Showing posts with label Xcode Ghost. Show all posts
Showing posts with label Xcode Ghost. Show all posts

Wednesday, 28 October 2015

Malwarebytes: No Malware Explosion On The Mac



Recently came out with a US security investigation that this year an explosion of Mac malware has occurred, but according to anti-malware company Malwarebytes this is not true. The amount of new malware for Apple's operating system would because for years the valleys.

Bit9 + Carbon Black, such as the US company called, suggested that this year almost 1000 new malware specimens was observed for the Mac. Five times as many as in 2010, 2011, 2012, 2013 and 2014 combined. Details were lacking in the investigation of the company. Malwarebytes late now know that last year only six new families of malware for the Mac have appeared. This year, the count is three new threats.

It involved an infected version of Xcode, Apple's development software where mostly Chinese app developers were victims. There was Ocean Lotus, a threat that infected a few users in China. Finally there was another nameless specimen discovered that users of MacKeeper attacked.

Adware

Why do Mac users with a surge of potentially unwanted software (PUPs) had to face, such as adware. "Adware for Mac multiplies like the proverbial rabbits," said analyst Thomas Reed. According to him making many Mac users with adware.While adware steal any information or money, it can cause problems. Thus users find it annoying and can cause performance problems and crashes.

Yet there is also possible, according to Reed a positive side because Mac users aware of online threats, which is an immediate serious danger. "This can ensure safe behavior, something that users were often told it was not necessary, as" Macs do not get viruses. "And that behavior can make a difference if there appear really something evil in the future."

Sunday, 27 September 2015

Apple Will Protect Mac Computers From malware XcodeGhost


 In addition, also put a new variant of the Genieo-adware on the black list, let developer of Mac software Intego know.

XcodeGhost came a few days regularly in the news. Chinese developers had downloaded an infected websites through unofficial version of Xcode for OS X, Apple's tool for developing apps. The infected Xcode ensured that the developed apps became infected. Apple yesterday published a list of the 25 most downloaded apps infected. Besides XcodeGhost is now also detected a new version of the Genieo-adware. This adware creates problems for years to Mac users, according to the questions and comments on the official Apple forum.

Friday, 25 September 2015

Apple Publishes List Of Top 25 Infected Apps


Apple has as indicated previously published the list of the 25 infected apps were downloaded the most. The apps infected with malware XcodeGhost, which can send information about the device and apps. According to Apple the malware is not in a position to steal personal information.

We deliberately for a Top 25 chosen because in addition to these 25 applications, the number of affected users is very small. Users who have downloaded an infected app are advised to update the app, which addresses the issue. If the app is no longer available in the App Store, the update will appear soon. In the Top 25 apps are of WeChat, DiDi Taxi, Railroad 12 306, China Unicom, Baidu music, Himalay FM and various games. The apps have been downloaded by millions of people, mainly in China. Furthermore, Apple users will also be separate warn.

Thursday, 24 September 2015

Apple Will Host Xcode In China to Prevent Malware


To new malware in the App Store has Apple decided to prevent the development program Xcode to host locally in China. That Apple chief executive Phil Schiller against the Chinese website Sina.com announced. Last week showed that infected apps in the App Store had ended.

The apps were infected with the XcodeGhost malware. Several Chinese Xcode developers had downloaded from an unofficial website. Xcode is Apple's official tool for developing apps for iOS or OS X. The version that the developers had downloaded were infected with malware, which also became infected by their developed apps. These apps were then placed in the App Store, where Apple controls the malware did not notice.

Download

For Chinese developers may take a very long time to download the 3GB large Xcode. "In the US there is only 25 minutes to download, in China, it may take three times longer," said Schiller. That is also a reason that Chinese developers are trying to download software through unofficial channels. Apple recommends that developers use Xcode and other development software, only download via the official website.

To make this easier for Chinese developers has now decided to host the development programs locally, so they can be downloaded quickly. Regarding XcodeGhost malware according to Schiller, there are no indications that the infected apps user data forwarded.

Wednesday, 23 September 2015

Researchers: Thousands Infected Apps In App Store


In the Apple App Store have been infected thousands of apps and a number of infected apps is still offered, say researchers from the Chinese Pangu Team. They have an app developed to iOS users can check whether they have downloaded an infected app.

The infected apps with the XcodeGhost-malware become infected. The name refers to Xcode, Apple's official tool for developing apps for iOS or OS X. Several Chinese developers had an infected version of Xcode which also downloaded the apps they developed became infected. Last Friday, September 18th, Apple began with the removal of the infected apps. On Sunday, let Apple know that all known infected apps was removed.

