Researchers have discovered a new iPhone Backdoor (or as they call it iOS Persistence Bug) called NoReboot. This particular backdoor cannot be detected and reminds us of predator spyware. For the record, the predator spyware that has infected mobile phones of important figures in the Greek political scene - and not only - while at the same time shocking the world public opinion with the revelation of its dark use in the country where Democracy was born, is a type of spyware that monitors everything we do on our mobile (calls, messages, emails and more) without us realizing it. The discovery of the NoReboot bug was made by the company ZecOps.

ZecOps , a cybersecurity company, is investigating various attack scenarios and recently shared all the information for the benefit of everyone.
iOS Persistence bugs are among the most difficult to detect as the attack surface is somewhat limited and is constantly analyzed by Apple's security teams. For those who don't know, persistence is the attack method that hackers use when they want to break into your environment whenever they want.
Introducing “NoReboot”: The Persistence Bug
ZecOps investigated the iOS system to show how the shutdown process can be modified and an infected user can be tricked into believing that their phone has been turned off, when in fact it is still working. “NoReboot” mimics the normal shutdown process. The person will not be able to distinguish between a real shutdown and a “fake” one – there will be no user-interface or feedback button until the user turns the device back on.
To demonstrate this method, a demonstration will be made of how access to a remote microphone and camera can be achieved after the phone is “turned off” and how it will remain in this state when the device is turned on again.
These days, our phones are overflowing with apps, and it can be difficult to figure out which ones are using our data without permission. Data breaches happen regularly – the information we post is constantly being collected and uploaded without our knowledge.
See also: Uber once again fell victim to a data breach
This article by Dan Goodin talks about an iOS malware discovered to be used by hackers. One of the sentences in the article says: “The installed malware… cannot remain on the device after the device is rebooted, … phones are disinfected immediately upon reboot.”

This is not true. Contrary to popular belief, one cannot rely on a standard reboot. As we will show in this article, a reboot is not enough – other preventive measures must be taken for real safety and security.
What is the most effective iPhone reboot process?
To restart your Apple phone, press the Volume Down and Power buttons simultaneously until a slider appears. Drag the slider from left to right and wait for it to restart.

The iPhone doesn't have an internal fan, so it can be difficult to tell if the phone is working or not. The most reliable way for end-users is to tap the screen and/or press the side button, which will wake the screen, providing users with feedback that their phone is working properly.
Here are some actions that constantly remind us that the phone is on:
- Ring/Sound from incoming calls and notifications
- Haptic Feedback (3D touch)
- Vibration
- Screen
- Camera display
“NoReboot”: Hijack the shutdown process
Let's see if we can disable all of the above indications while the phone with the trojan still works. Let's start with the hijack , which involves injecting code into three daemons.

When you slide to turn off your device, you are actually sending a shutdown from the /Applications/InCallService.app application to SpringBoard, which is a daemon that controls much of the user interface interaction.
See also: Microsoft: Fixes bug that allows ransomware installation
ZecOps managed to intercept the signal by exploiting the Objective-C method -[FBSSystemService shutdownWithOptions:]. Now, instead of sending a shutdown command to SpringBoard, it will notify both SpringBoard and backboardd, which in turn triggers the previously injected code.

The company goes on to say: “In Backboardd, we can hide the spinning wheel animation that appears immediately when SpringBoard stops working. The technique used is [[BKSDefaults localDefaults]setHideAppleLogoOnLaunch:1]. We then cause SpringBoard to exit and prevent it from being relaunched. Since SpringBoard happens to be responsible for handling user behavior and interaction, preventing it from working will make the device appear to be turned off – a perfect strategy for mimicking an artificial shutdown.”

Even though all physical feedback has been disabled, the phone is still fully functional and can maintain an active internet connection . A hacker could take full control of the device without any risk of detection because the phone appears to be turned off.
Below you will see how eavesdropping is done via camera and microphone while the phone is “off.” In reality, malicious actors can do anything the end user and more.

System startup with disguise
To turn their device back on, the user must ensure that it has been properly powered down. The system startup animation with the Apple logo can provide a sense of trust and confidence, so users know they are starting from scratch.
In the absence of control from SpringBoard, backboardd takes over. The company's research on theiphonewiki provides more information about its functions.

The company carefully examined the statement “All touch events are first processed by this daemon, then translated and transmitted to the foreground iOS app” and found that it is in fact true. Furthermore, backboardd even records and transmits the clicks you make on physical buttons! It is clear that using Backboardd enables seamless user experience capabilities in an iOS app.

Backboardd records the exact moment you press a button and then when you release it.

Using cycript, the company found a solution to intercept this event with Objective-C Method Hooking. An instance of _BKButtonEventRecord will be created and inserted into a global dictionary object BKEventSenderUsagePairDictionary. Here, the insertion method was inserted when the user attempts to “open” the phone.

The file will launch SpringBoard, which then allows a special code block to be inserted. This allows root access via local SSH, followed by the execution of /bin/launchctl reboot userspace. As all processes are terminated and the system reboots without the necessary changes to the kernel settings, the malicious code can continue to execute seamlessly after this type of reboot, as the kernel remains patched.
See also: HTML smuggling technique uses SVG files and distributes QBot

Immediately after rebooting, the user will see a mesmerizing Apple logo effect. This is carefully orchestrated by backboardd. When it's time to launch SpringBoard - that's when backboardd allows it to take control of the screen and display its stunning graphics!

From that point, the interactive user interface will be presented to the user. Everything appears normal as all processes have indeed been restarted. Non-persistent threats achieved “persistence” without persistence exploits.
Hijacking Force Restart?
To force restart your device, quickly press the volume up button, followed by the volume down button, and then hold down the power button until you see the Apple logo.
ZecOps , although the post below states that it is done at the hardware level.

Misleading Force Restart
However, it is possible for malicious actors to observe a user's attempts to reboot via backboardd and trick them into releasing the button prematurely. This would mean that in this case the end user failed to perform a successful reboot.

You can find the NoReboot Proof of Concept code here.
Never trust a device that is turned off
With the release of iOS 15, Apple users now have a new feature that allows them to track their device's location even when it's turned off. Malware researcher @naehrdine provided an in-depth analysis of this update and its potential security and privacy implications. And we totally agree that to make sure your device is turned off, simply remove the battery!
Check if your phone has been hacked
Reduce security risks with ZecOps for Mobile. With extensive data collection and incident response capabilities, you can rest assured that your phone is safe from malicious threats.
