- Insights This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
A hazardous iOS malware is quietly invading China

In mid-2015, a growing number of Apple OS users started reporting suspicious OS tweaks. A thorough analysis by WeipTech, a non-professional technical team, revealed that over 225,000 valid Apple accounts containing their respective passwords were found stored (stolen) on a remote server.
After subjecting 92 samples of the malware in question to further analysis in search for the hacker’s ultimate goal, an ominous-sounding name, KeyRaider, was appointed to the largest malware-induced account theft in Apple’s history.
Jailbroken devices targeted
Investigations showed that the infamous KeyRaider was designed to target Apple devices that were jailbroken. The malware has seemingly set its sights on Asia as ground zero, but has managed to spread its roots into 18 other countries, including United States, Canada, United Kingdom, Germany, Italy, Spain, Russia, China, Japan, South Korea and Israel. Even Australia was not spared.
This cleverly-designed malicious software uses MobileSubstrate and applies itself to system processes, stealing account usernames, passwords and device globally unique identifiers (GUIDs) in a curious manner – by intercepting iTunes traffic on each of the devices.
It also steals certificates and private keys used by Apple’s push notification service, while rendering local and remote unlocking functions disabled on infected iPhone or iPad devices.
To make matters worse, Keyraider uploads this data onto a vulnerable server, thus exposing the stolen user information to everyone. This has caused a stir among Apple officials, given its strong reputation in upholding user privacy.
An Apple store heist
The breach does not stop at allowing users to download apps for free, although this appears to be the hacker’s ultimate goal. Two affected users were also able to download apps and make in-app purchases without paying.

They work by hijacking purchase requests, downloading breached accounts and/or receipts from the server (C2) and then emulating the iTunes protocol with the goal of logging in to Apple servers. This way, the virtual criminal masterminds are able to purchase apps requested by their target users, the jailbroken victims, who had already intended to get Apple products for free.
Complaints from affected users were mostly about the infected accounts having purchase histories that were unaccounted for.
A smaller, yet far from insignificant number of users, seemed to have used 4Shared cloud-based sharing platform to download files of questionable security. After analyzing a number of 4Shared reviews, there appears to be no evidence indicating that any risk of breach was mentioned as a clear and present danger.
Malware first discovered in China
Even though the aliases mischa07 and i_82 are frequently mentioned in the list of suspects, the exact point of origin of KeyRaider remains a mystery.
The exact point of origin of KeyRaider remains a mystery.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.







