{"id":3743,"date":"2016-03-17T09:32:32","date_gmt":"2016-03-17T09:32:32","guid":{"rendered":"http:\/\/oldnumber7.com\/?p=3743"},"modified":"2016-03-17T09:32:32","modified_gmt":"2016-03-17T09:32:32","slug":"apple-app-piracy-technique-used-for-malware","status":"publish","type":"post","link":"https:\/\/oldnumber7.com\/?p=3743","title":{"rendered":"Apple App Piracy Technique Used For Malware"},"content":{"rendered":"<p><a href=\"\/images\/pirateapple.gif\" rel=\"attachment wp-att-29587\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/torrentfreak.com\/images\/pirateapple.gif\" alt=\"pirateapple\" width=\"180\" height=\"160\" class=\"alignright size-full wp-image-29587\"><\/a>Ever since the launch of Apple&#8217;s app-enabled devices, users have sought ways to run software not sourced from the official App Store. It&#8217;s been a cat-and-mouse battle, with teams of security experts trying to break Apple&#8217;s security to enable a process known as &#8216;jailbreaking&#8217;.<\/p>\n<p>A successfully jailbroken iPhone, for example, can not only run software from third party app stores such as <a href=\"https:\/\/cydia.saurik.com\/\">Cydia<\/a>, but can also run pirated iOS software. Needless to say, with this feature the popularity of jailbreaking has soared, prompting Apple to do everything it can to close security holes.<\/p>\n<p>However, in 2013 something unexpected happened. A new technique known as the \u201cFairPlay Man-In-The-Middle&#8221; (MITM) attack exploited flaws in Apple&#8217;s &#8216;Fairplay&#8217; DRM system to allow both pirated and third-party software (unapproved by Apple) to run on iOS devices. Crucially, this could all take place without a jailbreak being deployed on the device.<\/p>\n<p>Somewhat surprisingly people with the ability to carry out the third-party software exploit have been remarkably well behaved for the past three years but all good things come to an end. Rather than using the loophole for consumer-friendly activity, attackers are now using it for evil.<\/p>\n<p>According to <a href=\"http:\/\/paloaltonetworks.com\">Palo Alto Networks<\/a> researcher Claud Xiao, there now exists iOS malware that is able to deploy itself to non-jailbroken devices using the man-in-the-middle attack previously used by pirates.<\/p>\n<p>Named \u201cAceDeceiver\u201d by the researcher, the malware targets the method of transferring App Store purchases from the iTunes software installed on users&#8217; computers to their iOS devices.<\/p>\n<p>&#8220;iOS devices will request an authorization code for each app installed to prove the app was actually purchased,&#8221; Xiao explains.<\/p>\n<p>&#8220;In the FairPlay MITM attack, attackers purchase an app from App Store then intercept and save the authorization code. They then developed PC software that simulates the iTunes client behaviors, and tricks iOS devices to believe the app was purchased by victim. Therefore, the user can install apps they never actually paid for, and the creator of the software can install potentially malicious apps without the user\u2019s knowledge.&#8221;<\/p>\n<p><a href=\"http:\/\/torrentfreak.com\/images\/fairplay-mitm.png\" rel=\"attachment wp-att-119512\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/torrentfreak.com\/images\/fairplay-mitm.png\" alt=\"fairplay-mitm\" width=\"528\" height=\"294\" class=\"aligncenter size-full wp-image-119512\"><\/a><\/p>\n<p>But to do its dirty deeds AceDeceiver needs to find a way onto a user&#8217;s device in the first instance and that was achieved via Apple&#8217;s very own App Store.<\/p>\n<p>Between July 2015 and February 2016 software claiming to be wallpaper apps successfully passed Apple&#8217;s vetting systems and were made available to Apple users. The way this was achieved was extremely cunning, with the App only going into malicious mode if it was run in a certain geographical area, in this case, China.<\/p>\n<p>&#8220;The iOS apps of AceDeceiver mainly act as a third party app store if users access them from China. Note that some of the apps or games they provide in the store are also installed through a FairPlay MITM attack. In addition, these apps strongly suggest users input their Apple ID with password so that users could &#8216;directly install free apps from the App Store, execute in-app purchase, and login to Game Center&#8217;.&#8221;<\/p>\n<p>That doesn&#8217;t sound like good news and indeed, the researchers found that claims that the software did not transfer login credentials were simply untrue.<\/p>\n<p>&#8220;In fact, we discovered all versions of AceDeceiver will upload the Apple ID and password to [the attackers&#8217; server],&#8221; Xiao adds.<\/p>\n<p>All three apps were removed by Apple after the researchers reported them in February 2016 but their threat remains.<\/p>\n<p>&#8220;The attack is still viable because the FairPlay MITM attack only requires these apps to have been available in the App Store once. As long as an attacker could get a copy of authorization from Apple, the attack doesn\u2019t require current App Store availability to spread those apps,&#8221; Xiao explains.<\/p>\n<p>&#8220;While the attack requires a user\u2019s PC to be infected by malware first, after that, the infection of iOS devices is completed in the background without the user\u2019s awareness. The only indication is that the new malicious app does appear as an icon in the user\u2019s home screen, so the user may notice a new app he or she won\u2019t recall downloading.&#8221;<\/p>\n<p>The full disclosure from Claud Xiao can be found <a href=\"http:\/\/researchcenter.paloaltonetworks.com\/2016\/03\/acedeceiver-first-ios-trojan-exploiting-apple-drm-design-flaws-to-infect-any-ios-device\/\">here<\/a>, along with removal instructions for those concerned they may be infected by the malware.<\/p>\n<p>Source: <a href=\"https:\/\/torrentfreak.com\/\">TF<\/a>, for the latest info on copyright, file-sharing, <a href=\"https:\/\/torrentfreak.com\/top-10-most-popular-torrent-sites-of-2016-160102\/\">torrent sites<\/a> and  <a href=\"https:\/\/torrentfreak.com\/vpn-provider-anonymous-review-160220\/\">ANONYMOUS VPN services<\/a>.<\/p>\n<div class=\"feedflare\">\n<a href=\"http:\/\/feeds.feedburner.com\/~ff\/Torrentfreak?a=S_yd9PX-ph8:jtq4qZ1pPmo:yIl2AUoC8zA\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/Torrentfreak?d=yIl2AUoC8zA\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/Torrentfreak?a=S_yd9PX-ph8:jtq4qZ1pPmo:D7DqB2pKExk\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/Torrentfreak?i=S_yd9PX-ph8:jtq4qZ1pPmo:D7DqB2pKExk\" border=\"0\"><\/img><\/a>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/Torrentfreak\/~4\/S_yd9PX-ph8\" height=\"1\" width=\"1\" alt=\"\" \/><br \/>\nSource: TorrentFreak<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ever since the launch of Apple&#8217;s app-enabled devices, users have sought ways to run software not sourced from the official App Store. It&#8217;s been a cat-and-mouse battle, with teams of security experts trying to break Apple&#8217;s security to enable a process known as &#8216;jailbreaking&#8217;. A successfully jailbroken iPhone, for example, can not only run software &#8230; <a title=\"Apple App Piracy Technique Used For Malware\" class=\"read-more\" href=\"https:\/\/oldnumber7.com\/?p=3743\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":3744,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3743","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/oldnumber7.com\/index.php?rest_route=\/wp\/v2\/posts\/3743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oldnumber7.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/oldnumber7.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/oldnumber7.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oldnumber7.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3743"}],"version-history":[{"count":0,"href":"https:\/\/oldnumber7.com\/index.php?rest_route=\/wp\/v2\/posts\/3743\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oldnumber7.com\/index.php?rest_route=\/wp\/v2\/media\/3744"}],"wp:attachment":[{"href":"https:\/\/oldnumber7.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oldnumber7.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oldnumber7.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}