Assuming such applications existed, how would you install them on the "suspect" iPhone?
Assuming you were able to install such applications, you'd still not have any access to or control over the baseband (which I strongly suspect has plenty of issues of its own).
Assuming the malicious software avoided using Wi-Fi and used only the the cellular data connection for command and control, exfiltration, etc., it'd be damn near impossible to monitor the ("plain-text") data being sent and received (assuming such software would make use of private certificates -- or asymmetric encryption, in general -- to avoid being MITM'd itself, which seems like a reasonable assumption).
--
EDIT: This got me thinking, "what would be the most secure way to keep and use a mobile phone?" (assuming one could not simply avoid doing so).
My first thought is to use a mobile phone with the baseband radio(s) (verifiably) disabled/removed (if that is even possible?) or -- even better -- a Wi-Fi only device (similar in function as the old iPod Touch, for example) on which one used only SIP applications for calling (ideally via an "internal PBX" shared by all of one's correspondents) along with one's preferred E2E-encrypted messaging applications (e.g., Matrix, Signal, WhatsApp, etc.), all of which are used (importantly!) exclusively over an always-on VPN connection.
In instances where Wi-Fi was unavailable and/or one had no other options, a "mobile hotspot" or another ("real") mobile phone acting as one could potentially be used.
I'm interested in hearing thoughts on this idea (including any reasons why this is a bad idea that didn't occur to me during my two minute thought experiment), any other similar ideas that others have had, or any actual practices that are actually being used.