Showing posts with label WeChat. Show all posts
Showing posts with label WeChat. Show all posts

Thursday, 5 November 2015

New XcodeGhost-Malware For iOS Developers Discovered


Researchers have identified a new variant of the XcodeGhost malware discovered trying to infect iOS developers so they put infected apps in the official Apple App Store. There are more than 200 companies worldwide, which infected iOS users roam.

XcodeGhost is spread via infected versions of Xcode, Apple's official tool for developing iOS applications. Because of its size, the program is 4GB in size, some developers in China choose not Xcode via Apple's website, but can be downloaded via unofficial download sites. The Xcode on these websites provide the XcodeGhost malware. The apps that developers were thus also became infected.

After the discovery of the infected apps in the App Store, Apple decided to remove and arranged so that Chinese iOS developers can program easier downloading. Although the hit iOS developers new clean apps have provided, there are still users who continue to use the affected versions. These include to the popular chat app WeChat.

It also notes that users with infected iOS apps also walk around within companies. Security firm FireEye discovered 210 enterprises which infected apps were trying to communicate to the outside. However, most companies are located in Germany and the United States.

New version

There is also a new version of XcodeGhost discovered in unofficial versions of Xcode 7. This is the Xcode iOS version 9. In this version added new features to iOS infect 9 and bypass static detection by Apple. Also, there is one app is discovered which had become infected via the new XcodeGhost malware and ended up in the Apple App Store. It is a Chinese shopping app that also was offered in the US store. Apple has the app been removed.

Thursday, 24 September 2015

Apple Will Host Xcode In China to Prevent Malware


To new malware in the App Store has Apple decided to prevent the development program Xcode to host locally in China. That Apple chief executive Phil Schiller against the Chinese website Sina.com announced. Last week showed that infected apps in the App Store had ended.

The apps were infected with the XcodeGhost malware. Several Chinese Xcode developers had downloaded from an unofficial website. Xcode is Apple's official tool for developing apps for iOS or OS X. The version that the developers had downloaded were infected with malware, which also became infected by their developed apps. These apps were then placed in the App Store, where Apple controls the malware did not notice.

Download

For Chinese developers may take a very long time to download the 3GB large Xcode. "In the US there is only 25 minutes to download, in China, it may take three times longer," said Schiller. That is also a reason that Chinese developers are trying to download software through unofficial channels. Apple recommends that developers use Xcode and other development software, only download via the official website.

To make this easier for Chinese developers has now decided to host the development programs locally, so they can be downloaded quickly. Regarding XcodeGhost malware according to Schiller, there are no indications that the infected apps user data forwarded.

Tuesday, 22 September 2015

WeChat Replaces Infected App In Apple App Store


The developers of the very popular chat app WeChat have posted a new version in the Apple App Store, after the previous one with the XcodeGhost-malware had infected. A developer of WeChat used an unofficial version of Xcode to develop the app.

This unofficial version was infected with malware, which also developed apps became infected. In the case of WeChat went alone to the 6.2.5 version for iOS. According to the developers, the malware is no data or users of money stolen.Meanwhile released version 6.2.6 which does not contain the malware, although not in the release notes listed in the release. Only in a blog post, users are pointed out. WeChat has 600 million active users, of which at least 70 million outside China. This is the total number of users. In addition to the iOS app WeChat is also available for Android, Windows and other platforms.

Monday, 21 September 2015

Apple Removes Infected Apps From App Store


Apple has malware-infected apps from the App Store removed after investigators here last week warned. The apps were created with an infected version of Xcode, Apple's official tool for developing apps for iOS or OS X.

Several Chinese developers had downloaded an infected version of the development software through unofficial download sites, which then also developed apps became infected. The malware in apps called XcodeGhost is able to send information about the device and apps and can try different ways to steal passwords. Thus the malware on the device can display a warning dialog box where users enter their login details and the contents of the clipboard can be read and modified.

