logo

A lightweight method to detect potential iOS malware

ID: abf6579a-53f6-5540-a45b-e789bdb6a320

STIX ID: report--abf6579a-53f6-5540-a45b-e789bdb6a320

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2024-01-16

Date Updated: 2026-04-29

Author: Maher Yamout

...
...

This blog post presents an analysis of the iOS Shutdown.log artifact contained in sysdiag archives as a lightweight forensic method to detect advanced iOS spyware (Pegasus, Reign, Predator); it documents consistent indicators such as processes originating from /private/var/ and repeated reboot-delay ('sticky') processes, provides Python tools (iShutdown_detect, iShutdown_parse, iShutdown_stats) to extract and analyze Shutdown.log entries, and notes limitations (detection relies on the device rebooting and is not a silver bullet).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.