Monday, however, showed that there are still familiar with XcodeGhost infected apps were in the App Store, says security company Palo Alto Networks. How many apps now have become infected is unclear. Palo Alto first suggested that they were 39. China's Qihoo 360 did a survey of 344 apps, while Pangu Team says the 3418 infected apps have been identified. The researchers say that the actual number is much higher. In addition, not all infected apps from the App Store removed.

In previous posts Palo Alto Networks said that the malware was able to carry out phishing attacks on users by showing warning windows where people than their passwords might fill. This appears to be wrong afterwards. Today's malware is there not capable, but can be easily modified to do this.

Advice

In addition to turning the Pangu Team app and remove any found infected apps, users can also have two-factor authentication as an additional layer of security set, so advises Palo Alto Networks. Furthermore, app developers are advised to download development tools only through the official provider. Xcode should therefore only through the Apple website to download and no other location. Also need developers during development Gatekeeper protect their OS X machine set at the default level. Finally app developers are advised to check the integrity of their development tools and libraries before they release a new version of the app.

Tuesday, 22 September 2015

WeChat Replaces Infected App In Apple App Store


The developers of the very popular chat app WeChat have posted a new version in the Apple App Store, after the previous one with the XcodeGhost-malware had infected. A developer of WeChat used an unofficial version of Xcode to develop the app.

This unofficial version was infected with malware, which also developed apps became infected. In the case of WeChat went alone to the 6.2.5 version for iOS. According to the developers, the malware is no data or users of money stolen.Meanwhile released version 6.2.6 which does not contain the malware, although not in the release notes listed in the release. Only in a blog post, users are pointed out. WeChat has 600 million active users, of which at least 70 million outside China. This is the total number of users. In addition to the iOS app WeChat is also available for Android, Windows and other platforms.

Monday, 21 September 2015

Apple Removes Infected Apps From App Store


Apple has malware-infected apps from the App Store removed after investigators here last week warned. The apps were created with an infected version of Xcode, Apple's official tool for developing apps for iOS or OS X.

Several Chinese developers had downloaded an infected version of the development software through unofficial download sites, which then also developed apps became infected. The malware in apps called XcodeGhost is able to send information about the device and apps and can try different ways to steal passwords. Thus the malware on the device can display a warning dialog box where users enter their login details and the contents of the clipboard can be read and modified.

The infected apps were both in the Chinese App Store and the App Stores offered in other countries. "We have the apps from the App Store away that we know that are made ​​with counterfeit software," a spokeswoman told news agency Reuters. "We are working together with the developers to ensure that they use the correct version of Xcode to make their apps again." What iPhone and iPad users can do to see if their device is infected Apple has not said. Also, Apple does not report how many apps it has been removed, but the Chinese security company Qihoo argues that the total of 344 with XcodeGhost infected apps found.

Sunday, 20 September 2015

Dozens Of Malware Infected Apps In App Store Discovered


Researchers in the official Apple App Store dozens of malware infected apps discovered, reports security company Palo Alto Networks. The malware sends information about the device and the infected app to the attacker and can receive remote commands from the attacker.

Through these assignments, the malware can show an alert box that attempts to steal login information. Also, certain URLs can be hijacked and it is possible to read data in the clipboard of the user and adapt. In this way, pirated for example, passwords can be stolen. The malware XcodeGhost mentioned. Xcode is Apple's official tool for developing apps for iOS or OS X.

At various Chinese websites and forums were posted links to an infected version of Xcode. These infected version was downloaded again by Chinese developers and used to develop their apps. However, the infected Xcode version added to the malware apps, which were then placed by the developers in the App Store. According to analyst Claud Xiao some developers choose to make because of the slow internet in China nearly 3GB large Xcode not be downloaded directly from Apple, but through unofficial download sites.

At first it seemed to be two infected apps that were offered only in the Chinese version of the App Store. Now Palo Alto Networks announced that it has detected 39 infected apps, including apps for banking, stock trading, instant messaging and games. These include to WeChat, developed by the Chinese Internet giant Tencent, Didi Chuxing, a kind of Uber-like app and China Railyway 123 036, the only official app in China for purchasing train tickets.

Some of the apps developed by Chinese developers are also available on the App Store from other countries, such CamCard and WeChat. The infected apps have been downloaded by millions of people. The Dutch company Fox-IT checked the domain names used by the attackers and discovered much more infected apps, including Winzip and PdfReader. In total hit Fox-IT more than 50 infected apps on.