The infected apps were both in the Chinese App Store and the App Stores offered in other countries. "We have the apps from the App Store away that we know that are made ​​with counterfeit software," a spokeswoman told news agency Reuters. "We are working together with the developers to ensure that they use the correct version of Xcode to make their apps again." What iPhone and iPad users can do to see if their device is infected Apple has not said. Also, Apple does not report how many apps it has been removed, but the Chinese security company Qihoo argues that the total of 344 with XcodeGhost infected apps found.

Sunday, 20 September 2015

Dozens Of Malware Infected Apps In App Store Discovered


Researchers in the official Apple App Store dozens of malware infected apps discovered, reports security company Palo Alto Networks. The malware sends information about the device and the infected app to the attacker and can receive remote commands from the attacker.

Through these assignments, the malware can show an alert box that attempts to steal login information. Also, certain URLs can be hijacked and it is possible to read data in the clipboard of the user and adapt. In this way, pirated for example, passwords can be stolen. The malware XcodeGhost mentioned. Xcode is Apple's official tool for developing apps for iOS or OS X.

At various Chinese websites and forums were posted links to an infected version of Xcode. These infected version was downloaded again by Chinese developers and used to develop their apps. However, the infected Xcode version added to the malware apps, which were then placed by the developers in the App Store. According to analyst Claud Xiao some developers choose to make because of the slow internet in China nearly 3GB large Xcode not be downloaded directly from Apple, but through unofficial download sites.

At first it seemed to be two infected apps that were offered only in the Chinese version of the App Store. Now Palo Alto Networks announced that it has detected 39 infected apps, including apps for banking, stock trading, instant messaging and games. These include to WeChat, developed by the Chinese Internet giant Tencent, Didi Chuxing, a kind of Uber-like app and China Railyway 123 036, the only official app in China for purchasing train tickets.

Some of the apps developed by Chinese developers are also available on the App Store from other countries, such CamCard and WeChat. The infected apps have been downloaded by millions of people. The Dutch company Fox-IT checked the domain names used by the attackers and discovered much more infected apps, including Winzip and PdfReader. In total hit Fox-IT more than 50 infected apps on.

Thursday, 18 June 2015

Researchers Have Malware In Apple App Stores




Researchers at Indiana University have succeeded in malware for Mac OS X and iOS to get into the App Store from Apple that allows access to sensitive data from other apps can be obtained. Examples include passwords to iCloud, your default e-mail program and Internet banking and the secret token for the note program Evernote.

It also showed that the design of the app sandbox on Mac OS X was vulnerable, so the malware could approach the private directory apps. The malware could thus have access to notes, and contacts that were stored in Evernote, as well as photos of WeChat. The researchers published their work in late May in a report ( PDF ) called "Unauthorized Cross-App Resource Access on Mac OS X and iOS." To prevent apps access to each other's information systems get fit "app isolation" to which each app is in its own sandbox.

It appears that in some cases for apps still be possible to access the "resources" of other apps, which the researchers call "unauthorized cross-app resource access" (XARA). It was known that this problem played in Android, but the researchers wanted to know whether Mac OS X and iOS are vulnerable. Two platforms, which are believed to be safer than Android, so the researchers in the report know. They discovered that the problem also affects the Apple operating system. Thus, the mechanism can be hijacked that controls access to the Keychain, so it is then possible to gain access to passwords and other credentials of apps and websites that are stored here.

Impact

"The consequences of these attacks are serious, including the leak of passwords, secret tokens and all kinds of sensitive documents. Our research shows that the problem is caused by a lack of authentication at app-to-app and app-to-system interactions "the researchers said in their conclusion. They developed a scanner to analyze binaries for OS X and iOS apps to determine if the proper protection measure is contained in their code or not.

More than 88.6% of the 1612 popular Mac apps and 200 iOS apps were completely vulnerable to a XARA attack, which could steal a malicious app security information. Apple would be informed by the researchers in October 2014 and then asked to wait with the publication of the report, but the investigators would have since heard nothing more, reports The Register . The problem in Mac OS X 10.10.3 and 10.10.4 still present.