Hackers Bypass Apple's Checks to Deliver Malicious Keyboards Used to Spy on Users: Report

Here's how to identify if your iPhone has been infected with a keyboard designed to spy on you and your online activity — and how to get rid of it.

Advertisement
Written by David Delima | Updated: 8 December 2023 19:00 IST
Highlights
  • Hackers have found a way to bypass Apple's stringent checks for spyware
  • The keyboard spyware is distributed via Apple's TestFlight platform
  • iPhone users must beware of unidentified keyboard apps on their phone

Users can check their smartphone for keyboard-based stalkerware via the Settings app

Photo Credit: Unsplash/ Martin Sanchez

iPhone users could be targeted by malicious keyboards that can bypass Apple's stringent security checks to spy on user activity, according to a report. While apps that are distributed via the App Store are checked by Apple, these third-party keyboards are installed via another avenue that allows developers to test their apps on iOS. Once installed, these keyboards can be used to discreetly spy on a user and collect their sent messages, passwords, browsing history, bank credentials, and any other text entered on the phone.

Security firm Certo Software reports that third-party keyboards are being distributed by hackers as a form of 'stalkerware' — spyware apps or services used to monitor and stalk people online. While it is difficult to distribute these malicious apps via the App Store as Apple scans these apps before they are published, hackers have reportedly begun distributing these apps via TestFlight.

Apple's keyboard (left) compared with the malicious keyboard
Photo Credit: Certo Software

Advertisement

 

Apple's TestFlight service is an online platform that allows developers to invite people to test out unreleased software or run beta tests of their software, before it is published to the App Store. According to Certo Software, hackers are using the same platform to distribute malicious third-party keyboards to people, which can then be installed on an iPhone belonging to an unsuspecting partner, friend, or family member.

Advertisement

Once installed, the keyboard requires another setting to be enabled on the target's iPhone that allows third-party keyboards to collect a user's data. By default, no keyboard on iOS is allowed to access the Internet. Once this permission is enabled, the keyboard is able to transmit all keystrokes that are collected — including chat messages, passwords, notes, browsing history, OTP codes, bank credentials, and other information.

Advertisement

A screenshot of one of these keyboards shared by Certo Software illustrates how similar the malicious keyboard appears to Apple's default keyboard, making it difficult for users to identify such apps on their smartphone. Data captured from the phone can be viewed by a stalker via a web portal, according to the firm.

Information captured from a target's phone can be viewed via a web portal
Photo Credit: Certo Software

Advertisement

 

The security firm points out that Apple could implement a notification system — similar to WhatsApp's new login alert that is shown a few hours later — to notify users when a new keyboard is installed on their smartphone.

The security firm says that users can protect themselves from these kinds of software by opening the Settings app and tapping General > Keyboard > Keyboards. You should see the name of the language you type in — for example, English (UK) — and Emoji. Any third-party keyboards you have installed, like SwiftKey or Gboard will also show up here. However, if you recognise any unknown keyboards here, you can use the Edit button to quickly delete it.

Another sign that unauthorised software has been installed on your phone without your permission is if you haven't installed the TestFlight app on your phone but find it in your App Library or in the Settings app. You can also change your device passcode to ensure only you can access your phone, and seek support from online resources if you suspect you are a target of stalkerware on your devices, including your smartphone or computer.


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. UIDAI's New Aadhaar App Lets You Easily Update Mobile Number, Address
  2. Apple Watch Hypertension Notifications Are Now Available in These Countries
  3. New ALMA Images Reveal Complex Rings Left Behind by Planet Formation
  4. BSNL Launches Bharat Connect Prepaid; Slashes BSNL Superstar Premium Price
  5. The Redmi Turbo 5 Will Be Powered by This New MediaTek Chip
  6. Redmi Note 15 Pro Series Will Launch in These Colourways, Storage Options
  7. NASA Tests Nuclear Rocket Engine Designed for Faster Deep-Space Missions
  8. Nothing Phone 4a Pro's  Battery, Durability, Charging Details Revealed
  9. Samsung Galaxy S26 Series Listed on US FCC Database With This Feature
  10. Xiaomi 17 Max Tipped to Deliver This Notable Camera Improvement
  1. Redmi Note 15 Pro Series Colourways and Memory Configurations Listed on Amazon
  2. New ALMA Images Reveal Complex Rings Left Behind by Planet Formation
  3. BSNL Bharat Connect Prepaid Plan With 365-Day Validity Launched; Telco's BSNL Superstar Premium Plan Gets Price Cut
  4. Samsung Galaxy S26 Series Listed on US FCC Database With Support for Satellite Connectivity
  5. NASA Tests Nuclear Rocket Engine Designed for Faster Deep-Space Missions
  6. Hidden in Plain Sight: New Report Reveals Dozens of Nudify Apps in Major App Stores
  7. New Aadhaar App Full Version Launched in India, Introduces Easy Mobile Number Updation, and More
  8. Redmi Turbo 5 Chipset, Display and Other Key Features Confirmed Ahead of January 29 Launch
  9. GoBoult Tenet Launched in India With 13mm Dynamic Drivers, IPX5 Rating: Price, Features
  10. Highguard Hits Nearly 100,000 Concurrent Players on Steam at Launch
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.