A new malware targeting jailbroken Apple iOS devices has emerged. The malware targets user credentials, and was first discovered by Reddit users.
The Reddit Jailbreak community discovered the malware and dubbed it “Unflod Baby Panda.” The malware was found on some jailbroken Apple iOS devices last Thursday, when some users noticed unusual activity that was causing apps like Snapchat and Google Hangouts to crash.
Shortly after, a developer discovered a mysterious file named “Unfold.dylib” on his jailbroken device and found that it was collecting Apple IDs and passwords from all connections on the infected device that use Secure Socket Layer (SSL) to encrypt communications. According to researchers at German security firm SektionEins, the malware is believed to be spreading via Chinese iOS software websites.
The researchers found that the login details collected by the malware were sent to a server with IP “23.88.10.4” that appears to be run by Chinese people. Further investigation revealed that the malware is digitally signed by Wang Xin, as reported by THN.
“Currently, the Reddit Jailbreak community believes that deleting the Unfold.dylib and changing the Apple ID password is enough to stop this attack. However, it is still unknown how the malware got onto infected devices and therefore it is unknown whether it has any other payload (for hackers) besides this,” the researchers write.
“We therefore believe that the only safe way to remove it is a full restore of the device, which means you will lose your jailbreak.”
Affected devices
Owners of the iPhone 5 and any other 32-bit jailbroken iOS devices may be affected by the malware. Owners of these devices should change their Apple ID password immediately after removing the malware using the steps listed below.
Owners of the latest iPhones with 64-bit processors, such as the iPhone 5S, iPad Air, and iPad Mini Retina, are not at risk from the malware.
How to remove Malware
- Download the free iFile app from Cydia.
- Go to /Library/MobileSubstrate/DynamicLibraries/
- If you find files named Unflod.dylib or Unflod.plist or framework.dylib and framework.plist then you are infected.
- Use iFile to delete Unflod.dylib or Unflod.plist or framework.dylib and framework.plist
- Restart your device and then change your Apple ID password and security questions.

