YiSpecter malware affects both jailbroken and non-jailbroken iOS devices and abuses APIs for malicious activity....
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
How does YiSpecter infect non-jailbroken devices, and what is the best way to defend against it?
YiSpecter malware may seem like a relatively low-risk threat to enterprise users and to only be targeting users in China. However, the in-depth investigation performed by Palo Alto Networks brings to light how numerous low-risk security issues can, together, completely compromise the security of a non-jailbroken iOS device. It looks much like early forms of adware for Windows with affiliates, install tracking and ad injection among others, with many of the same risks.
YiSpecter infects non-jailbroken -- and jailbroken -- devices by abusing the enterprise distribution mechanism for iOS, using an app signed by a legitimate enterprise certificate that the user agrees to install. The user installs the malicious app thinking she is installing a video player or "free" versions of non-free software. Once it is installed on the device, it uses private APIs to install additional malware to replace legitimate applications, and ensure the malware protects itself from removal. It will be hidden from the list of installed apps and named similarly to legitimately installed apps. It will also start showing new ads on the device.
Palo Alto Networks stated the best way to defend against YiSpecter is to only download iOS apps from the official Apple iOS App Store or from an enterprise-managed internal app store. Users should resist the urge to access free versions of commercial software or free access to non-free content. Palo Alto Networks has published the IPS signatures to help enterprises to detect compromised devices. Apple was notified of the compromised enterprise certificates and said it has blocked the specific apps that were spreading the YiSpecter malware. Apple also said older versions of iOS are vulnerable to the malware, and that users should upgrade to iOS 8.4 to protect themselves.
Learn more about new iOS malware called KeyRaider
Discover how malware bypassed Apple's App Store security controls
Read more on the increase of digitally signed malware
Dig Deeper on Mobile security threats and prevention
Related Q&A from Nick Lewis
Can Structured Threat Information eXpression improve threat intelligence sharing? Nick Lewis breaks down the evolution of the STIX security framework.continue reading
A new type of WordPress malware, WP-Base-SEO, disguises itself as an SEO plug-in that opens backdoors. Nick Lewis explains how it works and how to ...continue reading
A new exploit of CLDAP servers can be used for a DDoS reflection attack that gives attackers a 70x boost. Nick Lewis explains how to defend against ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.