'KeyRaider' iOS malware targets jailbroken devices
More than 225,000 Apple accounts have been compromised. The credentials of more than 225,000 Apple accounts have been stolen by an advanced malware targeting iOS devices.
The malware, called Key Raider, allows attackers to download apps from the Apple App Store without paying or lock devices for ransom.
"We believe this is the largest known theft of Apple accounts by malware," Palo Alto Networks' Claud Xiao wrote in a blog post.
Palo Alto Networks notified Apple of KeyRaider on August 26 and provided the stolen account information, Xiao wrote.
Key Raider can only affect devices that are jailbroken. Jailbreaking removes all Apple protections that restrict which apps can be installed on the device. Apple advises users not to jailbreak for security reasons.
Palo Alto Networks researched Key Raider together with a Chinese amateur tech group called WeipTech. A member of that group, a student at Yangzhou University, discovered the attack, Xiou said.
Key Raider has spread by being incorporated into jailbreak tweaks, or software packages that enable some new functionality to work with iOS. The malware has been found inside tweaks posted on the Weiphone forum for jailbroken phones.
A new type of iOS malware, Key Raider, can also lock phones and demand a ransom.
It is suspected that a user, with the alias “mischa07” on Weiphone, may be responsible for spreading KeyRaider from his personal post about applications. The same username was embedded in Key Raider as an encryption and decryption key for the malware, Xiao wrote.

