HomeSecurityActive malware campaign steals passwords from jailbroken iOS devices

Active malware campaign steals passwords from jailbroken iOS devices

unflod-hook-499

Security researchers have discovered an active malware campaign that steals Apple ID credentials from jailbroken iPhones and iPads.

The new malware, dubbed “unflod” after a library installed on infected devices, first appeared on Reddit late last week. Readers reported that their jailbroken iOS devices had recently started experiencing recurring errors, often after installing jailbroken tweaks that are available in abundance on Cydia and many prefer to use them to further their hacking efforts.

Since then, security researcher Stefan Esser has performed static analysis of the binary code isolated on the compromised devices. In a blog post reporting the results, he said that “unflod” installs itself in the SSLWrite function of an infected device’s security framework.

To check if you are infected, you should use iFile to go to /Library/MobileSubstrate/DynamicLibraries/. If you find a file there named Unflod.dylib, then your device is infected.

The best way to remove malware is to restore your device via iTunes, which means you automatically lose your jailbreak.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS