Showing posts with label China Railway App. Show all posts
Showing posts with label China Railway App. Show all posts

Wednesday, 23 September 2015

Researchers: Thousands Infected Apps In App Store


In the Apple App Store have been infected thousands of apps and a number of infected apps is still offered, say researchers from the Chinese Pangu Team. They have an app developed to iOS users can check whether they have downloaded an infected app.

The infected apps with the XcodeGhost-malware become infected. The name refers to Xcode, Apple's official tool for developing apps for iOS or OS X. Several Chinese developers had an infected version of Xcode which also downloaded the apps they developed became infected. Last Friday, September 18th, Apple began with the removal of the infected apps. On Sunday, let Apple know that all known infected apps was removed.

Monday, however, showed that there are still familiar with XcodeGhost infected apps were in the App Store, says security company Palo Alto Networks. How many apps now have become infected is unclear. Palo Alto first suggested that they were 39. China's Qihoo 360 did a survey of 344 apps, while Pangu Team says the 3418 infected apps have been identified. The researchers say that the actual number is much higher. In addition, not all infected apps from the App Store removed.

In previous posts Palo Alto Networks said that the malware was able to carry out phishing attacks on users by showing warning windows where people than their passwords might fill. This appears to be wrong afterwards. Today's malware is there not capable, but can be easily modified to do this.

Advice

In addition to turning the Pangu Team app and remove any found infected apps, users can also have two-factor authentication as an additional layer of security set, so advises Palo Alto Networks. Furthermore, app developers are advised to download development tools only through the official provider. Xcode should therefore only through the Apple website to download and no other location. Also need developers during development Gatekeeper protect their OS X machine set at the default level. Finally app developers are advised to check the integrity of their development tools and libraries before they release a new version of the app.

Monday, 21 September 2015

Apple Removes Infected Apps From App Store


Apple has malware-infected apps from the App Store removed after investigators here last week warned. The apps were created with an infected version of Xcode, Apple's official tool for developing apps for iOS or OS X.

Several Chinese developers had downloaded an infected version of the development software through unofficial download sites, which then also developed apps became infected. The malware in apps called XcodeGhost is able to send information about the device and apps and can try different ways to steal passwords. Thus the malware on the device can display a warning dialog box where users enter their login details and the contents of the clipboard can be read and modified.

The infected apps were both in the Chinese App Store and the App Stores offered in other countries. "We have the apps from the App Store away that we know that are made ​​with counterfeit software," a spokeswoman told news agency Reuters. "We are working together with the developers to ensure that they use the correct version of Xcode to make their apps again." What iPhone and iPad users can do to see if their device is infected Apple has not said. Also, Apple does not report how many apps it has been removed, but the Chinese security company Qihoo argues that the total of 344 with XcodeGhost infected apps found.

Sunday, 20 September 2015

Dozens Of Malware Infected Apps In App Store Discovered


Researchers in the official Apple App Store dozens of malware infected apps discovered, reports security company Palo Alto Networks. The malware sends information about the device and the infected app to the attacker and can receive remote commands from the attacker.

Through these assignments, the malware can show an alert box that attempts to steal login information. Also, certain URLs can be hijacked and it is possible to read data in the clipboard of the user and adapt. In this way, pirated for example, passwords can be stolen. The malware XcodeGhost mentioned. Xcode is Apple's official tool for developing apps for iOS or OS X.

At various Chinese websites and forums were posted links to an infected version of Xcode. These infected version was downloaded again by Chinese developers and used to develop their apps. However, the infected Xcode version added to the malware apps, which were then placed by the developers in the App Store. According to analyst Claud Xiao some developers choose to make because of the slow internet in China nearly 3GB large Xcode not be downloaded directly from Apple, but through unofficial download sites.

At first it seemed to be two infected apps that were offered only in the Chinese version of the App Store. Now Palo Alto Networks announced that it has detected 39 infected apps, including apps for banking, stock trading, instant messaging and games. These include to WeChat, developed by the Chinese Internet giant Tencent, Didi Chuxing, a kind of Uber-like app and China Railyway 123 036, the only official app in China for purchasing train tickets.

Some of the apps developed by Chinese developers are also available on the App Store from other countries, such CamCard and WeChat. The infected apps have been downloaded by millions of people. The Dutch company Fox-IT checked the domain names used by the attackers and discovered much more infected apps, including Winzip and PdfReader. In total hit Fox-IT more than 50 infected apps on.