'Unflod' malware stealing Apple ID credentials from jailbroken iOS devices

Advertisement
By Robin Sinha | Updated: 23 April 2014 17:11 IST

A new active malware, dubbed 'unflod', has been discovered by some users who say that the bug targets certain files in Apple products and steals Apple ID credentials.

The malware is understood to attack only those jailbroken Apple devices that run on 32-bit versions of iOS. This indicates that iPhone 5s, iPad Air and iPad mini 2G would stay unaffected, as they 64-bit versions of iOS. "There is no ARM 64-bit version of the code in the copy of the library we got [...]This means the malware should never be successful on [the] iPhone 5S/iPad Air or iPad mini 2G," mentioned Stefan Esser, a security researcher for Ars Technica.

Unflod was first mentioned in a couple of Reddit threads (1, 2), in which users complained about how their jailbroken devices have been repeatedly crashing after installing some jailbroken customisations.

Advertisement

However, Esser performed a static analysis on the binary codes of the infected devices mentioned by the Reddit users. As per Esser's blog, the Unflod malware clings to the jailbroken devices' SSLWrite function and runs a scan on the links that include the Apple ID and passwords. After the credentials are discovered, they are transmitted to controlled servers.

Advertisement

As a temporary solution to bypass the malware, Esser recommended users to restore their devices to factory settings. Most users however, would not want to give up their jailbreaks and subsequent tweaks in the process. He also recommended users to change their Apple IDs and passwords.

One of the Reddit users also mentioned that users can delete the Unflod.dylib file by entering the devices' SSH/Terminal, and navigating through Folder > Library > MobileSubstrate > DynamicLibraries. However, Esser says the the bug might appear again after some time, as the source of its emergence is not yet known.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  2. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  3. India's Indigenous Vikram Microprocessor Showcased at Semicon India 2025
  4. Realme 15T 5G India Launch Today: All You Need to Know
  5. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.