Apple neuters iOS WireLurker trojan

Apple neuters iOS WireLurker trojan

 
 


Researchers also find a Windows version





Researchers also find a Windows version

Apple users had been worrying since a while about the WireLurker Tro/1//10//11//12/which had been targeting the iOS devices but now Apple says that they have nipped the Tro/1//10//11//12/in the bud. And it has become clearer now that the threat posed by the Tro/1//10//11//12/was more widespread than it was initially thought as researchers found an earlier variant which had been using Windows malware to attack Apple devices. An Apple spokesperson issued a statement yesterday to Business Insider in which he said “We are aware of malicious software available from a download site aimed at users in China, and we’ve blocked the identified apps to prevent them from launching. As always, we recommend that users download and install software from trusted sources.”

In an attempt to thwart the attack, Apple has revoked trust for a cryptographic certificate that it had previously issued to a developer. Some researchers at Palo Alto, a security firm, have exposed the WireLurker malware earlier this week. This malware apparently attacks the iOS devices through the USB connections which come from infected OS X systems. This enables the malware to be able to hijack users’ information. The Tro/1//10//11//12/gained so much hype because of its ability to automatically generate malware for iOS. This could happen even if the device is not jailbroken.

The Tro/1//10//11//12/could install third-party applications on non-jailbroken iOS devices with the help of a feature called “enterprise provisioning”. This relies on enterprise certificate which creates user profiles in corporate environments. You might all be wondering where this malware got its name of WireLurker from. Well, the main reason behind this name is that it infects the iOS device once it’s connected via USB with an infected Mac. In total, there were 467 pieces of Mac malware that could infect iOS devices in this manner and all these hosted on a third-party site in China called Maiyadi App Store.

Only a day earlier it was widely accepted that an infected Mac was the only attack vector but thanks to security researcher Jaime Blasco from AlienVault Labs, he revealed that there was also a Windows version and it was being distributed prior to the Mac-only variant. This newly discovered Windows malware was being hosted on the public cloud of China’s answer to Google search, Baidu. In an update from Palo Alto researchers Claud Xiao and Royce Lu said “Previously we knew the WireLurker was distributed through the Maiyadi App Store. However, the newly revealed samples were directly uploaded to Baidu YunPa by user “ekangwen206”.

180 Windows executables and 67 Mac OS X applications had been uploaded by this user and each one of them featured a variant of the WireLurker Trojan. In a much similar manner, malware is targeting Chinese iOS owners who have installed pirated software. Palo Alto has revealed that these 247 applications had been downloaded 65,213 times since they were uploaded on March 12 and March 13 last year. This was roughly a month earlier than the version that appeared on the Mayaidi App store. As opposed to this, the new variant had been downloaded 356,104 times.

The iOS apps which had been affected by the Tro/1//10//11//12/include the pirated versions of Facebook, WhatsApp, Twitter, Instagram, Minecraft, Flappy Bird, Bible, GarageBand, the iOS calculator, Keynote, iPhoto, Find My iPhone, iMovie and iBooks. The Windows version found on Baidu appears to be less refined predominantly because it has the ability to attack the jailbroken iOS devices. Moreover, this also seems to have been coming from the same attacker and it also holds the title of being the first iOS malware that attacks the ARM64 architecture.




“The main functionality of this malware is to copy sfbase.dylib and sfbase.plist in its Resources directory to specific locations to make them perform as a MobileSubstrate tweak, shown in Figure 7. Additionally, the malware will communicate with the C2 server ‘www.comeinbaby.com’, the same server used by the version of WireLurker we revealed yesterday,” wrote Xiao and Lu.

source: zdnet

This Could Also Interest You

Stephen Curry Best Point Guard in NBA Per Steve Kerr

Stephen Curry Best Point Guard in NBA Per Steve Kerr Golden State Warriors head coach Steve Kerr hailed his player, Stephen Curry, as the best point guard in the NBA.

13 minutes ago


Jordy Nelson, Randall Cobb Eclipse 30-Year Green Bay Packers Team Record

Jordy Nelson, Randall Cobb Eclipse 30-Year Green Bay Packers Team Record Green Bay Packers wide receivers Jordy Nelson and Randall Cobb combined for 238 receiving yards in a 53-20 rout of the…

1 hour ago


Giancarlo Stanton Agrees to Record 13-Year, $325M Deal With Miami Marlins

Giancarlo Stanton Agrees to Record 13-Year, $325M Deal With Miami Marlins Right fielder Giancarlo Stanton has agreed to a record 13-year, $325 million deal with the Miami Marlins on Nov. 17….

