::Trend Micro Threat Resource Center::
Showing posts with label WireLurker. Show all posts
Showing posts with label WireLurker. Show all posts
17 November 2014
Suspected WireLurker malware creators arrested in China
Beijing police have arrested three people suspected of developing the “WireLurker” malware that may have infected as many as hundreds of thousands of Apple users.
Local authorities arrested the three suspects on a tip from Chinese security company Qihoo 360 Technology, the Beijing police’s Internet security team said Friday.
The three suspects, surnamed Chen, Li and Wang, were detained Thursday and charged with creating and spreading the malware, the police said in a post on its official Sina Weibo account. The police did not publish the full names of the suspects. It's ironic that China, believed to be one of the largest state sponsors of organized cyberattacks against the Western world, moved so quickly to arrest the creators of WireLurker
The malware appeared to victimize Chinese users only, and didn't have a widespread presence outside of the country. The suspects had conspired to create WireLurker as a way to gain illegal profits, and used a Chinese third-party application store called Maiyadi to spread the malware, the police added. The Maiyadi site has also been shut down.
WireLurker made headlines last week, after researchers at Palo Alto Networks discovered the malware and found that it could collect call logs, phone book contacts, and other personal information from Apple mobile devices.
Qihoo 360 Technology traced the malware back to Maiyadi, a Chinese site devoted to Apple news that also offers downloads of iOS apps and Mac software.
The malware spreads when users download an infected Mac application to their desktops or laptops. It then will go on and try to infect iOS devices once they’ve connected to the Mac via a USB cable.
About 467 Mac desktop applications infected with the malware were discovered at Maiyadi. WireLurker had yet to progress beyond collecting users’ data, Palo Alto Networks said last week.
Apple was quick to act, and said it had blocked the infected apps from launching on users’ systems. Apple did not specify how it stopped the apps from launching.
10 November 2014
How To Find And Remove WireLurker Malware From iPhone, iPad
The WireLurker Malware is the malware which is badly affecting iPhone and iPad. This malware has hit many iOS and OS X devices in China already.Therefore, most of the users across the globe are little worried about the security of their device.
Known to exist as a threat in China for now, but if you think you’re infected by WireLurker, then here’s how you can remove it before it does any damage.
If you’re jailbroken and believe that you’re affected by WireLurker, then follow the steps which are outlined below. But be warned, the steps might be a little complicated for some users, and if you feel that you don’t want to go through the tedious process, then simply do a clean restore of your iPhone, iPad or iPod touch using iTunes on the latest currently available public iOS release.
For Jailbroken Users
Step 1: Make sure you have iFile installed from Cydia, or the capability to SSH into your iOS device to access system directories.
Step 2: Navigate to /Library > /MobileSubstrate > /DynamicLibraries.
Step 3: Here, look for a file named sfbase.dylib, and if found, you know your device is infected.
However, if no such file exists, breathe a sigh of relief.
Normally one would perceive deleting this file as a removal of the threat that WireLurker is, but it is recommended that you do a complete restore of your iOS device from iTunes.
For Non-Jailbroken Users
Although there’s no way you can be infected by WireLurker at this point, considering Apple has placed in appropriate security measures, but, there’s a possibility that you conceived the malware a while back before the Cupertino giant took action. And if you believe that you’re infected, and don’t happen to be jailbroken, then read on.
Step 1: Open the Settings app and go to General > Profile.
Step 2: Check for any anomalous profile listed here, and if you find one delete it.
Step 3: Check all installed apps for strange behavior, and delete all strange or suspicious ones that you find installed.
Again, it is highly recommended that you do a complete restore of your iOS device from iTunes till a more effective and sure fire solution comes up.
If you found this guide helpful, then do share it with your friends too, in order to make them safe and secure too.
Known to exist as a threat in China for now, but if you think you’re infected by WireLurker, then here’s how you can remove it before it does any damage.
If you’re jailbroken and believe that you’re affected by WireLurker, then follow the steps which are outlined below. But be warned, the steps might be a little complicated for some users, and if you feel that you don’t want to go through the tedious process, then simply do a clean restore of your iPhone, iPad or iPod touch using iTunes on the latest currently available public iOS release.
For Jailbroken Users
Step 1: Make sure you have iFile installed from Cydia, or the capability to SSH into your iOS device to access system directories.
Step 2: Navigate to /Library > /MobileSubstrate > /DynamicLibraries.
Step 3: Here, look for a file named sfbase.dylib, and if found, you know your device is infected.
However, if no such file exists, breathe a sigh of relief.
Normally one would perceive deleting this file as a removal of the threat that WireLurker is, but it is recommended that you do a complete restore of your iOS device from iTunes.
For Non-Jailbroken Users
Although there’s no way you can be infected by WireLurker at this point, considering Apple has placed in appropriate security measures, but, there’s a possibility that you conceived the malware a while back before the Cupertino giant took action. And if you believe that you’re infected, and don’t happen to be jailbroken, then read on.
Step 1: Open the Settings app and go to General > Profile.
