Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
defense-evasion-methodcommand-and-control-methodremote-access-implantthreat-infrastructure-tracking

Jamf Analysis Finds Predator Spyware Uses Diagnostic Error Codes and Anti-Analysis Telemetry

Updated 3mo agoFirst seen Jan 15, 20263 sources

New reverse-engineering by Jamf Threat Labs of an iOS Predator commercial spyware sample found previously undocumented anti-analysis and “deployment troubleshooting” capabilities that help operators understand why an infection attempt failed. The analysis describes an internal error-code taxonomy that reports specific failure conditions back to Predator’s command-and-control infrastructure, including error code 304 indicating the target device is running security or analysis tooling; Jamf assessed this turns failed deployments into actionable diagnostic events for operators rather than opaque failures.

Jamf also reported additional stealth and evasion features, including suppression of crash artifacts and mechanisms intended to hinder researcher analysis and user detection. Reported capabilities include checks for tools such as Frida and even utilities like netstat, suggesting Predator attempts to detect both professional analysis environments and privacy-conscious user behavior. Dark Reading highlighted that these telemetry and reporting behaviors imply Intellexa (Predator’s vendor) may have more visibility into, and potential control over, deployments than commercial spyware vendors typically claim, and noted other technical elements Jamf described such as crash reporting/monitoring and iOS SpringBoard hooking intended to conceal recording indicators.

Share:
Jamf Analysis Finds Predator Spyware Uses Diagnostic Error Codes and Anti-Analysis Telemetry
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 14, 20265mo ago

Jamf suggests Predator may use centralized or vendor-controlled C2

Based on standardized telemetry and troubleshooting mechanisms in the sample, Jamf said the spyware’s deployment framework may be centrally managed, potentially indicating vendor-controlled or vendor-managed infrastructure linked to Intellexa rather than purely customer-run operations. Jamf noted it could not definitively confirm who operates the C2.

Jamf publishes new reverse-engineering findings on Predator

Jamf Threat Labs reported that Predator has more advanced anti-analysis, anti-detection, and anti-forensics capabilities than previously documented. The research described a structured internal error-code system that reports why infection attempts fail and can abort deployment when analysis tools or hostile environments are detected.

Dec 1, 20242y ago

Google and Citizen Lab release Predator iOS sample

Google’s Threat Intelligence Group and Citizen Lab released an iOS Predator spyware sample that later became the basis for further reverse-engineering by Jamf researchers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

23 LINKEDOpen in app
Threat actors
2 linked
Malware
2 linked
Affected products
6 linked
WhatsappIosJamfIosIosIos
Organizations
13 linked
IntellexaJamfSecurityWeekCytroxNSO GroupMeta PlatformsCitizen LabThe Washington PostAmnesty InternationalInside StoryWAV Research CollectiveHaaretzGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.