Company Logo

The latest malware will infect the non-jailbroken phones without users’ knowledge

Technology Research & Development

Updated on Sep 13, 2018

View more like this | Visit Australia, UN | Contact Fashion and Living
Image for The latest malware will infect the non-jailbroken phones without users’ knowledge with ID of: 2800378
Apple users are now vulnerable to a malware called “Ace Deceiver,” which can infect the non-jailbroken iOS devices as well. The malware affects the devices through PCs and installs apps on a user’s phone without their knowledge.

FairPlay technique is used for Apple Store’s security. Hackers have utilized the same "FairPlay Man-in-the-Middle" technique to trespass the security system. The trespassers are able to buy an app from the Apple Store and then intercept to save the authorization code. Hackers then design software similar to iTunes, through which iOS devices believe that the app was bought by a user.

FairPlay technique has been breached before as well, but that was done just to increase the use of pirated apps. But this is the first time that FairPlay was breached to distribute malware to Apple users. The researchers at Palo Alto Network had found three malicious apps installed on the App Store in February.

How Does Ace Deceiver Work?



Initially, the malware apps were first uploaded on the App Store disguised as wallpapers. This helped hackers to pass through the security check.
Once they bypassed Apple’s review process, they bought back those apps, and intercepted the authorization code.

A program similar to iTunes was developed by the hackers called “Aisi Helper” that performed operations such as jail breaking, device management, system reinstallation, system backup, and system cleaning.

Once a user connects a device with PCs, Ace Deceiver is installed in the phone without a user’s knowledge through the authorization code. Once installed, the attack-icon will appear on the home screen of the devices.
These apps then encourage users to download other apps from the App Store developed by the hackers. Once users input their Apple ID and password on the Store they get more features.

The malicious apps have the ability to infect other users even after it’s removed through the PC software, as they already have the authorization code. According to Palo Alto’s blog post: “As of this writing, it looks as though AceDeceiver only affects users in mainland China. The bigger issue, however, is that AceDeceiver is evidence of another relatively easy way for malware to infect non-jailbroken iOS devices. As a result, it’s likely we’ll see this start to affect more regions around the world, whether by these attackers or others who copy the attack technique.”

These apps need to be available only once in the App Store. Earlier this month, hackers targeted Mac users in a ransom ware attack. This was the first ransomware attack on Mac, which infected the device, once you download the Transmission’s version 2.90.
goodideazs, LLC is not affiliated with the authors of this post nor is it responsible for its content, the accuracy and authenticity of which should be independently verified.