Predator Malware: Trust Broken At The Core - Matthias Frielingsdorf

Matthias Frielingsdorf (VP of Research · Verify)

Nullcon Goa 2025 · Main Stage

Overview

This talk by Matthias Frielingsdorf, VP of Research at A-Verify, delves into the sophisticated world of commercial spyware, specifically focusing on the evolution and technical intricacies of the Predator malware. Frielingsdorf highlights the critical challenge posed by such advanced persistent threats (APTs) on the iOS ecosystem, where traditional security models struggle to provide adequate visibility and detection capabilities. The presentation provides a detailed technical analysis of a recovered Predator 2023 loader sample, comparing its methodologies and evasive techniques against earlier versions.

Watch on YouTube

Visual summary for Predator Malware: Trust Broken At The Core - Matthias Frielingsdorf by Matthias Frielingsdorf
Visual summary for Predator Malware: Trust Broken At The Core - Matthias Frielingsdorf by Matthias Frielingsdorf

Key moments

  1. 0:00 Speaker introduction and talk agenda
  2. 0:50 Defining commercial spyware and its characteristics
  3. 2:30 First public surfacing of Predator malware (2021)
  4. 3:30 Predator's use of /private/tmp for stealth and evasion
  5. 4:40 Persistence mechanism: iOS shortcuts via zactionsd
  6. 6:00 Predator's extensive logging and shared Python loader
  7. 6:50 Geofencing and process name disguise tactics

Predator Malware: Trust Broken At The Core

Speakers: Matthias Frielingsdorf, VP of Research, A-Verify

Conference: Nullcon

YouTube: https://www.youtube.com/watch?v=1kZsUeV-_UA

Overview

This talk by Matthias Frielingsdorf, VP of Research at A-Verify, delves into the sophisticated world of commercial spyware, specifically focusing on the evolution and technical intricacies of the Predator malware. Frielingsdorf highlights the critical challenge posed by such advanced persistent threats (APTs) on the iOS ecosystem, where traditional security models struggle to provide adequate visibility and detection capabilities. The presentation provides a detailed technical analysis of a recovered Predator 2023 loader sample, comparing its methodologies and evasive techniques against earlier versions.

The talk is crucial for anyone involved in mobile security, incident response, or digital forensics, as it uncovers the cutting-edge tactics employed by private sector offensive actors (PSOAs) to compromise high-value targets. Frielingsdorf demonstrates how Predator leverages zero-click and zero-day exploits to achieve deep system access, circumventing Apple's robust security measures. By dissecting the malware's new multi-process architecture, revamped evasion strategies, and the persistent gaps in iOS detection, the presentation underscores the urgent need for enhanced forensic capabilities and a re-evaluation of the security-privacy balance on mobile platforms.

Ultimately, Frielingsdorf's analysis serves as a stark reminder that while Apple continuously adds mitigations, advanced adversaries adapt rapidly. The talk advocates for a proactive approach to threat hunting and forensic data collection, pushing for an endpoint security framework on iOS akin to what is available on macOS, which could significantly bolster the defensive posture against these highly impactful yet low-probability attacks.

Background

▶ Watch: Speaker introduction and talk agenda (0:00)

Commercial spyware represents a unique and highly dangerous category of offensive capabilities, typically developed by private companies and sold to nation-states. These tools are designed for targeted surveillance, often against civil society, journalists, business persons, and even government officials, frequently deviating from their stated purpose of combating terrorism or serious crime. Key characteristics include the use of zero-click or one-click exploit chains, meaning an attacker can compromise a device with just a phone number or email address, often without any user interaction. They frequently leverage zero-day exploits to infect devices running the latest operating systems, making detection exceptionally difficult. Once infected, these implants grant attackers full control over the device, compromising all data, passwords, camera, microphone, and banking information.

Predator malware first publicly surfaced in 2021, with reports from Citizen Lab, Google TAG, and Cisco Talos attributing its use to Intellexa and Sidewinders. The 2021 variant primarily used a WebKit vulnerability as an infection vector, targeting the Safari browser. Forensic analysis revealed processes spawning from /private/tmp, a directory typically not used by legitimate iOS processes, and the use of a kernel_task_port to read and write memory. Persistence was achieved via z_actions_d, the background process for executing shortcuts. Notably, the 2021 version featured a Python loader shared between iOS and Android samples, extensive logging (which ironically aided in its eventual discovery), and a locale check to avoid infecting devices in Israel. Despite these indicators, detection remained challenging due to the malware's sophisticated execution and attempts to disguise itself as legitimate system processes like WebKitNetworking.

