A lightweight method to detect potential iOS malware
ID: abf6579a-53f6-5540-a45b-e789bdb6a320
STIX ID: report--abf6579a-53f6-5540-a45b-e789bdb6a320
Feed Name: Securelist by Kaspersky
This blog post presents an analysis of the iOS Shutdown.log artifact contained in sysdiag archives as a lightweight forensic method to detect advanced iOS spyware (Pegasus, Reign, Predator); it documents consistent indicators such as processes originating from /private/var/ and repeated reboot-delay ('sticky') processes, provides Python tools (iShutdown_detect, iShutdown_parse, iShutdown_stats) to extract and analyze Shutdown.log entries, and notes limitations (detection relies on the device rebooting and is not a silver bullet).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
