Predator iPhone spyware is now in the spotlight after a new technical analysis from Jamf Threat Labs shows how advanced commercial spyware can bypass Apple's security indicators and silently activate the camera and microphone.
New research from Jamf Threat Labs publicly demonstrates for the first time how commercial spyware can bypass Apple’s camera and microphone indicators – and silently monitor iPhones without the user noticing. The report documents how Predator spyware is used in real-world attacks and provides a unique insight into how today’s most advanced mobile threats work in practice.
When camera or microphone is used on an iPhone, green or orange indicators normally appear on the screen. It has been known for some time that these signals could in theory be bypassed – but now presents Jamf Threat Labs the first technical analysis that shows how this is actually done in practice.
– This isn't about a new iOS vulnerability or something that requires a security patch from Apple. It's a malware analysis that shows how already-installed spyware behaves after a device has been compromised. The report aims to help defenders better understand the threat landscape and build stronger capabilities to detect these types of attacks., says Adam Boynton, Enterprise Strategy Manager, EMEA.
The report describes how Predator spyware, developed by Intellexa/Cytrox, can block iOS security indicators while the camera and microphone continue to record – and the device remains fully functional.
The report shows, among other things:
- A single technical manipulation turns off both camera and microphone warnings: Predator simultaneously blocks the green camera dot and orange microphone indicator by stopping sensor data before it reaches the user interface – making the surveillance completely invisible.
- Recording can occur without the system reacting: By manipulating internal iOS objects, Predator causes changes in recording status to be ignored completely – without error messages or visual cues to the user.
- Smartly constructed stealth design: Predator's call recording feature does not contain its own code to turn off indicators, but relies on this already being enabled via another module – a clear sign of advanced and modular architecture.
- Advanced attacks against iOS core functions: Jamf Threat Labs has documented how Predator targets private iOS frameworks and uses ARM64 techniques to covertly access the camera, including by redirecting authenticated code.
– These types of attacks are extremely difficult for an individual user to detect. That’s why it’s crucial for companies to be proactive about security: keep operating systems up to date, restrict permissions, avoid unknown apps and links, and most importantly – use solutions that continuously monitor device behavior. IT teams should be extra vigilant about any anomalous activity, unexpected battery drain, or data traffic, as these can be early signs of compromised devices., continues Adam Boynton.
The full report is available here: https://www.jamf.com/blog/predator-spyware-ios-recording-indicator-bypass-analysis/
About Jamf
Jamf's goal is to simplify the work of businesses and organizations by providing an Apple experience that users love and businesses trust.
Jamf is the only company in the world to provide a complete management and security solution for Apple first environments that is secure, user-friendly, and protects personal privacy.








