Inside Predator’s kernel engine
ID: b03cca3e-7f88-5072-a6fa-96a1a0cd0dc2
STIX ID: report--b03cca3e-7f88-5072-a6fa-96a1a0cd0dc2
Feed Name: Jamf Blog
Jamf Threat Labs presents a technical analysis of Predator commercial iOS spyware's kernel engine, revealing how it achieves arbitrary kernel read/write via FDGuardNeonRW (using ARM NEON registers), bypasses Pointer Authentication Codes by hunting a JavaScriptCore gadget and precomputing a 256-entry PAC signing cache, performs remote function execution (callFunc) and shares capabilities between processes (RWTransfer); the chain supports 21 iPhone models (iPhone XS through iPhone 14 Pro Max) on iOS versions prior to 17 and demonstrates a sophisticated, high-impact post-exploitation framework enabling persistent surveillance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
