Apple's approach to the latest threats leaves businesses vulnerable to new variants of exploits using the WireLurker and Masque malware, a security firm claims.
According to a publication by Marble Security, while Apple has taken steps to block the WireLurker malware, in no way can these measures prevent future versions of the malware. Recall that the WireLurker malware used various certificates to infect systems. Also, according to Marble Security, Apple does not protect iPhone and iPad users who sync their devices to Windows PCs.
“Apple’s responses to the WireLurker and Masque attacks show that iOS is entering an era of malware defenses similar to those that PCs have been using for the past decade,” said Dave Jevans, founder and CEO of Marble Security. “A proactive, not reactive, approach is needed to prevent these iOS vulnerabilities, as they could impact enterprise networks and device security applications if exploited.”
According to Apple, the Masque attack was only a threat to users who had disabled Apple's security controls, apparently forgetting that the malware displayed a dialog box asking the user if they trusted the app's certificate. If a user clicked "Yes," then the iOS device would be infected with malicious apps.
This is not a bug, but a way that applications use to install themselves. Now that it has already been used as an attack, it is very likely to be used again and again.
"The cybercrime underground has already begun to exploit mobile devices, and will intensify their attacks targeting employees in businesses. Proactive protection against malicious applications is more necessary than ever for mobile users – even those using iOS," said Jevans.
You can download the survey from the link below (PDF)
Source: secnews.gr

