IOS_YISPECTER.A
iOS


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This malware abuses the Apple enterprise certificates to install third-party apps into devices only when the iOS system is older than version 8.3.
It is able to receive commands from C&C server. It is able to replace legitimate apps with malicious apps. It can hijack other apps to show ads. It collects device info such as UUID, MAC address, and installed apps.
TECHNICAL DETAILS
NOTES:
This malware abuses the Apple enterprise certificates to install third-party apps into devices only when the iOS system is older than version 8.3. It abuses private APIs, usually not allowed and rejected in App Store review flow.
It is able to receive commands from C&C server. It is able to replace legitimate apps with malicious apps. It can hijack other apps to show ads. It collects device info such as UUID, MAC address, and installed apps.
It monitors itself to avoid being deleted. It hides it's icon in the iOS springboard.
The malware hijacks other apps to display ads.
SOLUTION
NOTES:
Keep your iOS device updated to the latest version.
Did this description help? Tell us how we did.

