Tired of ads? Enjoy an ad-free experience by signing up.
  • Insights
    This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
Oscar Waterworth · · 3 min read

A hazardous iOS malware is quietly invading China


In mid-2015, a growing number of Apple OS users started reporting suspicious OS tweaks. A thorough analysis by WeipTech, a non-professional technical team, revealed that over 225,000 valid Apple accounts containing their respective passwords were found stored (stolen) on a remote server.

After subjecting 92 samples of the malware in question to further analysis in search for the hacker’s ultimate goal, an ominous-sounding name, KeyRaider, was appointed to the largest malware-induced account theft in Apple’s history.

Jailbroken devices targeted

Investigations showed that the infamous KeyRaider was designed to target Apple devices that were jailbroken. The malware has seemingly set its sights on Asia as ground zero, but has managed to spread its roots into 18 other countries, including United States, Canada, United Kingdom, Germany, Italy, Spain, Russia, China, Japan, South Korea and Israel. Even Australia was not spared.

This cleverly-designed malicious software uses MobileSubstrate and applies itself to system processes, stealing account usernames, passwords and device globally unique identifiers (GUIDs) in a curious manner – by intercepting iTunes traffic on each of the devices.

It also steals certificates and private keys used by Apple’s push notification service, while rendering local and remote unlocking functions disabled on infected iPhone or iPad devices.

To make matters worse, Keyraider uploads this data onto a vulnerable server, thus exposing the stolen user information to everyone. This has caused a stir among Apple officials, given its strong reputation in upholding user privacy.

An Apple store heist

The breach does not stop at allowing users to download apps for free, although this appears to be the hacker’s ultimate goal. Two affected users were also able to download apps and make in-app purchases without paying.

iPhone and iPad Jailbreaking in China, 2013

They work by hijacking purchase requests, downloading breached accounts and/or receipts from the server (C2) and then emulating the iTunes protocol with the goal of logging in to Apple servers. This way, the virtual criminal masterminds are able to purchase apps requested by their target users, the jailbroken victims, who had already intended to get Apple products for free.

Complaints from affected users were mostly about the infected accounts having purchase histories that were unaccounted for.

A smaller, yet far from insignificant number of users, seemed to have used 4Shared cloud-based sharing platform to download files of questionable security. After analyzing a number of 4Shared reviews, there appears to be no evidence indicating that any risk of breach was mentioned as a clear and present danger.

Malware first discovered in China

Even though the aliases mischa07 and i_82 are frequently mentioned in the list of suspects, the exact point of origin of KeyRaider remains a mystery.

The exact point of origin of KeyRaider remains a mystery.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Oscar Waterworth

I am a writer and a senior editor at Bizzmarkblog. I am most interested in the China's startup ecosystem, technology, marketing and more. You can read my latest posts by following me on Twitter.