New iOS malware targets stock iPhones, spreads via App Store

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Bad news. Even worse news if you're in China...
16 Mar 2016 at 14:51, John Leyden

Miscreants have forged a strain of iOS malware which poses a greater risk than previous nasties because it can infect non-jailbroken devices without the user’s confirmation.

AceDeceiver is fundamentally different from recent iOS malware because it relies in exploiting flaws in Apple’s DRM software rather than abusing enterprise certificates, a common trick in iOS malware over the past two years or so.


fairplay_mitm.jpg

FairPlay MitM diddle: No certs required

AceDeceiver is the first iOS malware that exploits flaws in FairPlay, Apple’s DRM protection system to install malicious apps on iOS devices regardless of whether or not they are jailbroken.

Even though Apple has removed AceDeceiver from its App store, the malware can still spread, security researchers at Palo Alto Networks warn.

Malicious apps only need to have been available in the App Store once to spread, simply requiring the victim to install the client to his or her PC. After that, infection of iOS devices is completed in the background without the user’s awareness with the only indication being a new icon on the home screen that the user won’t recall downloading.
The hacking technique used by AceDeceiver, called “FairPlay Man-In-The-Middle (MITM)”, has been used to spread pirated iOS apps since 2013 but this is the first time it’s been used to spread malware.

Three different iOS apps in the AceDeceiver family were uploaded to the official App Store between July 2015 and February 2016, each claiming to be wallpaper apps. These apps successfully bypassed Apple’s code review at least seven times, according to Palo Alto. The success of AceDeceiver provides evidence that hackers have developed techniques to bypass Apple’s code review process and get malicious apps into the App Store.

AceDeceiver only displays malicious behaviours when a user is located in China, but this is likely to change over time.

Palo Alto Networks’ write-up of the AceDeceiver threat can be found in a blog post here. ®
 
  • Like
Reactions: Jrs30 and CySecy825

Azure

Level 28
Verified
Top Poster
Content Creator
Oct 23, 2014
1,714
I wonder what Apple will say about this after they decided to remove every anti-malware from the appstore because they thought they were unnecessary.

oh crap... Apple malware o_O I use an iPhone...
I use an Iphone as well. And honestly this kind of thing shouldn't be that surprising considering the immense popularity Apple has. It was only a matter of time someone would develop malware for it.

Now to wait and see how fast can Apple fix the issue
 
  • Like
Reactions: SecretKeeper

SecretKeeper

Level 3
Verified
Well-known
Dec 25, 2015
120
Oh great... You can't do anything on the internet anymore without these dang risks following you. Looks like I'll have to get an Anti-virus for my phone. :|
 

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
Maybe this an excuse to get Malwarebytes to make an IPhone app. :p I do love using the app manager.
 
  • Like
Reactions: SecretKeeper

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Like on viruses from Mac OS X, its time to revise some of their policy especially that threats are just somewhere in the corner to produce in the wild list.

If they [Apple] insist to create their own illogical point of view then none will lead to better outcome but rather just praising each other and continue to brainwash the users around.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top