University of Toronto's Citizen Lab examined the phone of a Saudi activist infected with NSO Group's Pegasus spyware — a person who chose to remain anonymous — and kept a backup. Re-analysing that backup months later, they found twenty-seven copies of an identical file with a .gif extension that was really a 748-byte Adobe PSD, and four more supposed GIFs that were really PDFs. On Tuesday 7 September they shared the artefacts with Apple. On Monday 13 September, Apple confirmed the files contained a zero-day, zero-click exploit against iMessage, registered it as CVE-2021-30860, and shipped the fix the same day — iOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Six days from handover to a patch for every current Apple device in the world.
The name Citizen Lab gave the exploit was earned. BlastDoor, added in iOS 14, was the sandbox Apple built specifically so that suspicious iMessage attachments would be opened somewhere they could do no harm; FORCEDENTRY went through it. The fake GIFs triggered an integer overflow in the JBIG2 codec of Apple's image-rendering library — "processing a maliciously crafted PDF", the advisory said flatly, "may lead to arbitrary code execution". No link was tapped, no attachment opened, no mistake made; the target saw nothing at all. Citizen Lab judged the exploit had been in use since at least February 2021, matching crash signatures it had reported in August on the phones of Bahraini activists, and tied it to NSO through forensic artefacts it had previously catalogued in Pegasus infections.
Apple urged everyone to update while framing the danger carefully. "Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals," said Ivan Krstić, who runs the company's security engineering and architecture — not a threat to the overwhelming majority of users, in other words, and every threat to a specific few. NSO Group, asked for comment, said it would continue to provide agencies with technologies to fight "terror and crime". Neither statement dwelt on the person at the centre of the story: an activist whose phone had been silently compromised, who clicked nothing and saw nothing, and who was protected in the end not by the platform but by a laboratory re-reading an old backup.
The full measure of what had been captured arrived in December, when Google's Project Zero published its analysis of the sample. Inside the fake GIF, NSO's engineers had used the JBIG2 format's logical operators to assemble the components of a small computer — logic gates built from pixel-level operations — and then run their attack on it: a machine conjured into existence during a single pass of an image decompressor. Ian Beer and Samuel Groß judged it "one of the most technically sophisticated exploits we've ever seen", with capabilities rivalling those once thought reserved for a handful of states. July's Pegasus Project had been a list and a controversy. September produced a specimen: captured, dissected, patched — and no longer deniable.
REvil restores itself from backups
On 7 September, REvil's dark-web infrastructure — the Happy Blog leak site and the payment portal beside it — came back online, almost two months after the gang vanished mid-negotiation in the wake of July's Kaseya attack. Fresh victims appeared within days, and a figure calling himself 0_neday told a Russian-language crime forum that the crew had waited for their missing frontman, Unknown, and then restored everything from backups. The month kept undercutting the comeback. On 16 September, Bitdefender released a free universal decryptor for victims encrypted before 13 July, built with what it described only as a trusted law-enforcement partner; on 21 September, the Washington Post reported that the FBI had quietly held the Kaseya decryption key for about three weeks while planning an operation against the gang. The reader in 2026 knows what the gang did not: those backups were the way in. When REvil's sites went dark again in October, reporting indicated a multi-country operation had compromised them long before the restoration. "The server was compromised, and they were looking for me," 0_neday wrote, and disappeared.
BlackMatter and the grain co-op
NEW Cooperative, a farmer-owned grain co-operative based in Fort Dodge, Iowa, confirmed on Monday 20 September that ransomware had struck over the preceding weekend, and said it had proactively taken its systems offline, contained the threat and called law enforcement. BlackMatter — the operation researchers assessed to be DarkSide's successor — demanded $5.9 million, to double after five days, and claimed to have taken roughly 1,000GB of data including source code for the co-op's soil-mapping platform; those figures come from the attackers, not from published forensics. The leaked negotiation transcript is what the case is remembered for. The co-op's negotiator argued the gang had broken its own published rule sparing critical infrastructure, warned that the impact would likely be "much worse than the pipeline attack" — Colonial, four months earlier — and said about 40 per cent of national grain production ran through its software. BlackMatter replied that the co-op did not "fall under the rules". Grain kept moving on workarounds through harvest; six weeks later, BlackMatter announced it was shutting down, citing pressure from the authorities.
Pegasus in court: the state declines to answer
In New Delhi, the Pegasus Project's revelations reached the point where someone had to answer on the record — and the government chose not to. On 7 September, the Supreme Court gave the Centre more time to decide whether it would file a detailed affidavit in response to petitions from journalists and others who said their phones had been targeted. On 13 September, Solicitor General Tushar Mehta told the bench of Chief Justice N.V. Ramana and Justices Surya Kant and Hima Kohli that the government would file nothing further, citing national security, and offered instead an expert committee that the government itself would constitute. The bench reserved its interim order, telling the Solicitor General to mention the matter if the government reconsidered. It did not reconsider. The order, when it came on 27 October, appointed the court's own technical committee under the supervision of the retired judge R.V. Raveendran — and rejected the idea that invoking national security ends judicial scrutiny.
