{"id":7986,"date":"2025-10-28T10:03:27","date_gmt":"2025-10-28T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/28\/ios-26-deletes-pegasus-and-predator-spyware-infection-evidence-by-overwriting-the-shutdown-log-file-on-reboot\/"},"modified":"2025-10-28T10:03:27","modified_gmt":"2025-10-28T10:03:27","slug":"ios-26-deletes-pegasus-and-predator-spyware-infection-evidence-by-overwriting-the-shutdown-log-file-on-reboot","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/28\/ios-26-deletes-pegasus-and-predator-spyware-infection-evidence-by-overwriting-the-shutdown-log-file-on-reboot\/","title":{"rendered":"iOS 26 Deletes Pegasus and Predator Spyware Infection Evidence by Overwriting The \u2018shutdown.log\u2019 file on Reboot"},"content":{"rendered":"<p>    iOS 26 Deletes Pegasus and Predator Spyware Infection Evidence by Overwriting The \u2018shutdown.log\u2019 file on Reboot<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The emergence of Pegasus and Predator spyware over the past several years has transformed the landscape of mobile device security.<\/p>\n<p>These advanced malware strains\u2014deployed by sophisticated threat actors for <a href=\"https:\/\/cybersecuritynews.com\/smarter-security-how-modern-surveillance-improves-business-decisions\/\" target=\"_blank\" rel=\"noreferrer noopener\">surveillance<\/a> and espionage\u2014have repeatedly demonstrated their ability to exploit zero-click vulnerabilities, leaving high-profile individuals and at-risk communities exposed.<\/p>\n<p>Critical forensic analysis has long relied on remnants within iOS system logs, particularly the shutdown.log file, to discern traces of such infections even after the malware attempts to erase itself.<\/p>\n<p>With the release of iOS 26, forensic methodologies face an unprecedented setback. iVerify analysts <a href=\"https:\/\/iverify.io\/blog\/key-iocs-for-pegasus-and-predator-spyware-cleaned-with-ios-26-update\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that Apple\u2019s latest OS version now overwrites the shutdown.log file upon each device reboot, instead of appending new log entries.<\/p>\n<p>This seemingly innocuous change\u2014whether intentional or inadvertent\u2014has significant consequences for digital evidence preservation.<\/p>\n<p>Any device updated to iOS 26 that is subsequently restarted will see all prior shutdown.log content erased, destroying potential indicators of compromise linked to Pegasus, Predator, or similar threats.<\/p>\n<p>Previously, sophisticated spyware like <a href=\"https:\/\/cybersecuritynews.com\/nso-developed-another-whatsapp-spyware-even-after-being-sued\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pegasus<\/a> would attempt to purge or tamper with shutdown.log as part of its anti-forensics tactics, a process that still left behind subtle indicators for vigilant analysts.<\/p>\n<p>iVerify researchers have detailed that this \u201cdouble erasure\u201d\u2014malware deletion followed by OS-level overwriting\u2014now fully sanitizes this critical artifact, hampering investigations and masking successful compromises far more effectively than previous tactics.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-and-evidence-erasure-in-ios-26\"><strong>Infection Mechanism and Evidence Erasure in iOS 26<\/strong><\/h2>\n<p>Inspection of historic shutdown.log entries revealed unique markers left by Pegasus in past infections, such as references to processes like <code>com.apple.xpc.roleaccountd.stagingcom.apple.WebKit.Networking<\/code>.<\/p>\n<p>Since iOS 26, such forensic signals are not merely buried\u2014they are irretrievably deleted on the next boot.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj0MoBUwwWFukZgEGfp_fl1Q8uE-usNEjCXnCrm1EtQzalhnZDakinDmw2Gmq7lrIb6ypvAEedu2XtvdGkzsbUXtfWf0-xh_2M06eDXyF4gh-2OKrYvijmgFXO_RWqnvBS0bmYggvyYG1HbPc_t6AocRajFXRQw517TGTOBAEYql3d50ZG6_u076959o2E\/s16000\/Boot%2520and%2520reboot%2520events%25209Source%2520-%2520iVerify%29.webp?ssl=1\" alt=\"\"><\/figure>\n<p>Boot and reboot events (Source \u2013 iVerify)<\/p>\n<p>The log\u2019s prior structure, which appended each shutdown entry, offered investigators a chronological view vital for tracing infection timelines.<\/p>\n<p>The technical transition to full overwriting shows a before-and-after comparison of the shutdown.log behavior after reboot.<\/p>\n<p>This system-level change, reported by iVerify as the foremost group uncovering this development, alters the balance between attackers and defenders, raising urgent questions about digital evidence, user protection, and <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> accountability.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ios-26-deletes-pegasus-and-predator-spyware-infection-evidence\/\">iOS 26 Deletes Pegasus and Predator Spyware Infection Evidence by Overwriting The \u2018shutdown.log\u2019 file on Reboot<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ios-26-deletes-pegasus-and-predator-spyware-infection-evidence\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>iOS 26 Deletes Pegasus and Predator Spyware Infection Evidence by Overwriting The \u2018shutdown.log\u2019 file on Reboot The emergence of Pegasus and Predator spyware over the past several years has transformed the landscape of mobile device security. These advanced malware strains\u2014deployed by sophisticated threat actors for surveillance and espionage\u2014have repeatedly demonstrated their ability to exploit zero-click [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7986","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7986"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7986"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7986\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7986"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7986"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7986"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}