iShutdown detection Pegasus

simmerskool

Level 47
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Apr 16, 2017
3,679
11,953
4,570
USA
Cybersecurity researchers have identified a "lightweight method" called iShutdown for reliably identifying signs of spyware on Apple iOS devices, including notorious threats like NSO Group's Pegasus, QuaDream's Reign, and Intellexa's Predator.

Kaspersky, which analyzed a set of iPhones that were compromised with Pegasus, said the infections left traces in a file named "Shutdown.log," a text-based system log file available on all iOS devices and which records every reboot event alongside its environment characteristics...