The emergence of a new Predator variant in 2023 was hinted at by the iOS 17.1 vulnerability disclosure, which patched three critical flaws: a certificate validation issue in CourtTrust, a local privilege escalation (LPE) from WebKit to the kernel, and a remote code execution (RCE) vulnerability used to gain initial access via Safari. Google TAG confirmed these vulnerabilities were exploited by a commercial surveillance vendor in Egypt, and Citizen Lab subsequently linked them to Predator. While Google TAG promised a technical deep dive, the CourtTrust bug was independently reverse-engineered and implemented in tools like TrollStore, allowing sideloaded applications to run with arbitrary entitlements. An interesting twist came with a Google report detailing a Russian state actor using a remarkably similar WebKit exploit—not to deploy an implant, but to extract cookie databases. This raised questions about the shared origin of these exploits, suggesting a common developer or shared exploit chain. The 2023 Predator variant represents a significant evolution, building on these advanced exploitation capabilities to refine its stealth and operational security.

Key Findings

▶ Watch: First public surfacing of Predator malware (2021) (2:30)

The analysis of the Predator 2023 loader sample revealed a sophisticated evolution from its 2021 predecessor, focusing on enhanced evasion, modularity, and operational security. A primary finding is the complete transition from a Python-based loader to a natively compiled codebase written in C, C++, and Objective-C. This shift significantly improves performance, reduces the malware's footprint, and makes cross-platform sharing less evident, moving away from the "shared iOS/Android code" seen previously.

The malware now employs a multi-process architecture, consisting of at least three distinct components: a Watcher, a Helper, and an Agent. The Watcher likely acts as the initial orchestrator, responsible for initial checks, downloading subsequent components, and ensuring their execution. The Helper leverages a kernel read/write primitive obtained from earlier exploit stages, indicating deep system access, and establishes a unique socket server for inter-process communication and remote procedure calls (RPCs). The Agent is the actual implant responsible for data exfiltration and device control.

Crucially, Predator 2023 has significantly improved its evasion and cleanup mechanisms. Unlike the 2021 version that merely stopped shutdown processes (leaving traces), the new variant actively detects shutdown events and initiates a comprehensive cleanup to remove all traces from the device. It also employs a sophisticated crash log monitoring function, registering for kernel events and specifically targeting crash logs containing "system memory" to kill the memory_maintenance_D process, thereby preventing the logging of its own process list. Furthermore, the malware diligently clears its command-line arguments immediately after execution, preventing their forensic recovery, a stark contrast to the easily visible arguments in the 2021 sample. Despite these advancements, the analysis uncovered a substantial amount of dead code (approximately 50% of the sample), including references to apply_install_D_bypass and apply_sandbox_escape_for_others, suggesting either unused capabilities or a deliberately complex structure designed to mislead reverse engineers. The continued presence of logging, although more discreet, still offers potential forensic indicators.

Technical Deep Dive

▶ Watch: Predator's use of /private/tmp for stealth and evasion (3:30)

The technical analysis of the Predator 2023 loader sample employed a mixed approach, primarily focusing on static analysis due to the absence of a dedicated security research device for dynamic execution. Tools like strings, otool, codesign, and this_arm were instrumental, complemented by IDA Pro and Ghidra for deeper code inspection. The speaker also highlighted an innovative use of Large Language Models (LLMs) to assist in translating disassembled code into more readable, pseudo-source code, streamlining the reverse engineering process by generating better naming conventions and removing boilerplate.

Initial inspection using strings quickly revealed references to "developer mode status," iOS build numbers, and iPhone modules, hinting at specific targeting or compatibility checks. Running otool -L on the binary showed links to CallKit and AudioToolbox frameworks, strongly suggesting capabilities for audio recording and call interception. Further otool -l analysis confirmed the sample's compatibility, indicating it supports iOS 16 and upwards and was built with the iOS 16 SDK. This means devices running iOS 15 or older would not be targeted by this specific variant.

