November 10, 2014 By Shane Schick 2 min read

Apple may have managed to thwart the WireLurker Trojan targeting iOS devices, but an earlier version that used Windows malware suggests the attacks are more widespread than previously believed.

In a prepared statement sent to The Wall Street Journal, Apple said it has blocked iOS apps available in a Chinese app store that carried WireLurker, which waits for an iPhone or iPad to be activated and then steals data. The company suggested consumers only obtain iOS apps through “trusted sources” such as its own App Store.

This type of Trojan is aimed at non-jailbroken iOS devices and uses binary file replacement to automatically generate malicious iOS apps, according to a research paper from Palo Alto Networks, which first revealed the Trojan. USB sticks are used to spread the attacks, which is unusual for OS X and iOS security, the researchers said.

The Palo Alto Networks paper also reported that while the creators’ goal is not yet clear, the Trojan is capable of stealing a variety of information and can monitor any iOS device connected via USB to an infected OS X computer.

AppleInsider said hundreds of thousands of users may already have been affected by WireLurker after nearly 470 infected apps were downloaded more than 350,000 times via the China-based Maiyadi App Store.

Even before the attacks on Mac computers surfaced, a variant of WireLurker was using Windows malware, according to a story on ZDNet that quoted researchers from AlienVault Labs. The attackers advertise the Windows malware as pirated versions of popular iOS apps such as Flappy Bird, Minecraft and Facebook, and was hosted on Baidu, a public-cloud search engine in China.

This means that while Apple may have revoked the certificate as part of its enterprise provisioning feature to wipe out WireLurker, the Trojan could be easily revived and may use alternative channels to find its next victims.

A story on Tom’s Guide warned that the Trojan’s creators could easily set up a new command-and-control server or use an alternative certificate.

Besides encouraging users to avoid third-party iOS app stores and to be careful about connecting devices to untrusted Mac computers, a free online tool is available on GitHub to detect WireLurker and hopefully contain the worst of the damage.

More from

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today