Apple’s App Store Targeted by Chinese Hackers

Apple’s App Store Targeted by Chinese Hackers

LOS ANGELES — Apple’s longstanding reputation for flawless security is in jeopardy, following reports of dozens of malware-infected apps being distributed through its proprietary App Store.

It is a first for the distribution outlet that prides itself on its scrutiny and security of the products it carries — and an attack potentially impacting many millions of users.

The malware was payloaded onto some of the store’s most popular Chinese apps for iPad and iPhone users, including mobile chat app WeChat, which boasts a half-billion users; the Uber-inspired Didi Kuaidi; and a Spotify-style music app from NetEase.

It appears that rather than a direct attack on Apple, the malware authors took an innovative approach, by spreading a tainted version of Apple’s Xcode toolset, which then secretly installed the malware on any app it was used to create. The tainted Xcode file was labeled XcodeGhost by security researchers, and provides a stern example on the dangers of using pirated software — while exposing information about the app user’s device, passwords and more to the criminal attackers.

According to Palo Alto Networks security researcher Claud Xiao, the hack allows attackers to take control of iOS devices.

“We believe XcodeGhost is a very harmful and dangerous malware that has bypassed Apple’s code review and made unprecedented attacks on the iOS ecosystem,” Xiao stated.

For its part, Apple says the company is addressing the problem.

“To protect our customers, we’ve removed the apps from the App Store that we know have been created with this counterfeit software,” an Apple rep stated. “We are working with the developers to make sure they’re using the proper version of Xcode to rebuild their apps.”

So far, no sensitive customer data release has been reported.

“At present, we haven’t discovered any loss of user information or assets as a result of this, though the WeChat team will continue to monitor and do tests,” a WeChat parent Tencent rep revealed, noting that an updated version of the WeChat app is available from the app store.

Altogether, it is an embarrassing breach of Apple’s closed app distribution channel, which has long kept legitimate adult entertainment apps from its ecosystem due to corporate censorship of carnal content.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Nineties Japanese Performer Sues to Remove Titles from Streaming Site

Former Japanese performer Miyuki Ariga is suing the Fanza adult streaming site at the Tokyo District Court to remove four titles she appeared on in 1994.

Free Speech Coalition Asks Court to Block Montana AV Law

The Free Speech Coalition (FSC) has asked the US District Court of Montana to block the state's new age verification law.

Segpay Launches Virtual 'Segcard' Creator Payout Solution

Segpay has updated its Segcard creator payout option by offering a new, virtual version.

Leading Conservative Think Tank Slams 5th Circuit for Upholding Texas Age Verification Law

Leading conservative think tank the American Enterprise Institute has published an opinion piece penned by one of its senior fellows criticizing the 5th Circuit endorsement of Texas’ controversial age verification law.

OpenAI Shuts Down AI-Generated Porn Rumors

A spokesperson for OpenAI, the company behind ChatGPT, has shut down online chatter about how a rumored relaxation of the company’s stance against AI-generated NSFW content may result in a lifting of its porn ban.

Former Trump Staffer, Project 2025 Advisor John McEntee Predicts a Total Porn Ban

John McEntee, senior advisor to the Heritage Foundation’s Project 2025 and a former key figure in the Trump administration, is predicting an eventual full ban on pornography, claiming that once it is enacted, “this country will flourish.”

Vendo Launches 'Pay by Bank' Service

Vendo has launched its new Pay by Bank checkout system.

CrakRevenue Taps Maxime Bergeron as New CEO

CrakRevenue has appointed longtime staffer Maxime Bergeron as the company's new CEO.

Clips4Sale Adds 'Spatial Video' Category

Clips4Sale (C4S) has debuted a “spatial video” category for the next generation of VR and AR devices.

Lemon Social Launches Educational Program, 'Metaverse' Feature

Premium fan platform Lemon Social has debuted an "Adult Content University" program and a "Lemon Social Metaverse" feature.

Show More