Code signature analysis proved particularly insightful. While Apple's codesign tool only showed a single signer with the identifier "Watcher," the more specialized this_arm tool revealed a more complex picture. It showed two distinct code signatures: one copied from a valid Apple App Store directory (leveraging the CourtTrust vulnerability detailed in Lluís's earlier talk) and the "Watcher" signature. The timestamp on the "Watcher" signature indicated it was signed around September 7th, providing a valuable chronological marker. The binary was also identified as arm64e, restricting its execution to newer Apple Silicon devices and precluding older, checkra1n-compatible devices.

The malware's entitlements were extensive, granting it significant privileges. Notable entitlements included security-no-container for sandbox escape, com.apple.security.cs.disable-library-validation for potential library injection, and a particularly alarming allow-obliterate-device, whose full implications remain to be explored but suggests a capability to wipe the device.

Diving into the code, the primary entry point, main, revealed a sophisticated argument parsing and process initiation mechanism. The binary expects 14 command-line arguments, with the 14th argument (arg[14]) determining the execution mode (either "Watcher" or "Helper"). Crucially, the malware immediately zeros out these command-line arguments after processing, a direct countermeasure to forensic techniques that would have easily exposed arguments in the 2021 Predator variant. The main function then proceeds to initialize and spawn two dedicated processes: the Watcher and the Helper, both designed to run continuously in a loop.

The Watcher process is likely the initial stage, responsible for coordinating the infection. Its init and start functions perform several critical tasks:

  1. Binary Copying: It calls copy_watcher, which copies the actual Watcher binary from memory to disk, thereby establishing its presence.
  2. Validation Checks: It executes a series of checks, mirroring those previously detailed by Citizen Lab. These include:
  • Country Locale: Checking for Israel and the US. If detected, the malware reports and aborts, indicating a geo-fencing mechanism.
  • Processes from /private/tmp: It checks for other processes running from /private/tmp. Interestingly, it allows one process to run from this directory (itself), suggesting it's looking for other, potentially competing, malware or prior infections.
  • Console Attached: Checks if a console is attached, likely to detect debugging or analysis environments.
  • Developer Mode Status: If developer mode is enabled, it aborts, possibly to avoid detection or because developer mode might alter certain system behaviors it relies on.
  • is_unsafe Running: A check for jailbreak applications or specific VPNs.
  • Device Type: Checks if the device is a phone (e.g., Qualcomm-specific checks).
  • Proxy Running: Detects the presence of network proxies, another common analysis technique.

If any of these checks fail, the Watcher reports back to its server and aborts execution.

  1. Component Download and Execution: Upon successful validation, it downloads an executable, specifically checking for an "agent." It uses two hardcoded paths: a Watcher file path and a bit_path for the actual agent binary, and a helper_path for the helper binary. Depending on a binary_type flag, it opens and spawns either the agent or the helper.
  2. Shutdown Event Monitoring: The Watcher registers itself to listen for device shutdown events. If a shutdown is detected, it triggers a comprehensive cleanup routine, ensuring all components stop and disappear, a significant improvement over the 2021 version's less effective shutdown prevention.
  3. Agent Monitoring: A check_agent_timer function continuously monitors the agent process, ensuring it remains running. If the agent is not active, the Watcher attempts to download and execute it again.
  4. Crash Log Evasion: A monitoring_crash_reporter function registers for kernel events. Upon the creation of a new crash log, it specifically checks if the log name contains "system memory." If so, it kills the memory_maintenance_D process. This is a highly sophisticated evasion technique, as crash logs containing "system memory reset events" often include a full list of running processes, which would expose the malware.

The Helper process, initialized with a kernel memory read/write primitive from earlier exploit stages, also plays a crucial role.

  1. Shutdown Monitoring: Like the Watcher, it listens for shutdown events and performs cleanup.
  2. Agent Check: It also has a check_agent_timer to ensure the agent's continued operation.
  3. Kill Switch: It checks for the existence of a dedicated file at a specific path. If this file is found, the Helper immediately stops, acting as a potential kill switch or deactivation mechanism.
  4. Unique Socket Server: The Helper's core functionality involves creating a first_unit_socket, starting a unique socket server, and processing incoming requests. This server-client model suggests it handles remote procedure calls (RPCs) from the agent or other components, acting as a privileged backend.

