Apple's Bad Apps are More Plentiful and Dangerous than Initially Reported

By Dominick Sorrentino September 21, 2015

All the due-diligence in the world could not stop the ironclad iOS App store from falling prey to malware. Today, it was announced that several trusted app developers were conned into using counterfeit versions of Xcodes, dubbed XcodesGhost, in application construction. The result, according to initial reports, was approximately 40 apps being infected with malware.

In more recent developments, as reported by WIRED, Apple has removed more than 300 infected apps from the App store. What’s more, the company has found that the bad apples might be more harmful to customers than previously thought.

Initial reports indicated that Palo Alto Networks managed to single out 40 applications that were infected, including banking apps, mobile carrier apps, stock trading apps, messaging services—one of which was WeChat—among others. According to WIRED, the infection was thought to be able to pilfer minute snippets of information, “such as a device’s ID, and the current time.”  

However, updates to the findings of Palo Alto—among other researchers—suggest the apps are also capable of receiving commands from the attacker, making it possible for bad actors to read and write data to a user’s clipboard, prompt fraudulent alerts on a user’s display, and open certain URLS—some of these tactics make it possible to phish data, for example, by stealing passwords. While many of the 300-plus apps were for the Chinese market, some such as ‘CamCard’ are used in the United States.     

Xcodes is an authentic software development tool from Apple that allows for the creation of iOS and Mac apps. In this case, cyber criminals were able to leverage Chinese developers’ limited access to Internet-downloaded software. Scammers created a counterfeit version of Xcodes, and made it more immediately available to legitimate app developers, who subsequently embedded their iOS applications with the malware. Apple, despite its draconian approval process, was blindsided.

Image via Shutterstock

At last report, Apple told the Guardian that the company had removed all infected apps from the App store, and was ensuring that the developers were employing the correct version of Xcodes.

The Cupertino computer makers’ App store has long been regarded as a safer environment than Android’s Google Play, but even Apple has chinks in its armor. At present, the take away seems to be a rehash of the old refrain, “you can never be too careful,” especially when it comes to cybersecurity in today’s digital landscape of threats.

More updates and expert analysis may follow




Edited by Maurice Nagle
SHARE THIS ARTICLE
Related Articles

Consumer Privacy in the Digital Era: Three Trends to Watch

By: Special Guest    1/18/2018

Digital advertising has exploded in recent years, with the latest eMarketer data forecasting $83 billion in revenue this year and continued growth on …

Read More

CES 2018: Terabit Fiber - Closer Than We Think

By: Doug Mohney    1/17/2018

One of the biggest challenges for 5G and last mile 10 Gig deployments is not raw data speeds, but middle mile and core networks. The wireless industry…

Read More

10 Benefits of Drone-Based Asset Inspections

By: Frank Segarra    1/15/2018

Although a new and emerging technology, (which is still evolving), in early 2018, most companies are not aware of the possible benefits they can achie…

Read More

VR Could Change Entertainment Forever

By: Special Guest    1/11/2018

VR could change everything from how we play video games to how we interact with our friends and family. VR has the power to change how we consume all …

Read More

Making Connections - The Value of Data Correlation

By: Special Guest    1/5/2018

The app economy is upon us, and businesses of all stripes are moving to address it. In this age of digital transformation, businesses rely on applicat…

Read More