A new wave of iOS malware that attacks jailbroken iPhones, has resulted in the theft of 225,000 credentials related to iOS users' Apple IDs. The results include app purchases that are 100% fraudulent. In some cases, legitimate users cannot unlock their iPhones. These units are often held for ransom. The "KeyRaider" malware has been discovered on jailbroken iPhones throughout the world, including the U.S. the U.K.

By "Jailbreaking" an iPhone, users are able to use their iOS powered handset to do things that the device is usually not capable of doing. Unfortunately, it leaves users open to having their Apple ID and password stolen by the malware. It also allows hackers to steal each iPhone's unique identifier, security certificates, and keys that help run the iOS push notification system. Those breaking in to jailbroken iPhones can obtain data from the App Store that can allow them to install App Store apps for free.

With the credentials stolen from a victim's Apple ID, those using the malware can impersonate other iPhone users and ring up large App Store purchases. Hopefully, Apple will soon send out a software patch that will end the ability of "KeyRaider" to do so much damage.

source: AppleInsider

Post a Comment

 
Top