Mobile Forensics & Malware Analysis Guide: ADB Extraction, Sysdiagnose & IOC Hunting

🛡️ Verified Threat IntelDigitalSpying Research Desk
📅 August 26, 2026⏱️ 5 min read

Commercial spyware suites, nation-state mercenary surveillance implants (such as NSO Group's Pegasus, Intellexa's Predator, and Cytrox), and sophisticated mobile banking trojans operate with unprecedented stealth inside modern mobile operating systems. Because iOS and Android employ strict kernel-level application sandboxing, traditional on-device antivirus scanners are ineffective at detecting zero-click kernel exploits. Uncovering mobile compromises requires disciplined digital forensics methodologies combining Android Debug Bridge (ADB) logical dumps, iOS Sysdiagnose log carving, and Mobile Verification Toolkit (MVT) indicator hunting.

The Asymmetric Landscape of Mobile Device Exploitation

Smartphones represent the ultimate surveillance prize: they maintain continuous physical proximity to human targets, possess high-definition cameras and ambient microphones, record precise satellite geolocation coordinates, and store end-to-end encrypted messaging databases (Signal, WhatsApp, Telegram). Advanced threat actors achieve device takeover via zero-click remote exploits targeting media parsing libraries (such as Apple's BlastDoor sandbox or Android's Stagefright architecture) delivered silently through iMessage, MMS, or WhatsApp calls.

Once injected into memory, sophisticated mobile implants avoid persistent disk modifications that would trigger secure boot verifications (Apple Secure Enclave or Android Verified Boot). Implants reside in volatile memory or hide inside legitimate system processes, exfiltrating cryptographic session keys, ambient microphone recordings, and call logs directly to remote C2 infrastructure.

Forensic Protocol: Isolation Prior to Triage

Never connect a suspected infected mobile device directly to a live enterprise network. Isolate the target device inside an RF Faraday bag, terminate cellular and Wi-Fi radios immediately, and conduct acquisitions strictly over physical, hardware-isolated USB connections.

Android Forensic Triage: ADB Extraction and Permission Auditing

On Android devices, initial live-system triage is conducted via the Android Debug Bridge (ADB). Analysts establish an authorized USB debugging session to extract logical system state, package manifests, and battery telemetry without altering device partition integrity:

  1. Third-Party Package Enumeration: Threat actors frequently disguise stalkerware and trojans using generic package identifiers (e.g., com.android.system.service). Analysts dump all third-party and sideloaded APK paths to verify developer signing certificates:
# 1. Enumerate all third-party installed packages and APK filesystem locations
adb shell pm list packages -3 -f

# 2. Extract APK file for static reverse engineering with JADX
adb pull /data/app/~~randomString/com.suspicious.payload-1/base.apk ./analysis/

# 3. Audit active Accessibility Services (Common trojan keylogging primitive)
adb shell settings get secure enabled_accessibility_services

Banking trojans and commercial stalkerware abuse Android's Accessibility Services API to bypass OS sandboxing. By obtaining accessibility permissions, malware can inspect the view hierarchy of any running app, scrape two-factor authentication SMS codes, record keystrokes, and automatically grant itself device administrator privileges without user intervention.

Operating System Forensic Acquisition Vector Key Artifact Databases
Android OS ADB Logical Dump & Bugreport dumpsys appops, accessibility, batterystats
Apple iOS Encrypted Backup via libimobiledevice DataUsage.sqlite, InteractionC.db, sms.db
Apple iOS Sysdiagnose Diagnostic Tarball powerlog_*.PLSQL, Unified Log Streams (.tracev3)
Network Layer Cellular Radio & Wi-Fi PCAP Capture TLS SNI Handshakes, DNS Queries, IP Flow Exfiltration

iOS Forensic Triage: Sysdiagnose Analysis and MVT Carving

Because iOS enforces rigid root filesystem read-only locks, extracting forensic evidence requires parsing diagnostic archives or extracting encrypted backups using open-source tools like libimobiledevice:

