A new malware campaign is targeting iOS devices affiliated with a wide range of entities, including European Defense Organizations, governments, and media outlets, with dangerous spyware capable of compromising non-jailbroken devices, a recent report has revealed.
The campaign of the spyware, which was characterized as «Operation Pawn Storm» by security experts, was first detected on Windows computers at the end of last year, but now it is also circulating on Apple devices, as security researchers at TrendLabs report. The researchers linked the attack to the Russian government.
One of the two spywares used is actually an application, the XAgent app, that attempts to install and run on iOS.
Subsequently, the fake website distributes the spyware via Apple ad hoc, a feature intended for businesses and developers who wish to distribute their applications to a small group of people, and allows users to bypass the company's App Store.
Once installed, XAgent will collect text messages, contact lists, images, data, information from a list of installed applications on the device, as well as the device's WiFi information. This information is then sent back to a server used by the hackers. XAgent can also open the phone's microphone and record conversations.
The XAgent malware runs on both iOS 7 and 8 devices, regardless of whether they are jailbroken or not. The app is more dangerous on iOS 7, as it hides its icon to avoid detection, but it is unable to do the same or launch automatically on iOS 8.

