'Unflod' malware stealing Apple ID credentials from jailbroken iOS devices

Advertisement
By Robin Sinha | Updated: 23 April 2014 17:11 IST

A new active malware, dubbed 'unflod', has been discovered by some users who say that the bug targets certain files in Apple products and steals Apple ID credentials.

The malware is understood to attack only those jailbroken Apple devices that run on 32-bit versions of iOS. This indicates that iPhone 5s, iPad Air and iPad mini 2G would stay unaffected, as they 64-bit versions of iOS. "There is no ARM 64-bit version of the code in the copy of the library we got [...]This means the malware should never be successful on [the] iPhone 5S/iPad Air or iPad mini 2G," mentioned Stefan Esser, a security researcher for Ars Technica.

Unflod was first mentioned in a couple of Reddit threads (1, 2), in which users complained about how their jailbroken devices have been repeatedly crashing after installing some jailbroken customisations.

Advertisement

However, Esser performed a static analysis on the binary codes of the infected devices mentioned by the Reddit users. As per Esser's blog, the Unflod malware clings to the jailbroken devices' SSLWrite function and runs a scan on the links that include the Apple ID and passwords. After the credentials are discovered, they are transmitted to controlled servers.

Advertisement

As a temporary solution to bypass the malware, Esser recommended users to restore their devices to factory settings. Most users however, would not want to give up their jailbreaks and subsequent tweaks in the process. He also recommended users to change their Apple IDs and passwords.

One of the Reddit users also mentioned that users can delete the Unflod.dylib file by entering the devices' SSH/Terminal, and navigating through Folder > Library > MobileSubstrate > DynamicLibraries. However, Esser says the the bug might appear again after some time, as the source of its emergence is not yet known.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  2. Galaxy S26 Series Benchmarks Highlight Snapdragon-Exynos Performance Gap
  3. Apple Reportedly Announces 'Special Experience' on March 4
  4. Xiaomi 17 Series Leak Hints at Imminent Launch Ahead of MWC at These Prices
  5. Poco X8 Pro Spotted on Geekbench With This Dimensity 8000 Series Chipset
  6. PS6 Could Reportedly be Delayed to 2029 Due to RAM Shortage
  7. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  8. Kingdom Come: Deliverance Gets a Next-Gen Update on PS5, Xbox Series S/X
  9. Deals on iPhone 17, Google Pixel 10 and More During Flipkart Sale
  10. iPhone 18 Series May Arrive Without a Physical SIM Slot in This Region
  1. Vivo V60 Lite 4G (2026) Launched With Snapdragon 6s Gen 2 Chip and 6,500mAh Battery
  2. Snapdragon-Powered Galaxy S26 Ultra Leads Exynos-Powered S26 in Early Benchmarks: Report
  3. Apple Reportedly Announces ‘Special Experience’ on March 4; May Launch iPhone 17e, Low-Cost MacBook
  4. Sony Could Reportedly Delay PS6 to as Late as 2029 Due to RAM Shortage
  5. iPhone 18 Series to Drop SIM Card Slot in Europe to Make Room for Slightly Larger Battery: Report
  6. Poco X8 Pro Spotted on Geekbench With MediaTek Dimensity 8500 Ultra SoC, Android 16
  7. Xiaomi 17, Xiaomi 17 Ultra Global Price Details, Launch Date and Colour Options Leaked
  8. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  9. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  10. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.