Analysis of the Helper's code, while not fully executable without dynamic analysis, revealed several potential operations:

  • Keylogger code.
  • Camera enabler, which hooks mediaserverd.
  • VoIP recording, also hooking mediaserverd.
  • DM hooker and IM hooker for intercepting direct and instant messages.
  • A particularly interesting function named NS_task_read without developer mode, which appears to enable executing code in arbitrary processes without requiring developer mode, showcasing its deep system access.

Despite the extensive analysis, several command-line arguments (6 out of 14) remain fully understood, with others indicating the transport of URLs, decryption material, and binary names. The presence of significant unreachable code (approximately 50% of the binary) is noteworthy. This includes references to apply_install_D_bypass and apply_sandbox_escape_for_others, and other kernel-level functionalities. While currently inactive, these dead code segments might represent dormant capabilities, debugging artifacts, or decoys. Interestingly, a full URL of a GitHub commit was also found embedded within the code, potentially referencing an exploit development source.

Comparing Predator 2021 and 2023 highlights a clear trajectory towards increased sophistication:

  • Process Architecture: From two known processes in 2021 to at least three (Watcher, Helper, Agent) in 2023, with configurable names. Still using /private/tmp.
  • Persistence: 2021 used z_actions_d (shortcuts). 2023's persistence mechanism is less clear, though apply_install_D_bypass hints at potential application installation.
  • Command-Line Arguments: 2021 had few, easily visible arguments. 2023 uses 14 arguments, which are immediately cleared.
  • Shutdown Handling: 2021 stopped shutdown but left traces. 2023 actively detects shutdown and performs a thorough cleanup.
  • Programming Language: 2021 used Python (shared code). 2023 is entirely C/C++/Objective-C (native, local).
  • Logging: Both versions log, but 2023's logging is more discreet, though still present.
  • Locale Checks: 2021 checked for Israel. 2023 checks for both Israel and the US.
  • Dead Code: Both versions contain dead code, with 2023 estimated at 50%.
  • Cleanup: 2021 removed crash logs. 2023 kills memory_maintenance_D and likely uses the Agent for further crash log removal.

Demo / Proof of Concept

▶ Watch: Predator's extensive logging and shared Python loader (6:00)

While no live demonstration or proof of concept was presented during the talk due to the speaker's lack of an applicable security research device for dynamic analysis, the technical deep dive extensively outlined the expected behaviors and functionalities that such a demo would showcase. If dynamic analysis were possible on a compromised iOS 16+ arm64e device, a demonstration would involve observing the spawning of the Watcher and Helper processes from /private/tmp, noting their configurable names and the immediate clearing of command-line arguments. Network analysis would reveal the Watcher's attempts to report validation failures and download the Agent executable. Furthermore, a PoC could illustrate the Helper's establishment of a unique socket server and the execution of its core capabilities, such as the keylogger or camera enabler, by monitoring system calls and process interactions (e.g., mediaserverd hooks). The effectiveness of the shutdown detection and cleanup mechanisms could also be demonstrated by observing the rapid disappearance of malware components upon a device restart.

Defensive Implications

▶ Watch: Geofencing and process name disguise tactics (6:50)

The sophisticated nature of Predator 2023 highlights a critical gap in current iOS security paradigms, particularly concerning the detection of advanced commercial spyware. Traditional detection methods, primarily relying on Mobile Device Management (MDM) solutions or standard iOS applications, are largely ineffective against a threat like Predator. These tools operate within the confines of the iOS sandbox and lack the deep system visibility required to identify processes spawning from /private/tmp, monitor kernel events, or detect the subtle inter-process communication that characterizes this malware.

