Inside EggShell: The iOS Surveillance Time Capsule
How a Python script and a handful of Objective-C hooks turned jailbroken iPhones and locked Macs into remote sensor arrays.
EggShell is a post exploitation tool written in Python. It gives you a command line session with extra functionality between you and a target machine. EggShell gives you the power to upload/download files, tab complete, take pictures, take screenshots, and much more.
- EggShell uses AppleScript to generate native system dialogs that trick users into providing root credentials.
- The framework leverages private Objective-C frameworks to turn jailbroken iOS devices into silent remote surveillance bugs.
- A central Python server dynamically fingerprints targets to deliver platform-specific payloads for macOS, iOS, and Linux.
- EggShell represents a legacy era of post-exploitation that relied on pre-installed system dependencies like Python 2.7.
The Native UI Phish
Most Remote Administration Tools treat a compromised machine as just a UNIX shell. A blinking cursor in a terminal window. EggShell approached the problem differently. It treated Apple devices as rich, physical sensor arrays and interactive surfaces. The framework did not just want to execute commands in the background. It wanted to manipulate the user in the foreground.
This philosophy is most visible in its entry vectors and social engineering tactics. The framework includes a teensy_payload.py module designed specifically for USB HID (Human Interface Device) injection. An attacker could plug a small microcontroller into an unattended Mac. The device would emulate a keyboard, typing out a malicious payload at superhuman speed before the user returned.
Once inside, EggShell needed root access. Instead of relying solely on complex kernel exploits, it often took the path of least resistance: asking the user nicely. The prompt_macos.py module uses AppleScript to generate a pixel-perfect, native-looking macOS system dialog. It presents a padlock icon and politely requests the user's password to "install system updates." When the user complies, the credentials are piped directly back to the attacker's server, enabling a silent privilege escalation.
Piercing the iOS Sandbox
The true power of EggShell lies in its iOS capabilities. Standard iOS applications operate within a strict sandbox. They cannot access other apps' data, silently turn on the camera, or read system-level messages. EggShell bypassed these restrictions by specifically targeting jailbroken devices.
The core of this capability lives in src/esplios/espl.m. This Objective-C payload acts as the malicious implant. Because the device is jailbroken, the payload can link against Apple's private frameworks. It uses AVCaptureSession to silently snap photos from the front or rear cameras without triggering the shutter sound or UI indicators. It leverages CPDistributedMessagingCenter to intercept secure system messages.
It even simulates physical hardware interactions. The framework includes modules to simulate Home button presses or force the device to respring (restart the SpringBoard UI process). This level of control goes far beyond standard network surveillance. It turns the target's pocket device into a remote-controlled physical bug.
Python Orchestrating Objective-C
Managing multiple compromised devices across different operating systems requires a flexible orchestrator. EggShell uses a Python 2.7 server to manage multi-platform staging and dynamic payload delivery. The multihandler.py module allows a single operator to maintain multiple backgrounded sessions simultaneously.
The architecture relies heavily on the "stager" pattern. When an attacker gains initial execution on a target, they do not drop a massive, fully-featured binary. Instead, they execute a tiny bash one-liner. This stager reaches out to the Python server and fingerprints the target operating system using the uname -p command.
The Python server receives this fingerprint and dynamically routes the request. If the target is a Mac, it pulls down the compiled macOS Objective-C binary. If it is Linux, it sends a Python script. The payload is downloaded to the temporary directory, executed in the background, and establishes an encrypted JSON socket connection back to the operator. The Python server acts as a switchboard, seamlessly translating high-level operator commands into platform-specific executions.
The Shift to Static Binaries
EggShell is a product of its era. It relies heavily on Python 2.7 being pre-installed on target systems (a guarantee Apple eventually revoked in macOS Monterey) and uses bash one-liners to bootstrap its execution. This approach is lightweight but fragile in modern environments.
Today, the post-exploitation landscape has shifted. Modern offensive security teams favor tools written in compiled languages like Go or Rust. Frameworks like Sliver or Go-Hydra compile down to massive, self-contained static binaries. They bring their own runtime, completely ignoring the target system's installed dependencies. They are harder to deploy blindly but much more resilient once running.
| Feature | EggShell (Legacy Approach) | Modern C2 (e.g., Sliver) |
|---|---|---|
| Primary Language | Python 2.7 & Objective-C | Go (Golang) |
| Payload Delivery | Bash one-liner stagers | Static cross-compiled binaries |
| Dependency Footprint | High (Requires Python/Bash on host) | Zero (Self-contained runtime) |
| Target Environment | macOS, Jailbroken iOS, Linux | Windows, Linux, macOS (Universal) |
| Encryption Standard | Custom AES/OpenSSL wrappers | Mutual TLS (mTLS), WireGuard |
EggShell remains a fascinating technical artifact. It demonstrates how briefly the walls between mobile hardware and remote software were completely transparent. By combining simple Python scripts with deep Objective-C hooks, it turned consumer electronics into highly effective surveillance tools.
Sources: Codeface analysis of the EggShell repository, system architecture documentation, and historical post-exploitation framework comparisons.