2 hours ago


Holiday Gift Guide 2014: Dell Inspiron i3531-1200BK 15.6-Inch Laptop

Holiday Gift Guide 2014: Dell Inspiron i3531-1200BK 15.6-Inch Laptop This is a great laptop with a great price.

8 hours ago, 12:38pm CST


Sam's Club Black Friday 2014 Deals Highlighted

Sam’s Club Black Friday 2014 Deals Highlighted Sam’s Club announced today their Black Friday deal highlights.

8 hours ago, 12:23pm CST


Dell Black Friday 2014 Sale Detailed

Dell Black Friday 2014 Sale Detailed Dell announced its plans and deals for Black Friday 2014.

8 hours ago, 12:10pm CST


Costco Black Friday 2014 Ad released

Costco Black Friday 2014 Ad released The Costco Black Friday Ad has been officially released. See the compact Costco ad below.

9 hours ago, 11:45am CST


Rakuten offers 7% back on Tech Deals and 15% on Everything Else

Rakuten offers 7% back on Tech Deals and 15% on Everything Else Rakuten offers 7% back in Rakuten points on tech deals until Nov. 18.

9 hours ago, 11:28am CST


Holiday Gift Guide 2014: Dell Inspiron i3542-5000BK Laptop

Holiday Gift Guide 2014: Dell Inspiron i3542-5000BK Laptop Features a 15.6-Inch Screen with Touchscreen laptop.

9 hours ago, 11:15am CST


The Advertised Black Friday 2014 Deals sold by Amazon Now

The Advertised Black Friday 2014 Deals sold by Amazon Now Amazon is already offering Black Friday deals advertised in Black Friday 2014 Ads of competitors.

9 hours ago, 11:08am CST


[title}

Black Friday 2014 Deal Guides Updated The Black Friday 2014 sale events are only days away. Find below the best 2014 Black Friday deals in our constantly…

10 hours ago, 10:38am CST


Bill Cosby’s Rape Accusation List Increases as Another Woman Confesses

Bill Cosby’s Rape Accusation List Increases as Another Woman Confesses Bill Cosby has also been accused in the past when he had to settle a civil suit brought against him in 2006.

11 hours ago, 9:52am CST


Holiday Gift Guide 2014: Acer C720 Chromebook

Holiday Gift Guide 2014: Acer C720 Chromebook Features 11.6-Inch screen, 2GB.

11 hours ago, 9:35am CST


New Office Depot OfficeMax Cyber Monday Sale is Underway

New Office Depot OfficeMax Cyber Monday Sale is Underway Office Depot OfficeMax hosts another Cyber Monday sale featuring a Core i3 Laptop deal.

11 hours ago, 9:25am CST


Gamestop Black Friday 2014 Ad leaks

Gamestop Black Friday 2014 Ad leaks The Gamestop Black Friday 2014 Ad surfaced on Black Friday sites.

11 hours ago, 9:14am CST


Holiday Gift Guide 2014: ASUS 15.6-Inch Dual Core Intel 2.16 Ghz Laptop

Holiday Gift Guide 2014: ASUS 15.6-Inch Dual Core Intel 2.16 Ghz Laptop With 4GB RAM and 500GB Hard Drive.

12 hours ago, 9:00am CST


I4U News announces Winner of $5,000 Black Friday Giveaway and New Giveaway

I4U News announces Winner of $5,000 Black Friday Giveaway and New Giveaway The big $5,000 Black Friday Giveaway has a winner. I4U News launches another cash giveaway that will have a winner in…

12 hours ago, 8:33am CST


Mobile wallets get some resistance in some quarters

Mobile wallets get some resistance in some quarters Why some retailers won’t buy the ideas of mobile wallets

12 hours ago, 8:29am CST


Pay your rent and school fees using Apple Pay

Pay your rent and school fees using Apple Pay How effective is RadPad?

12 hours ago, 8:23am CST


Holiday Gift Guide 2014: Dell Inspiron i3531-1200BK 15.6-Inch Laptop

Holiday Gift Guide 2014: Dell Inspiron i3531-1200BK 15.6-Inch Laptop A laptop makes a great Holiday Gift for anyone on your list.

13 hours ago, 7:34am CST


Holiday Gift Guide 2014: Canon PowerShot G7 X Digital Camera

Holiday Gift Guide 2014: Canon PowerShot G7 X Digital Camera This camera would make great gift this Holiday Season.

15 hours ago, 5:51am CST


Holiday Gift Guide 2014: Fujifilm X30 12 MP Digital Camera with 3.0-Inch LCD

Holiday Gift Guide 2014: Fujifilm X30 12 MP Digital Camera with 3.0-Inch LCD This is a great gift idea for the Holidays.

15 hours ago, 5:42am CST


Related Posts

Leave a Reply

Your email address will not be published. Required fields are marked *