  1. Generating an iOS Sysdiagnose: Pressing and holding Volume Up + Volume Down + Power for 1.5 seconds triggers a hardware vibration, initiating an automated system diagnostic dump. The resulting archive contains system power logs, crash logs, process trees, and unified log archives.
  2. Carving the Powerlog Database: Inside the sysdiagnose archive, the file powerlog_*.PLSQL contains granular SQLite records of every background process, CPU cycle, and network socket spawned by the operating system over the preceding 30 days. Spyware processes (such as Pegasus's bh or setframed binaries) appear as anomalous background tasks consuming cellular data while the device screen is off.
  3. Executing Mobile Verification Toolkit (MVT): MVT cross-references SQLite records extracted from an iOS backup or sysdiagnose against known STIX2 Indicator of Compromise (IOC) feeds published by Amnesty International and Citizen Lab:
# Running Mobile Verification Toolkit against Decrypted iOS Backup
mvt-ios check-backup --iocs ./citizen_lab_malware.stix2 ./extracted_backup_dir/

# Checking DataUsage.sqlite for anomalous network sockets
mvt-ios check-backup --iocs ./iocs.json --output ./results ./backup_folder

Static and Dynamic Reverse Engineering: JADX and Frida

When an investigator extracts a suspicious Android APK or iOS Mach-O binary, in-depth malware analysis is necessary to identify C2 infrastructure and cryptographic keys:

  • Decompilation with JADX: Opening the APK in JADX-GUI decompiles Dalvik Executable (DEX) bytecode back to readable Java. Analysts inspect the AndroidManifest.xml for excessive permissions (RECEIVE_BOOT_COMPLETED, RECORD_AUDIO, ACCESS_FINE_LOCATION) and locate C2 communication classes.
  • Dynamic Hooking with Frida: In a controlled mobile lab environment, analysts deploy Frida to hook runtime API calls on a rooted or jailbroken test device. Frida scripts intercept plaintext data before it is encrypted for network transit, capture dynamically loaded payload classes, and bypass SSL certificate pinning:
// Frida Hook: Intercepting HTTP Request URLs on Android
Java.perform(function () {
    var OkHttpClient = Java.use("okhttp3.OkHttpClient");
    var Request = Java.use("okhttp3.Request");
    Request.url.implementation = function () {
        var result = this.url();
        console.log("[+] Intercepted HTTP Request: " + result.toString());
        return result;
    };
});

Mobile Hardening and Counter-Surveillance Recommendations

Protecting high-risk personnel (such as executives, investigative journalists, and legal counsel) against zero-click mobile exploits requires proactive operational security controls:

  • Enable Apple Lockdown Mode: On iOS 16 and later, enabling Lockdown Mode drastically restricts the attack surface by disabling complex web technologies (such as JIT compilation), blocking unrequested iMessage attachments, and preventing unauthorized USB configuration profiles when locked.
  • Perform Daily Device Reboots: Because advanced zero-click exploits often operate strictly in volatile RAM to evade persistent root verifications, daily device reboots terminate memory-resident implants, forcing adversaries to re-exploit the device and increasing the probability of detection.
  • Disable 2G GSM on Mobile Handsets: Modern smartphones permit disabling legacy 2G connectivity in cellular settings. This prevents IMSI-catchers (StingRays) from executing downgrade attacks that strip cellular encryption and force cleartext interception.
  • Disable Bluetooth and Wi-Fi When Not in Use: Prevent passive proximity tracking, BLE beacon triangulation, and rogue Wi-Fi access point spoofing by turning off wireless radios in transit.
Classification:Cyber Security IntelligenceZero-Day AnalysisDefensive Engineering
🛡️

About the DigitalSpying Research Desk

The DigitalSpying Threat Intelligence Desk is composed of seasoned security researchers, reverse engineers, and blue team architects. Our mission is to publish reproducible, peer-audited threat analyses, hardware security evaluations, and defensive countermeasures.