The same month showed the unglamorous end of the same problem. On 23 September, Cisco Talos published research on a campaign it called Operation Armor Piercer, running since at least December 2020 against Indian government and military personnel. The lures were documents about Kavach, the two-factor authentication app government employees use to reach official email; the payloads were Netwire and Warzone, commercial remote-access trojans sold openly online. Talos noted the tactics resembled those of Transparent Tribe, a group researchers assess to be Pakistan-based, while stopping short of attribution. That was India's September: military-grade spyware argued over in the Supreme Court, and commodity spyware arriving by email, dressed as the government's own security app.
Full Self-Driving becomes an audition
The month's most consequential AI release was a button. On 25 September 2021, Tesla's 2021.32.22 software update let owners in the United States request the Full Self-Driving beta from their dashboards, admission decided by a new Safety Score that graded hard braking, aggressive turning and following distance against the company's insurance models. A hand-picked test fleet became a mass audition for city-streets autonomy — the template for the wide rollout, and the regulatory reckoning, that filled the years that followed. The quieter work aged better. Britain published its first National AI Strategy on 22 September, a ten-year programme for becoming a "global AI superpower"; DeepMind and the Met Office showed in Nature, on 29 September, a generative model that could nowcast the next ninety minutes of rain convincingly enough that professional forecasters preferred it to the operational tools; and OpenAI taught GPT-3 to summarise entire books through recursive human feedback — a modest paper whose alignment method resurfaced, fourteen months later, in ChatGPT.
The vendor as rescue service
The month's defining vendor act appears in the REvil brief above only in passing. On 16 September 2021, Bitdefender released a free universal decryptor for REvil/Sodinokibi victims — anyone encrypted before the gang's 13 July disappearance could recover files at no cost — built, the company would say only, with a trusted law-enforcement partner, and published while REvil's restored servers sat freshly back online. A commercial anti-virus vendor was operating as a public rescue service inside an active case, as it had for GandCrab, the operation researchers regard as REvil's ancestor; by Bitdefender's later count the tool spared victims more than half a billion dollars in ransoms never paid. The month's other lesson about vendors and states came from Moscow, where officers raided Group-IB's headquarters on 29 September and arrested its founder, Ilya Sachkov, for state treason — later reporting tied the case to information about Kremlin-linked hackers passed to the Americans, which he denied. His company declared full confidence in his innocence; a Moscow court handed him fourteen years in 2023.
⏳ Time capsule — September 2021
- El Salvador became the first country to make Bitcoin legal tender on 7 September; the official Chivo wallet went offline for part of launch day.
- Emma Raducanu, an 18-year-old qualifier, won the US Open on 11 September without dropping a set — the first qualifier ever to win a Grand Slam singles title.
- Squid Game premiered on Netflix on 17 September and reached No. 1 in 94 countries, on its way to becoming the platform's most-watched series.
- Germany voted on 26 September: the Social Democrats narrowly beat Angela Merkel's bloc, setting up the coalition that ended her 16 years as chancellor.
What the specimen set in motion
FORCEDENTRY's afterlife ran through export controls and courtrooms. On 3 November 2021, the US Commerce Department added NSO Group to its Entity List; on 23 November, Apple sued — the same month it began sending threat notifications to people its systems believed had been targeted by state-sponsored attackers. Lockdown Mode followed in 2022, an iPhone setting that exists because of what one laboratory pulled out of an old backup. The litigation outlasted the exploit: a US jury ordered NSO to pay WhatsApp more than $167 million in damages in May 2025 over the 2019 hacking of its users, while Apple by 2024 was asking to drop its own case rather than expose its threat intelligence in discovery.
The month's other stories ended the way September hinted. REvil's restored backups proved to be law enforcement's way in; the sites went dark for good in October, and Russia's FSB arrested fourteen alleged members in January 2022, weeks before the invasion of Ukraine ended such cooperation — a rupture that runs through this archive's 2022 editions and the collapse of Conti. BlackMatter closed on 1 November, citing pressure from the authorities, and researchers watched its methods resurface in ALPHV — the operation that, in February 2024, stopped healthcare payments across America. India's technical committee reported in August 2022: malware on five of twenty-nine phones, nothing conclusively identified as Pegasus, and a note that the government had not cooperated. The Vault continues backwards from here, into the summer that made this September inevitable.