Predator’s kill switch: undocumented anti-analysis techniques in iOS spyware
ID: eb894fa0-53b6-5818-8647-70e424ffb7a4
STIX ID: report--eb894fa0-53b6-5818-8647-70e424ffb7a4
Feed Name: Jamf Blog
Jamf Threat Labs' analysis of Predator iOS spyware uncovers undocumented anti-analysis and anti-forensics features — a detailed error-code taxonomy that reports precise deployment failures to C2, process/jailbreak/locale/console detection, kqueue-based crash-reporter monitoring that suppresses memory-forensics, SpringBoard hooking to hide recording indicators, kernel exploitation class names, and self-cleanup behaviors — demonstrating a highly sophisticated commercial spyware capability used by Intellexa operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
