Not long after the discovery of WireLurker, the dangerous malwarethat attacks iOS devices, a new threat has emerged. FireEye, a cybersecurity firm, has identified “Masque,” a highly dangerous and destructive malware that replaces a series of third-party applications with fake applications that trick the user into downloading the infected applications, allowing hackers to steal sensitive personal data .
The Masque Attack was born from a hacker group that discovered a major security flaw in iOS 7 and iOS 8, which allows anyone who wants to carry out malicious actions to install fake applications via sending e-mails and SMS. What the hacker essentially does is give the fake application the same name as the real one and thus confuse the user. Of course, it is understood that the problem only occurs if the user downloads an infected application on their iPhone or iPad.
The Masque Attack is very dangerous, with FireEye demonstrating its capabilities in a fake app that replaced the Gmail app. In fact, once the infected app is installed, it is almost impossible for the user to uninstall it.
The only positive thing about the whole Masque Attack story is that hackers are currently unable to use the security hole to exploit the preloaded applications that come with every iOS device (such as the Safari browser).
FireEye officials are sounding the alarm about the Masque Attack, also emphasizing that they had discovered this malware long before WireLurker and had even informed Apple, which has been developing afix that will shield its operating system since July. The Masque Attack can affect devices running iOS 7.1.1, 7.1.2, as well as iOS 8.0, 8.1 and 8.1.1 beta and is not related to whether a device has been jailbroken. In any case, in these cases the only defense is to never download applications from sites you do not know.
Source: digitallife.gr