Step 2: Check for any anomalous profile listed here, and if you find one delete it.
Step 3: Check all installed apps for strange behavior, and delete all strange or suspicious ones that you find installed.
Again, it is highly recommended that you do a complete restore of your iOS device from iTunes till a more effective and sure fire solution comes up.
If you found this guide helpful, then do share it with your friends too, in order to make them safe and secure too.
09 November 2014
The iPhone WireLurker malware - what you need to know
There’s a scary new piece of malware that collects call logs, phonebook contacts and other sensitive information from Apple iPhones and iPads. Should you be worried?
The malware was first discovered by researchers at Palo Alto Networks who dubbed it WireLurker and said it exhibited behavior that had never been seen before in malicious software targeting Apple’s platforms.
It works by infecting software downloaded from the Web into a desktop or laptop computer. Once installed, the malware waits for an iPhone or iPad to be connected via USB, then it scans the mobile device to see what software it contains. If a target app is installed, it copies the app from the mobile device to the desktop or laptop PC, infects the app and then copies it back.
Once infected, the malware appears to collect data from the user but, to date, no other malicious activity has been discovered, said Palo Alto Networks.
For hundreds of millions of Apple iOS users, malware is a scary prospect. The platform has seen so few attacks that many users don’t run antivirus software.
If you’re one of them, you probably don’t have much to worry about from WireLurker.
The primary route of initial infection has been through several hundreds apps offered through a third-party Chinese software site called Maiyadi, so if you’ve kept away from that you’re almost certainly safe.
Secondly, the malware primarily targets iPhones that have been “jailbroken”—that is had some of their security removed so certain apps can be run on them. There is a version that targets conventional iPhones and carries an Apple digital security certificate, but researchers say even that version requires that users approve it before it runs.
And finally, it targets popular Chinese apps like Taobao, Alipay or Meitu, so if you’re not running those, you have another layer of protection.
Palo Alto Networks estimates several hundred thousand iPhone and iPad users have nonetheless been infected.
For the rest, Apple has blocked affected apps so that should halt infection this time.
The limited nature of the security problem might turn out to be a blessing in disguise. Engineers at computer security companies and Apple will be able to analyze the way WireLurker works and prevent similar malware from spreading the same way in the future.
07 November 2014
Chinese iOS devices fall prey to invasive WireLurker malware
Researchers at Palo Alto Networks said they’ve discovered an impressive malware attack against Apple devices, which for now appears to be limited to users of a Chinese application store.
The campaign revolves around infecting Mac OS X applications with “WireLurker,” which collects call logs, phone book contacts and other sensitive information on Apple mobile devices.
Some 467 Mac OS X applications offered on a Chinese third-party application store called Maiyadi were found to have been seeded with WireLurker, including “The Sims 3,” “International Snooker 2012” and “Pro Evolution Soccer 2014,” according to Palo Alto’s research paper.
Over the last six months, those applications and others have been downloaded 356,104 times ”and may have impacted hundreds of thousands of users,” the paper said.
Apple advises that users stick to downloading applications from its App Store, which it closely vets, and stay away from third-party stores for security reasons.
It would appear some people turn to the Maiyadi store because it offers applications for free, said Ryan Olson, intelligence director for Palo Alto Network’s Unit 42, the company’s threat intelligence branch.
Palo Alto analyzed three versions of WireLurker, each of which were improvements on the previous one, Olson said in a phone interview Wednesday. But it doesn’t appear the WireLurker attack progressed beyond collecting data from mobile devices.
“We think we sort of caught someone developing the attack, and they haven’t gotten to the point of launching the full attack,” Olson said. “From our perspective, it still looks like an information gathering operation.”
The WireLurker attack is notable for how it leverages desktop Mac applications as part of the attack on iOS. If someone downloaded a Mac OS X desktop application from Maiyadi, WireLurker came along with it.
WireLurker then waits for when an iOS device is connected by a USB cable. A second version of WireLurker checks if the Apple device was “jailbroken,” the term for removing restrictions that Apple uses to prevent users from running applications it has not approved.
Then it would look to see if applications such as Taobao, Alipay or Meitu, a photo editing application, were installed, Olson said. If so, it would copy the application to the desktop Mac, infect it with WireLurker and copy it back to the device.
The third iteration of WireLurker targets iOS devices that are not jailbroken as well. In that version, WireLurker used a digital certificate that Apple issues to enterprise developers so they can run their own applications in-house that do not appear on the App Store.
Using the digital certificate means iOS would allow a third-party application to be installed, although it would display a warning to users, Olson said. If a user approves the installation, WireLurker could be installed along with a legitimate application.
Olson said Palo Alto Networks has been in contact with Apple in the last few days, which is now aware of WireLurker.
“There’s no vulnerability here for them to patch, but they certainly want to be aware of malware and how it works,” Olson said.
Apple could first revoke the enterprise digital certificate that WireLurker’s creators are using, Olson said. The company could also issue an update to detect WireLurker in XProtect, Apple’s antivirus engine, he said.
Subscribe to:
Posts (Atom)