06.11.2016 Views

Technical Analysis of Pegasus Spyware

lookout-pegasus-technical-analysis

lookout-pegasus-technical-analysis

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

• Run the jsc script calling --early-boot<br />

• Run the exploit that maps the kernel base<br />

• Run the kernel exploit<br />

• Spawn the main running daemons <strong>of</strong> <strong>Pegasus</strong>: systemd, watchdogd<br />

As Citizen Lab mentioned in their report, <strong>Pegasus</strong> puts its own protection above all else. From the manual, as quoted by<br />

Citizen Lab:<br />

In general, we understand that it is more important that the source will not be exposed and the target will suspect<br />

nothing than keeping the agent alive and working.<br />

To this end, <strong>Pegasus</strong> has a large number <strong>of</strong> features that enable it to maintain its secrecy. It constantly monitors the phone<br />

for status and disables any other access to the phone by previous/other jailbreaking s<strong>of</strong>tware. <strong>Pegasus</strong> also contains a<br />

complex self-destruct mechanism which completely removes it from the phone.<br />

TECHNICAL ANALYSIS OF PEGASUS SPYWARE | 14

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!