Inside EggShell: The iOS Surveillance Time Capsule

How a Python script and a handful of Objective-C hooks turned jailbroken iPhones and locked Macs into remote sensor arrays.

Read time: 8 min · lucasjacks0n/EggShell

A mechanical apple with a small trapdoor revealing camera lenses and microphones hidden inside, rendered in black ink crosshatching.
EggShell bypassed traditional software boundaries by tapping directly into the physical sensors of Apple devices.
Portrait of Lucas Jackson

EggShell is a post exploitation tool written in Python. It gives you a command line session with extra functionality between you and a target machine. EggShell gives you the power to upload/download files, tab complete, take pictures, take screenshots, and much more.

Lucas Jackson, Author/Maintainer (lucasjacks0n/EggShell)
Key Takeaways

The Native UI Phish

Most Remote Administration Tools treat a compromised machine as just a UNIX shell. A blinking cursor in a terminal window. EggShell approached the problem differently. It treated Apple devices as rich, physical sensor arrays and interactive surfaces. The framework did not just want to execute commands in the background. It wanted to manipulate the user in the foreground.

This philosophy is most visible in its entry vectors and social engineering tactics. The framework includes a teensy_payload.py module designed specifically for USB HID (Human Interface Device) injection. An attacker could plug a small microcontroller into an unattended Mac. The device would emulate a keyboard, typing out a malicious payload at superhuman speed before the user returned.

Once inside, EggShell needed root access. Instead of relying solely on complex kernel exploits, it often took the path of least resistance: asking the user nicely. The prompt_macos.py module uses AppleScript to generate a pixel-perfect, native-looking macOS system dialog. It presents a padlock icon and politely requests the user's password to "install system updates." When the user complies, the credentials are piped directly back to the attacker's server, enabling a silent privilege escalation.

A close-up of a human hand holding a USB drive that unravels into a fishing line, with a shiny computer dialog box attached as the lure.
EggShell bridged the physical and digital divide, using hardware injection and native UI phishing to bypass standard security boundaries.

Piercing the iOS Sandbox

The true power of EggShell lies in its iOS capabilities. Standard iOS applications operate within a strict sandbox. They cannot access other apps' data, silently turn on the camera, or read system-level messages. EggShell bypassed these restrictions by specifically targeting jailbroken devices.

The core of this capability lives in src/esplios/espl.m. This Objective-C payload acts as the malicious implant. Because the device is jailbroken, the payload can link against Apple's private frameworks. It uses AVCaptureSession to silently snap photos from the front or rear cameras without triggering the shutter sound or UI indicators. It leverages CPDistributedMessagingCenter to intercept secure system messages.

It even simulates physical hardware interactions. The framework includes modules to simulate Home button presses or force the device to respring (restart the SpringBoard UI process). This level of control goes far beyond standard network surveillance. It turns the target's pocket device into a remote-controlled physical bug.

A multi-stage sequence showing the EggShell stager flow. Step 1 shows a small bash terminal icon labeled "Target Execution". An arrow points to Step 2

Python Orchestrating Objective-C

Managing multiple compromised devices across different operating systems requires a flexible orchestrator. EggShell uses a Python 2.7 server to manage multi-platform staging and dynamic payload delivery. The multihandler.py module allows a single operator to maintain multiple backgrounded sessions simultaneously.

The architecture relies heavily on the "stager" pattern. When an attacker gains initial execution on a target, they do not drop a massive, fully-featured binary. Instead, they execute a tiny bash one-liner. This stager reaches out to the Python server and fingerprints the target operating system using the uname -p command.

The Python server receives this fingerprint and dynamically routes the request. If the target is a Mac, it pulls down the compiled macOS Objective-C binary. If it is Linux, it sends a Python script. The payload is downloaded to the temporary directory, executed in the background, and establishes an encrypted JSON socket connection back to the operator. The Python server acts as a switchboard, seamlessly translating high-level operator commands into platform-specific executions.

A vintage telephone switchboard being operated by mechanical hands, plugging physical braided cables directly into the back of a sleek, modern smartphone.
The Python C2 server acts as a central orchestrator, dynamically routing the correct platform-specific payloads to diverse target environments.

The Shift to Static Binaries

EggShell is a product of its era. It relies heavily on Python 2.7 being pre-installed on target systems (a guarantee Apple eventually revoked in macOS Monterey) and uses bash one-liners to bootstrap its execution. This approach is lightweight but fragile in modern environments.

Today, the post-exploitation landscape has shifted. Modern offensive security teams favor tools written in compiled languages like Go or Rust. Frameworks like Sliver or Go-Hydra compile down to massive, self-contained static binaries. They bring their own runtime, completely ignoring the target system's installed dependencies. They are harder to deploy blindly but much more resilient once running.

Feature EggShell (Legacy Approach) Modern C2 (e.g., Sliver)
Primary Language Python 2.7 & Objective-C Go (Golang)
Payload Delivery Bash one-liner stagers Static cross-compiled binaries
Dependency Footprint High (Requires Python/Bash on host) Zero (Self-contained runtime)
Target Environment macOS, Jailbroken iOS, Linux Windows, Linux, macOS (Universal)
Encryption Standard Custom AES/OpenSSL wrappers Mutual TLS (mTLS), WireGuard

EggShell remains a fascinating technical artifact. It demonstrates how briefly the walls between mobile hardware and remote software were completely transparent. By combining simple Python scripts with deep Objective-C hooks, it turned consumer electronics into highly effective surveillance tools.


Sources: Codeface analysis of the EggShell repository, system architecture documentation, and historical post-exploitation framework comparisons.