5 ms·
I read that if Pegasus is on your phone, even a factory reset will not get rid of it. Could someone explain why?
by egonschiele 3y ago
I read that if Pegasus is on your phone, even a factory reset will not get rid of it. Could someone explain why?
- negus 3y agoHaven't read about Pegasus, but what you describe is the behavior of bootkits. Factory reset does not imply that you erase 100% of your permanent storage: some part of it should contain the system programs to restore the system. If these system programs or the clean OS image are modified, then factory reset won't help
- scintill76 3y agoI don’t know about the original claim either way, but I would be even more impressed and scared if it survived an iTunes restore (basically a PC reflashes the iPhone’s OS image with an image downloaded from Apple.)
- negus 3y agoIf the malware controls the bootloader nothing will help: it can imitate any kind of restore, modifying the OS image on the fly
- heywhatupboys 3y agoeverything is signed. should not be even remotely possible
- scintill76 3y agoApple has firmware restore features in ROM. I would also assume (hope?) that there’s a procedure to enter the ROM-based restore that is impossible to intercept in software (maybe holding the power button for 10 seconds initiates a hardware reset into the ROM.)
- saagarjha 3y agoThere is.
- runjake 3y agoI am not an expert, but my belief is that Pegasus does not maintain persistence. While the Wikipedia article claims Pegasus "jailbreaks" the iPhone to maintain persistence. Every technical article I've read says that a reboot clears Pegasus (albeit, it is easy to re-infect with a no-click exploit without the user's knowledge). Hopefully, someone more knowledgeable can chime in with citations.
- deleted 3y ago[deleted]
- saagarjha 3y agoGenerally these attacks do not persist, as this is quite a bit more challenging.
- sleepybrett 3y agoHere is a very technical breakdown of the malware: https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegasus-technical-analysis.pdf https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas...
- saagarjha 3y agoNote that this is a very old analysis.
- zozbot234 3y agoIf you're being targeted with anything like Pegasus (i.e. a state sponsored attack), you should definitely assume that even a factory reset will not fix the issue. It's more about "better safe than sorry" than anything that can be said with certainty, since these attacks may evolve over time.