logo

New iShutdown Method Exposes Hidden Spyware Like Pegasus on Your iPhone

ID: 81d106ae-2ca6-5521-9fcc-036abb258d5a

STIX ID: report--81d106ae-2ca6-5521-9fcc-036abb258d5a

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-01-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers (Kaspersky) described "iShutdown," a lightweight forensic method that extracts and parses iOS Shutdown.log entries to reliably surface indicators of compromise left by sophisticated spyware families (Pegasus, Reign, Predator), including common filesystem paths and reboot-delay traces; Kaspersky published Python scripts to automate analysis. The report also notes SentinelOne findings that macOS infostealers (KeySteal, Atomic, JaskaGo) are evolving to bypass Apple's XProtect, highlighting active evasion and the limits of signature-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.