Skip to main content

Apple tells Digital Trends that it has blocked ‘WireLurker’ malware targeting iPhones and iPads

iPhone 6
Image used with permission by copyright holder
It’s not very often you hear about malware targeting iOS, but security researchers in Silicon Valley said on Wednesday they’ve spotted new malicious software doing just that.

Although it appears to be spreading through a third-party OS X app store in China and consequently largely confined to that country, the development could be a taste of things to come for iDevice owners in other parts of the world if similarly designed malware is launched by other cybercriminals, or even the same group.

Palo Alto Networks said the one it’s uncovered, called ‘WireLurker’, loads onto iPhones and iPads when the device is connected via USB to a Mac computer onto which an infected OS X app has already been downloaded.

Updated on 11-06-2014 by Jeffrey Van Camp: An Apple representative has told Digital Trends that “We are aware of malicious software available from a download site aimed at users in China, and we’ve blocked the identified apps to prevent them from launching. As always, we recommend that users download and install software from trusted sources.”

The security firm’s Claud Xiao said in a blog post (via NYT) that the malicious software is apparently only the second known case of a malware attack on iOS devices through OS X via USB, and can infect Apple devices whether or not they’ve been jailbroken. In an ominous note, the researcher said the discovery “heralds a new era in malware attacking Apple’s desktop and mobile platform” and is “the biggest in scale we have ever seen.”

According to Palo Alto Networks’ research, WireLurker has infected 467 OS X apps on the third-party Maiyadi App Store, with just over 356,000 downloads made to OS X computers, meaning the malware could have impacted “hundreds of thousands” of iOS users.

The malware is capable of stealing “a variety of information” from a user’s mobile device, though according to Xiao, the goal of the person or people behind the software, which is continuing to be updated, is yet to be identified.

For now, the security firm suggests users take a number of steps to ensure they steer clear of WireLurker and similar threats, including avoiding Mac apps from third-party app stores, and refraining from connecting iOS devices to untrusted or unknown accessories or computers. See Xiao’s post for the full list of recommended measures.

While the software appears to be confined to users in China for now, Ryan Olson, the director of threat intelligence at Palo Alto Networks, suggested it may not stay that way, telling the NY Times that it “demonstrates to a lot of attackers that this is a method that can be used to crack through the hard shell that Apple has built around its iOS devices.”

We’ve reached out to Apple for comment and will update when we hear back.

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
10 reasons you should buy an iPhone in 2024
Purple iPhone 14 (left) and a green iPhone 15 in hand.

The iPhone 15 lineup — which includes the standard iPhone 15 and the iPhone 15 Pro — is the iPhone at its best. It's the latest series of iPhones available today and the default choice if you're buying a new iPhone in 2024.

But it’s not the only choice of iPhones you can purchase. In fact, Apple still sells the iPhone 14, iPhone 13, and the iPhone SE on its website. You could also find other iPhone models available – refurbished or new — from other retailers or carrier stores.

Read more
We now know when Apple is adding RCS to the iPhone
The iPhone 14 Plus held in a man's hand.

Last November, Apple made a surprise announcement when it confirmed that RCS was coming to the iPhone in 2024. It's something iPhone and Android phone users alike have been waiting years for, but there was just one small problem: Apple never said when in 2024 RCS was coming. Thanks to Google, of all companies, we now have a better idea of when RCS is heading to the iPhone.

As spotted by 9to5Google, the Android website was recently updated with a new page dedicated to Google Messages. If you click on the "See more features" button for the section talking about RCS, there's a section titled "Better messaging for all" with the following text: "Apple has announced it will be adopting RCS in the fall of 2024. Once that happens, it will mean a better messaging experience for everyone."

Read more
iOS 18 could make my iPhone look like Android, and I hate it
The Apple iPhone 15 Pro Max and the Samsung Galaxy S23 Ultra's rear panels.

If rumors are to be believed, iOS 18 will allow you to customize the home screen on your iPhone more substantially than ever before. This feature will be familiar to Android phone owners, but I don’t want my iPhone to look like an Android phone.

It’s a weird double-edged sword, as by giving you more freedom to make the home screen look unique, iOS may also lose what makes it unique compared to the less constrained world of Android.
iOS 18 and your iPhone home screen

Read more