products Apple were immune to malware is starting to be questioned, as reports from the security industry in recent months clearly show an increased interest from cybercriminals in devices running OS X and iOS.
“OS X and iOS users have been relatively protected from malware compared to Windows users. However, both Apple operating systems are gaining popularity among users, and thus are starting to be viable targets for cybercrime,” says Bogdan Botezatu, senior malware analyst at Bitdefender.
In recent times, it has been observed that these platforms have become more attractive for various types of attacks, not only for financial motives.
Revenue from advertising and spying
In August, an investigation revealed that a threat called AdThief had infected about 75,000 iOS devices, generating $22 million in ad revenue. The users of the devices weren't directly affected by this, but the iOS app developers were making millions.
According to the analysis, AdThief has been around since December 10, 2014, and caught the attention of security researchers in March 2014, when approximately 22,000 daily activations of the malware were observed.
In this case, the malware only worked on jailbroken devices, which do not benefit from Apple's inherent security restrictions.
In September, researchers from FireEye announced that a malware called XSLCmd had “jumped” from Windows to OS X. The goal of the malicious application was to steal data from the infected computer.
According to the evidence, it was created by a group called Gref for espionage activity, which, based on historical information, is believed to have been operating since 2009.
Another Trojan was discovered by Lacoon Mobile Security experts at the end of September. The malware, called Xsser mRAT, is designed for the iOS platform, and according to the security firm, is the work of the Chinese government.
It was found on a server that also hosted its Android counterpart, and was being served in Hong Kong to pro-democracy protesters under the guise of being an application that would help them better coordinate the demonstrations.
Like AdThief, Xsser mRAT only worked on jailbroken devices, and sent information to the command and control server about the infected phone, such as the operating system version, MAC address, IMSI and IMEI, phone number, and information from the SIM card.
Mac hacks and infections on non-jailbroken iPhones
September was unusually productive in reports of malware targeting Apple products, as Doctor Web warned of a botnet of OS X systems infected with iWorm.
According to telemetry data, connections were recorded from more than 17,000 unique IP addresses. This does not reflect the actual number of infected computers, since there are dynamic IPs, and therefore, an infected computer can connect to the command and control server with different IPs.
In October, we saw yet another report about a new threat to OS X. Kaspersky researchers called it Ventir, and it was an open-source tool developed to intercept keystrokes.
According to recent news now, in November, Palo Alto Networks discovered WireLurker, a striking malware targeting users from China. The malware hits devices running OS X and is served to iOS via a USB connection. It even attacks non-jailbroken devices.
Researchers expect more malware
It is clear that there is real interest in Apple products from criminals.
“Most of the cybercriminals are focused on making money, and Apple systems are usually unprotected, which in turn makes developing Mac and iOS malware a profitable business. We expect to see more of these threats over the next year,” said Botezatu.
Other researchers agree that malware for Apple products is a reality, and that WireLurker is the perfect example of their argument, according to Christian Funk, senior security researcher at Kaspersky.
It reports that the chances of an unprotected Mac system being infected have increased by three percent in the first eight months of 2014, as 25 different malware families for Apple's platform emerged.
Apple users are facing a harsh reality. Their devices have been targeted, and Apple's security measures are proving to be no longer 100% effective, even for non-jailbroken devices.
