HomeSecurityYiSpecter|Jailbreak is no longer a prerequisite for malware attacks

YiSpecter|Jailbreak is no longer a prerequisite for malware attacks

YiSpecter: The first iOS malware capable of attacking jail-broken and non-jailbroken Apple devices has been detected.

YiSpecter|Jailbreak is no longer a prerequisite for malware attacks

This malware was detected in China and Taiwan, and hijacks the traffic of ISPs in these countries. This has resulted in a large 'wave' of reports to Apple Inc. in recent weeks, while YiSpecter's activity has been discussed in many online forums in recent months, during which, out of 57 leading global cyber security systems, only one managed to detect this malware.

The malware consists of four interdependent parts. By accepting enterprise certificates, these parts abuse private APIs and download files from a command and control (C2) server. Three of them use sophisticated tricks to hide their icons from the SpringBoard, which prevents them from being detected and of course removed.

YiSpecter can download, install, and launch arbitrary iOS apps, replace existing apps with those it downloads, hijack the execution of other apps to display advertisements, change Safari's default search engine, bookmarks, and open pages, and upload information about the infected iOS device to the C2 server.

This malware has the ability to determine:
• Whether an iPhone is jailbroken or not, the malware will install itself on the device successfully in either case.
• If you delete the malware manually, it will reappear.

YiSpecter|Jailbreak is no longer a prerequisite for malware attacks

YiSpecter began spreading in November 2014. The main iOS applications of this malware have a user interface and functionality that allow watching free porn videos online, and are advertised as a “private version” or “version 5.0” of a famous media player, “QVOD.” QVOD was developed by Kuaibo and became particularly popular in China among pornographic traffickers.

So far, we know of two apps that distribute this malware:

  • HYQvod (bundle id: weiying.Wvod)
  • DaPian (bundle id: weiying.DaPian)

Both were spread in the ways mentioned above. They include the functionality of watching videos online by consuming credits, while users can earn credits by installing recommended iOS apps. But more importantly, they will download and install another malicious app, commonly known as NoIcon.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS