Predator Spyware Sample Indicates 'Vendor-Controlled' C2
ID: e39a019b-c6db-5f5f-a711-e1a9df32fdba
STIX ID: report--e39a019b-c6db-5f5f-a711-e1a9df32fdba
Feed Name: Dark Reading
Jamf researchers analyzed a Predator iOS spyware sample (previously published by Google and Citizen Lab) and discovered sophisticated anti-analysis features—an error-code taxonomy, crash-report monitoring, and SpringBoard hooks to hide indicators—that report deployment failures to a C2, suggesting centralized or vendor-managed control by Intellexa; the findings both raise concerns about vendor visibility into deployments and provide actionable defensive insights (for example, enabling iOS Developer Mode triggers an abort error).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
