HomeinetXcodeGhost Is the CIA behind the hack at Apple?

XcodeGhost Is the CIA behind the Apple hack?

XcodeGhost: As discovered by security firm Palo Alto Networks on September 17, 2015, a modified version of Apple's Xcode integrated development environment (IDE) was used by Chinese developers to unknowingly distribute malware through a compiler called XcodeGhost.

XcodeGhost

The malicious code was sneaking into their iOS apps, without their knowledge as we mentioned above. Apple reportedly didn't say anything about the issue, and just yesterday confirmed that around 300 malware had sneaked into iOS apps and were removed from the App Store.

Apple's Christine Monaghan told the Guardian that

“We have removed apps from the App Store that we know were created with this counterfeit software. We are working with developers to ensure they are using the correct version of Xcode to redevelop their apps.”

Where does the CIA stand, though? The Intercept reported on March 10, 2015, that during a secret annual meeting where security researchers work with the Central Intelligence Agency (CIA) to share their latest discoveries, some of the researchers in attendance reported that they had created a modified version of Xcode that is capable of adding backdoors to any application the developer develops.

Additionally, iOS apps built using the malicious Xcode IDE had the ability to steal passwords from devices, and send them to a command and control center of their choosing.

As revealed in the Intercept publication:

“It remains unclear how the intelligence agencies will get developers to use the ‘tampered’ version of Xcode.”

The malware described by CIA security researchers has very similar capabilities to XcodeGhost, and the way it could infect iOS apps matches that used by XcodeGhost.

It should also be mentioned that a few days ago, as discovered by PixelsTech, an anonymous Github user published the alleged source code of XcodeGhost in a new repository, stating in the description that the malware would not steal personal information from iOS users.

He claims that XcodeGhost was designed to demonstrate the fact that Xcode allows you to modify configuration files and that it loads custom source code.

Let's mention that the only reason this story has happened is that Chinese developers were looking for a server from where they could quickly download Xcode. Let's remember that the Asian APNIC network may be very fast within Asia, but it "crashes" if someone tries to download something from Europe or America.

Thus, malicious Xcode installers distributed through Baidu's cloud file sharing service were hijacked by Chinese developers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS