Thursday, November 13, 2014

'Masque Attack' iOS Malware - Can Steal Sensitive Information



It’s barely been a week since we learned about the WireLurker malware for iOS, and now we have new reports that an even more dangerous iOS malware called "Masque Attack" is in the wild.
"Masque Attack" works much like WireLurker in that it takes advantage of Apple’s enterprise provisioning to bypass other security checks on iOS. This proves that Apple’s banning of the infected WireLurker apps has been mostly ineffective, as expected, and until the company fixes this enterprise provisioning loophole, a whole new class of malware is going to invade iOS devices in the coming months or years.
Unlike WireLurker, though, Masque Attack doesn’t even need to infect the user's PC and then have the user connect to the iOS devices through USB. Instead, it can just infect iPhones or iPads when the user visits a certain infected web page online; then, it prompts the user to install a new app. Once the user clicks to install it, the device is infected.
The new app can replace any application from the user’s device, other than the pre-installed Apple applications. That includes email, banking or any other type of third-party app. If the user introduces his or her login credentials in those apps, that information will be stolen by the malware’s creators. The apps will look identical to the ones they are replacing.


No comments:

Post a Comment