New iShutdown Method Exposes Hidden Spyware Like Pegasus on Your iPhone
ID: 81d106ae-2ca6-5521-9fcc-036abb258d5a
STIX ID: report--81d106ae-2ca6-5521-9fcc-036abb258d5a
Feed Name: The Hacker News
Researchers (Kaspersky) described "iShutdown," a lightweight forensic method that extracts and parses iOS Shutdown.log entries to reliably surface indicators of compromise left by sophisticated spyware families (Pegasus, Reign, Predator), including common filesystem paths and reboot-delay traces; Kaspersky published Python scripts to automate analysis. The report also notes SentinelOne findings that macOS infostealers (KeySteal, Atomic, JaskaGo) are evolving to bypass Apple's XProtect, highlighting active evasion and the limits of signature-based defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