Frielingsdorf strongly argues that detecting Predator in the wild necessitates a shift towards forensic-based detection. This involves:

  1. Scaling Forensic Data Collection: Defenders must frequently collect comprehensive forensic sources such as sysdiagnose archives and device backups. These sources, unlike live app data, often contain granular system information, including process lists, file system artifacts, and logs, which can reveal the presence of stealthy malware.
  2. Advanced Threat Hunting: Organizations need to invest in scalable technology and expertise to analyze these vast forensic datasets effectively. This includes developing automated tools to parse sysdiagnose logs, inspect backup contents, and correlate indicators of compromise (IOCs) like specific file paths (e.g., within /private/tmp), process behaviors (e.g., memory_maintenance_D termination), and log messages (even the subtle ones Predator leaves behind).
  3. Understanding Evasion: Defenders must understand Predator's new evasion tactics, such as clearing command-line arguments, actively cleaning up on shutdown, and killing memory_maintenance_D to obscure process lists. This knowledge can guide forensic investigations to look for more subtle or indirect indicators.
  4. Locale and Developer Mode Checks: The malware's checks for specific locales (Israel, US) and developer mode status can be leveraged. While not direct detection, understanding these conditions can inform analysis strategies or reveal attacker intent.

The fundamental challenge, as Frielingsdorf explains, lies in Apple's delicate balance between security and privacy. While iOS offers strong security against mass-market malware and excellent user privacy, it severely limits the visibility available to Endpoint Detection and Response (EDR) tools. This lack of visibility prevents security researchers and enterprises from effectively detecting advanced threats like Predator in real-time. The speaker advocates for Apple to introduce an Endpoint Security Framework (ESF) for iOS, similar to the one available on macOS. Such a framework would grant approved security vendors the necessary visibility and hooks into the operating system to detect and respond to sophisticated threats without compromising user privacy for the vast majority of users. Without this, the defensive community will continue to play catch-up, detecting infections months after the harm has been done, even with Apple's valuable victim notification efforts.

Key Takeaways

  • Predator's Evolution: The malware has significantly evolved from its 2021 Python-based variant to a more sophisticated C/C++/Objective-C native implementation in 2023, enhancing stealth and operational security.
  • Multi-Process Architecture: The 2023 version employs a complex Watcher-Helper-Agent architecture, with the Watcher orchestrating initial checks and component deployment, and the Helper leveraging kernel primitives.
  • Advanced Evasion: Predator 2023 implements robust evasion techniques, including clearing command-line arguments, detecting and cleaning up on device shutdown, and actively tampering with crash logs (memory_maintenance_D) to hide its presence.
  • Persistent Detection Challenges on iOS: Apple's strong security-privacy balance severely limits the visibility for traditional MDM and app-based EDR tools, making advanced commercial spyware like Predator extremely difficult to detect in real-time.
  • Forensic-Centric Defense: Effective detection requires a shift towards scaling forensic data collection (sysdiagnose, backups) and implementing advanced threat hunting processes to identify subtle indicators of compromise.
  • Call for iOS Endpoint Security Framework: The defensive community urgently needs an Endpoint Security Framework on iOS, similar to macOS, to gain the necessary visibility to counter advanced commercial spyware and protect high-risk individuals proactively.

About the Speaker(s)

Matthias Frielingsdorf is the Co-founder and current VP of Research at A-Verify, a company dedicated to developing software for detecting commercial spyware at scale. His expertise lies in iOS malware and exploitation, and he is passionate about uncovering the technical details of sophisticated threats like Predator. Beyond his professional endeavors, Matthias enjoys playing basketball and board games. His work frequently involves analyzing novel vulnerabilities and exploits used by private sector offensive actors, contributing significantly to the understanding and defense against these advanced threats.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Frielingsdorf delivers a technically substantive teardown of the Predator 2023 loader — native rewrite, multi-process architecture, crash-log suppression via memorymaintenanceD, argument zeroing — with enough concrete artifact detail to actually move defensive and forensic work forward. Not a 5-star because it's static-analysis only with no live device, ~50% of the binary stays unresolved, and the ESF policy ask at the end is a known talking point, not novel advocacy.

Heather Calloway (CISO) — SOLID

Technically rigorous reverse engineering of a significant commercial spyware sample, with real forensic value for the mobile security research community. The defensive and governance implications are present but underdeveloped — the talk diagnoses the detection gap clearly, then stops short of telling the institutional audience what to do about it.

→ Top-rated talks at Nullcon Goa 2025

All talks from Nullcon Goa 2025