MVT – forensic tool to look for infections on smartphones
github.com
github.com
I’ve never seen my phone present any kind of scan results or notice of infection, nor are there any kind of malware scanning apps in the App Store (since they wouldn’t be able to leave the app jail to scan anyway)
Is this just like a glaring hole in mobile security for iOS?
2. Use the tool in question to identify IoC (indicators of compromise).
You're literally commenting on a tool that does this ;)
How do I run a tool like this on my idevice itself?
As mobile malware becomes more prolific, is the paradigm we want to set to find it really you make a back up and run a tool on it on your PC?
That UX won’t work for 90% of mobile users
If Pegasus knows these "on device malware detection" apps exist, they'll just add them to the list ion things their malware (which runs with significantly more privileges than an app you download from the app store) modifies/breaks/circumvents.
A (partial) list of Pegasus C&C servers is also known, and some iOS log files store hostnames you have connected to in the past.
It's fairly standard IoC analysis -- lots of malware leave traces on the client endpoint in question.
Maybe if the app bundled an exploit. But that's unlikely to be sustainable.
Didn’t Amazon just shutdown the servers belonging to such a group?
pihole probably would be too late to stop them anyway.