iShutdown Method Makes Finding Spyware on Apple iPhones Easier

Kaspersky has released Python scripts to automate the process for easy evaluations.

January 18, 2024

Spyware on chip
  • Cybersecurity researchers have identified iShutdown, a new method of detecting spyware on devices that run on the iOS platform.
  • Spyware such as Pegasus, Predator, and Reign leave traces in a file named Shutdown.log, which is available on all iOS devices.

Cybersecurity researchers have discovered iShutdown, a new method that reliably detects signs of spyware infesting compromised Apple devices running on the iOS platform. The method can detect high-profile spyware such as Predator, Reign, and Pegasus. Furthermore, Kaspersky has released Python scripts that automate the entire process for easier evaluation of devices.

According to Kaspersky, Spyware like Pegasus leave traces in a file called “Shutdown.log.” This text-based log file is found in all iOS devices and essentially works to record each instance of the reboot process with details about the environment’s characteristics. The file can be found in the sysdiagnose (sysdiag) archive.

See More: U.S. Federal Agencies Send Out Warnings About Androxgh0st Malware Botnet

One can identify spyware by looking for sticky processes that cause delays in reboots, essentially indicating that a device has been compromised. For the detection to work, a device user has to reboot the device frequently.

The iShutdown method is reportedly easier to implement than other popular methods, such as running a complete iOS backup or conducting forensic device imaging. Using Kaspersky’s Python Scripts makes the entire process much more efficient and easier.

The development has come on the heels of numerous data-stealing software, such as Atomic, KeySteal, and JaskaGo, capable of circumventing signature-based detection through XProtect, Apple’s in-house antivirus tech.

What best practices do you follow to protect your devices from spyware? Let us know your thoughts on LinkedInOpens a new window , XOpens a new window , or FacebookOpens a new window . We’d love to hear from you!

Image source: Shutterstock

LATEST NEWS STORIES

Anuj Mudaliar
Anuj Mudaliar is a content development professional with a keen interest in emerging technologies, particularly advances in AI. As a tech editor for Spiceworks, Anuj covers many topics, including cloud, cybersecurity, emerging tech innovation, AI, and hardware. When not at work, he spends his time outdoors - trekking, camping, and stargazing. He is also interested in cooking and experiencing cuisine from around the world.
Take me to Community
Do you still have questions? Head over to the Spiceworks Community to find answers.