Security News SandJacking Attack Can Replace iOS Apps with Malicious Versions

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Apple has yet to fix a vulnerability which could allow attackers to replace regular apps with rogue versions without the user’s knowledge.

Chilik Tamir from security vendor Mi3 Security disclosed the bug at the Hack in the Box conference in Amsterdam last week and has been told by Cupertino that it is working on a patch, although so far none has been forthcoming, according to reports.

Tamir demoed a similar attack at Black Hat Asia at the end of March. Using a self-built tool dubbed ‘Su-A-Cyder’ he showed how an attacker could replace legitimate apps developed with Xcode7 – an iOS IDE. Anyone can apparently get an Xcode7 developer’s certificate as long as they can produce an email address and Apple ID.

If the malicious replacement app has the same bundle ID as the original it could be downloaded onto a victim’s device – allowing an attacker to carry out a potentially wide range of malicious activities without the user's knowledge

Apple’s iOS 8.3 release blocked this attack route by preventing any app upgrades if the files don’t match.

However, in Amsterdam last week, Tamir apparently showed a way to circumvent this mitigation with SandJacking – a new technique in which an attacker with access to a victim’s device initiates a back-up, then deletes the original app, before loading the malicious replacement and restoring the device from back-up.


Full Article. SandJacking Attack Can Replace iOS Apps with Malicious Versions
 

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
Another reason why IOS needs a real time security app. I am still waiting for a MBAM Mobile (Apple) Edition! Apple products in general are more secure than Windows but still not invincible.
 
  • Like
Reactions: frogboy

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
More implementation on the security mechanism of IOS, even though more secure than Android however its more deadly when split through because of possible unique vulnerability,
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top