Clipping Wings: Our Analysis of a Pegasus Spyware Sample
ID: 766acb0e-d20d-58b4-9672-5aff6a22e514
STIX ID: report--766acb0e-d20d-58b4-9672-5aff6a22e514
Feed Name: iVerify Blog
Threat Score
This post previews a Black Hat Asia 2024 briefing on an analysis of an iOS spyware exploit sample (linked to Pegasus/BLASTPASS) recovered from an iTunes backup; it highlights repeated homed and MessagesBlastDoorService crashes, IMTransferAgent activity delivering files named sample.pkpass, and a pkpass archive containing a large WebP image and a binary plist (NSKeyedArchiver) consistent with known BLASTPASS exploitation techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
