'Unflod' malware stealing Apple ID credentials from jailbroken iOS devices

Advertisement
By Robin Sinha | Updated: 23 April 2014 17:11 IST

A new active malware, dubbed 'unflod', has been discovered by some users who say that the bug targets certain files in Apple products and steals Apple ID credentials.

The malware is understood to attack only those jailbroken Apple devices that run on 32-bit versions of iOS. This indicates that iPhone 5s, iPad Air and iPad mini 2G would stay unaffected, as they 64-bit versions of iOS. "There is no ARM 64-bit version of the code in the copy of the library we got [...]This means the malware should never be successful on [the] iPhone 5S/iPad Air or iPad mini 2G," mentioned Stefan Esser, a security researcher for Ars Technica.

Advertisement

Unflod was first mentioned in a couple of Reddit threads (1, 2), in which users complained about how their jailbroken devices have been repeatedly crashing after installing some jailbroken customisations.

However, Esser performed a static analysis on the binary codes of the infected devices mentioned by the Reddit users. As per Esser's blog, the Unflod malware clings to the jailbroken devices' SSLWrite function and runs a scan on the links that include the Apple ID and passwords. After the credentials are discovered, they are transmitted to controlled servers.

Advertisement

As a temporary solution to bypass the malware, Esser recommended users to restore their devices to factory settings. Most users however, would not want to give up their jailbreaks and subsequent tweaks in the process. He also recommended users to change their Apple IDs and passwords.

One of the Reddit users also mentioned that users can delete the Unflod.dylib file by entering the devices' SSH/Terminal, and navigating through Folder > Library > MobileSubstrate > DynamicLibraries. However, Esser says the the bug might appear again after some time, as the source of its emergence is not yet known.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Razr Fold Goes on Sale in India With These Offers
  2. Lenovo Legion Y70 (2026) With 8,000mAh Battery Arrives at This Price
  3. Google IO 2026: Here's Everything That Was Announced During the Event
  4. Redmi Turbo 6 Max Tipped to Launch With a Notably Larger Battery
  5. Here's How the Oppo Reno 16 Series Will Look
  6. WhatsApp for iOS Gets New Media Sharing Interface: Report
  7. Pritam and Pedro OTT Release Date: When and Where to Watch Rajkumar Hirani's Online?
  8. Airtel's Priority Postpaid Becomes India's First 5G Network Slicing Service
  9. Xiaomi 17 Max Reportedly Spotted on Geekbench Ahead of May 21 Launch
  1. Pritam and Pedro OTT Release Date: When and Where to Watch Rajkumar Hirani's Online?
  2. Redmi Turbo 6 Max Leak Hints at a Significant Battery Upgrade and a Larger Display: Expected Specifications
  3. Acer Aspire 5 AI Laptop With Up to Intel Core Ultra 7 CPU Launched in India: Price, Features
  4. Apple's New Chief Hardware Officer Restructures Leadership to Speed Up Product Development: Report
  5. The Super Mario Galaxy Movie Now Available for Rent on Prime Video: What You Need to Know
  6. Lenovo Legion Y900 2026 Launched With 144Hz Display, Dimensity 9500s SoC: Price, Specifications
  7. Google Brings C2PA to Gemini App, OpenAI Adds SynthID to AI Images as Industry Pushes for Transparency
  8. Google IO 2026: Gemini App for macOS Gets Spark Upgrade, Bringing Agentic Capabilities to Apple’s Mac
  9. Motorola Razr Fold Goes on Sale in India With Snapdragon 8 Gen 5 SoC, Triple 50-Megapixel Cameras: Price, Offers
  10. Xbox Launches Player Voice Feedback Portal, Fans Say Bring Back Xbox Exclusives
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.