A new version of XcodeGhost has appeared and is trying to defeat the built-in defenses in iOS 9
Dozens of US businesses are still using Apple mobile apps that contain malware from a clever hacking system known as XcodeGhost.
Computer security firm FireEye said Tuesday it has identified 210 businesses still using infected apps, showing that the XcodeGhost malware “is a persistent security threat,” according to a blog post.
Last month, more than 4,000 applications were found to have been modified with a fake version of Xcode, which is an app development tool from Apple.
The malicious version, dubbed XcodeGhost, adds hidden code to apps that can collect identifying information about a device or even open URLs.
It was possible that some app developers, mostly based in China, may have downloaded the wrong version of Xcode due to the difficulty of downloading it directly from Apple. file hosted the modified Xcode, but it was later removed, according to Palo Alto Networks.
XcodeGhost was concerning, as apps infected with it easily bypassed Apple's controls designed to prevent malicious apps from being offered in the Mobile App Store. This was somewhat troubling for Apple, which has maintained tight control over the store to keep quality high and security and risks low.
Apple removed the infected apps from its App Store, and some of them were subsequently replaced with non-malicious versions.
Apple's Xcode tool is used to create apps for the company's devices.
But FireEye's latest finding suggests that many users may not have updated the infected apps on their devices with clean versions.
FireEye said that remaining malicious apps inside U.S. businesses are still trying to communicate with XcodeGhost's command and control servers. The apps include older versions of Tencent's WeChat app and a music app called Music 163.
This is dangerous since the communications, which are not encrypted, could be used by hackers for attacks, the researchers write.
Since XcodeGhost was discovered, some companies have blocked network traffic and DNS leading to XcodeGhost's command and control servers.
But “until these employees update their devices and applications, they remain vulnerable to potential XcodeGhost CNC attacks, particularly when outside their corporate networks,” FireEye wrote.
The intrusion could allow a hacker to display unexpected windows requesting personal data, force the device to go to a URL, or distribute an app that is not in the Apple store
Somewhat surprisingly, FireEye found that 70 percent of Apple mobile devices are still affected and have not upgraded to iOS 9, as recommended. Users should also ensure that all their apps are up to date, which should eliminate the infected apps from their devices.
Whoever created XcodeGhost has also developed a new version targeting iOS 9 called XcodeGhost S, FireEye wrote.
This update appears to be intended to bypass Apple's defenses built into iOS 9 to secure more connections to other servers. It also uses a method to try to defeat static detection of the command and control servers it communicates with.
Apple has removed an app infected with XcodeGhost S, which loosely translates to “Free State.” It is a shopping app for travelers that was offered on Apple’s App Store in the U.S. and China, FireEye said .

