Over 225,000 Apple Accounts Reportedly Stolen From Jailbroken iPhones

Advertisement
By Manish Singh | Updated: 1 September 2015 19:00 IST

Apple's iOS is known for its security sophistication. In the eight years of its existence, the company's mobile operating system has largely remained unaffected to any major security vulnerability. That is until you decide to do away with its built-in security features. Known as jailbreaking, the process gives users the ability to gain full control of the device, and sideload apps. As per reports, malware is being installed via third-party iOS app repositories, resulting in what may be "the largest known Apple account theft caused by malware."

An iOS malware called KeyRaider, distributed by third-party Cydia repositories in China, has stolen around 225,000 iOS users' Apple account credentials, certificates, private keys, and purchasing receipts, revealed security firm Palo Alto Networks and Chinese iPhone developers group Weiptech. The credentials were sent to a remote server, and stolen accounts were used to purchase paid apps on other iOS devices. Over 20,000 users have reportedly downloaded the jailbreak tweaks that will give them access to stolen credentials for unauthorised purchases.

"The malware hooks system processes through MobileSubstrate, and steals Apple account usernames, passwords and device GUID by intercepting iTunes traffic on the device. KeyRaider steals Apple push notification service certificates and private keys, steals and shares App Store purchasing information, and disables local and remote unlocking functionalities on iPhones and iPads," the Palo Alto Networks wrote in a blog post. The firm in conjunction with WeipTech found 92 samples of the new iOS malware family

Advertisement

About 225,000 accounts are affected, and while some users say their accounts show abnormal purchasing history, others say their phones are being held for ransom. The good news is that people who haven't jailbroken their iOS devices (iPad, iPhone, iPod) don't need to worry about this attack. About half of the victims have email accounts with qq.com, 163.com, 139.com, popular Chinese email services, suggesting that the attack largely affects Chinese accounts. Researchers found evidence of victims in 18 countries including France, Russia, Japan, United Kingdom, United States, Canada, Germany, Australia, Israel, Italy, Spain, Singapore, and South Korea.

Advertisement

This is the second major iOS attack we have heard about in the recent past. Infamous Hacking Team also reportedly attacked jailbroken iOS devices.

The report truly serves to illustrate the potential terrible consequences of jailbreaking devices to iOS users. Experts advise users not to jailbreak devices unless they're fully aware of the methods the tool uses to bypass Apple's built-in security, and the legitimacy of the apps they are installing on their devices. No Indian user has been reported to be affected by the vulnerability as of yet. Palo Alto Networks has set up a tool to assist users to check whether their device is affected, and if so, a guide to help them patch the vulnerability.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15T 5G India Launch Today: All You Need to Know
  2. Oppo Enco Buds 3 Pro Available for Purchase in India: See Price, Offers
  3. Your Gmail Password Might Have Been Leaked: How to Secure Your Account
  4. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  5. Motorola Razr 60, Buds Loop With Swarovski Crystals Debut in India
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.