Analysis by: Lambert Sun

 PLATFORM:

iOS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This malware abuses the Apple enterprise certificates to install third-party apps into devices only when the iOS system is older than version 8.3.

It is able to receive commands from C&C server. It is able to replace legitimate apps with malicious apps. It can hijack other apps to show ads. It collects device info such as UUID, MAC address, and installed apps.

  TECHNICAL DETAILS

NOTES:

This malware abuses the Apple enterprise certificates to install third-party apps into devices only when the iOS system is older than version 8.3. It abuses private APIs, usually not allowed and rejected in App Store review flow.

It is able to receive commands from C&C server. It is able to replace legitimate apps with malicious apps. It can hijack other apps to show ads. It collects device info such as UUID, MAC address, and installed apps.

It monitors itself to avoid being deleted. It hides it's icon in the iOS springboard.

The malware hijacks other apps to display ads.

  SOLUTION

Minimum Scan Engine: 9.750

NOTES:

Keep your iOS device updated to the latest version.


Did this description help? Tell us how we did.