Experts think they've found a great new way to see if your iPhone is infected with malware iOS spyware

iPhone 15 Pro review back handheld angled camera
(Image credit: Future | Alex Walker-Todd)

Top antivirus company Kaspersky has released Python scripts to automate the analysis of Shutdown.log, an Apple iOS system log file that covers device activity during a reboot, in an effort to curb spyware on the world’s most popular mobile platform.

Per an announcement on its Securelist blog aimed at security researchers, the collection of scripts known as iShutdown, available now on Github, avoids any byzantine technical solution, such as attempting to access encrypted backups, in favour of the relatively easily accessible Shutdown.log file.

Spyware, a specific form of malware that seeks to send sensitive and private user data, as well as device activity to unknown assailants, should be of great concern to employers who issue Apple iPhones to employees as corporate phones. As such, sysadmins would also be wise to take an interest in the iShutDown scripts in order to identify device intrusions. 

 iShutDown scripts in detail

There are three scripts in the package, designed to find and access data inside the Shutdown.log file, which is itself stored within ‘Sysdiagnose.tar’. 

That amount of scripts appear to be necessary to search for the .log file inside the archive, extract it, and then go onto extract reboot data from it. The good news is that, despite this being an iterative, multi-script process written in Python, you could use Python to automate that, too.

Despite being freely available on GitHub, the tools are geared towards security researchers, meaning that the output of the scripts could be impenetrable to those who aren’t sure of what they’re looking for. We doubt this will be a huge problem, as this is a very niche bit of news, unlikely to pique the interest of anyone who doesn’t already know what a Python interpreter is.

For those who do know what they’re doing, the main caveat will be that, because the iShutdown scripts retrieve reboot data, this will require quite a lot of rebooting, probably. Enough that Kaspersky is being deliberately evasive on the point, preferring in the announcement to “leave this as an open-ended question”, depending on the user’s “threat profile”.

Even with all this, security researchers’ lives are about to get easier. The obvious potential caveat with this kind of ‘it just works’ solution is that spyware developers already know, now, where these scripts are checking for aberrations in logs. 

iShutdown will likely lead to some disruption for black-hat developers, such as those responsible for the notorious Pegasus spyware package, but likely just mean that the cat-and-mouse game to detect spyware, to then see it avoid detection, on repeat forever, will just intensify.

Via BleepingComputer

More from TechRadar Pro

Luke Hughes
Staff Writer

 Luke Hughes holds the role of Staff Writer at TechRadar Pro, producing news, features and deals content across topics ranging from computing to cloud services, cybersecurity, data privacy and business software.

Read more
Spyware
Government-linked Italian spyware maker caught distributing malicious Android apps
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
Illustration of a laptop with a magnifying glass exposing a beetle on-screen
This devious macOS malware is evading capture by using Apple's own encryption
A person in a wheelchair working at a computer.
Why betting on Mac security could put your organization at risk
Clario
Clario review
Latest in Pro
Epson EcoTank ET-4850 next to a TechRadar badge that reads Big Savings
I found the best printer deal you won't see in the Amazon Spring Sale and it's got a massive $150 saving
Microsoft Copiot Studio deep reasoning and agent flows
Microsoft reveals OpenAI-powered Copilot AI agents to bosot your work research and data analysis
Group of people meeting
Inflexible work policies are pushing tech workers to quit
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
An image of network security icons for a network encircling a digital blue earth.
Why multi-CDNs are going to shake up 2025
Latest in News
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game