As usual …
Malware XcodeGhost Infects 39 iOS Apps, Including WeChat, Affecting Hundreds of Millions of Users
Yesterday we posted an analysis report on a novel malware XcodeGhost that modifies Xcode IDE to infect Apple iOS apps. In the report, we mentioned that at least two popular iOS apps were infected. We now believe many more popular iOS apps have been infected, including WeChat, one of the most popular IM applications in the world.
After we posted the report, some security companies like Qihoo 360 scanned popular apps in App Store by code analysis; and some iOS developers analyzed some more apps using crowd-sourcing techniques. Several Internet companies such as Tencent, NetEase, and Jianshu, have made statements on their respective affected products..
We checked these apps and list them below in this report. As of this writing, we see 39 iOS apps being infected, some of which are extremely popular in China and in other countries around the world, comprising hundreds of millions users.
The infected iOS apps include IMs, banking apps, mobile carrier’s app, maps, stock trading apps, SNS apps, and games. Among the more well-known apps are WeChat (developed by Tencent); Didi Chuxing (developed by Didi Kuaidi) the most popular Uber-like app in China; Railway 12306, the only official app used for purchasing train tickets in China; China Unicom Mobile Office, which is in use by the biggest mobile carrier in China; and Tonghuashun, one of most popular stock trading apps.
Figure 1. WeChat 6.2.5 is also infected
Some apps are also available from the App Store in other countries. For example, CamCard, developed by a Chinese company, is the most popular business card reader and scanner in many countries (including the US) around the world. WeChat is the most popular IM app not only in China but also in many countries or regions in Asia Pacific. Version 6.2.5 of WeChat is what we have verified to be infected. Tencent has updated to 6.2.6, which removed the malicious code.
Palo Alto Networks is cooperating with Apple on the issue and we also suggest all iOS developers be aware and take necessary actions.
Infected iOS apps
网易云音乐 2.8.3
微信 6.2.5
讯飞输入法 5.1.1463
滴滴出行 4.0.0.6-4.0.0.0
滴滴打车 3.9.7.1 – 3.9.7
铁路12306 4.5
下厨房 4.3.2
51卡保险箱 5.0.1
中信银行动卡空间 3.3.12
中国联通手机营业厅 3.2
高德地图 7.3.8
简书 2.9.1
开眼 1.8.0
Lifesmart 1.0.44
网易公开课 4.2.8
马拉马拉 1.1.0
药给力 1.12.1
喜马拉雅 4.3.8
口袋记账 1.6.0
同花顺 9.60.01
快速问医生 7.73
懒人周末
微博相机
豆瓣阅读
CamScanner
CamCard
SegmentFault 2.8
炒股公开课
股市热点
新三板
滴滴司机
OPlayer 2.1.05
电话归属地助手 3.6.5
愤怒的小鸟2 2.1.1
夫妻床头话 1.2
穷游 6.6.6
我叫MT 5.0.1
我叫MT 2 1.10.5
自由之战 1.1.0
Fox-IT (fox-it.com), a Netherlands based security company, checked all C2 domain names from our reports in their network sensors and has found thousands of malicious traffic outside China. According to their data, these iOS apps were also infected:
Mercury
WinZip
Musical.ly
PDFReader
guaji_gangtai en
Perfect365
网易云音乐
PDFReader Free
WhiteTile
IHexin
WinZip Standard
MoreLikers2
CamScanner Lite
MobileTicket
iVMS-4500
OPlayer Lite
QYER
golfsense
同花顺
ting
installer
下厨房
golfsensehd
Wallpapers10000
CSMBP-AppStore
礼包助手
MSL108
ChinaUnicom3.x
TinyDeal.com
snapgrab copy
iOBD2
PocketScanner
CuteCUT
AmHexinForPad
SuperJewelsQuest2
air2
InstaFollower
CamScanner Pro
baba
WeLoop
DataMonitor
爱推
MSL070
nice dev
immtdchs
OPlayer
FlappyCircle
高德地图
BiaoQingBao
SaveSnap
Guitar Master
jin
WinZip Sector
Quick Save
CamCard
8 Comments
None of them seem to be apps used at all or generally in the West
If an Apple iPhone user has downloaded and used one of these infected apps, what is the recommended course of action? What are the potential security risks and what should one do to protect themselves?
“SJCAM zone” v2.5.0 are infected!
Ok but what should I do when having an infected app?
Would be nice if the Affected IOS apps was translated to english
If you have one of the apps, uninstall immediately.
As I understand it, the apps not listed in English are local Asian versions of some popular apps (i.e. Localized version of Angry Birds). Ref: arstechnica.
Post Your Comment
143 Pingbacks & Trackbacks
September 21, 2015 9:30 AM
Image-Kratzer bei Apple: Verseuchte Software im offiziellen App-Store | Michael Gessat
September 21, 2015 10:04 AM
XcodeGhost, y porqué no es para tanto en iPaderos
September 21, 2015 10:06 AM
Apple iOS hack: What is it, what apps are affected and is my iPhone at risk?
September 21, 2015 10:07 AM
XcodeGhost iOS malware: The list of affected apps and what you should do | Lookout Blog
September 21, 2015 10:29 AM
Apple pulls infected apps after malware strikes App Store | Apple Act
September 21, 2015 10:50 AM
Apple descubre malware en aplicaciones de la App Store | JnicolaslazaroC
September 21, 2015 10:51 AM
Security Researchers Publish List Of iOS Apps Infected By XcodeGhost - LocurasGeek - Tecnologia e Internet y Juegos
September 21, 2015 10:59 AM
Apple pulls infected apps after malware strikes App Store | Mobile Security Review
September 21, 2015 11:33 AM
Apple Removes 40 Malware-Infected Apps From App Store | SOUTHBAY INTERNET SOLUTIONS
September 21, 2015 11:40 AM
Malware-Laden Apps Pulled From Apple's iOS App Store | Laptop Charger Canada
September 21, 2015 11:50 AM
Bréking! Ezeket az appokat töröld villámgyorsan a telefonodról!
September 21, 2015 11:56 AM
XcodeGhost hack: Delete these infected iOS apps immediately | Apple Act
September 21, 2015 12:00 PM
Apple combats cyberattack, begins iOS App Store scrub - Digital Answers
September 21, 2015 12:04 PM
Apple pulls infected apps after malware strikes App Store | POPALZ News – Latest news from Pakistan
September 21, 2015 12:10 PM
Apple scrambles after 40 malicious “XcodeGhost” apps haunt App Store • Reliable Tech & IT Blog for Everyone
September 21, 2015 12:16 PM
9/21 更新 | 没越狱的 iPhone 也被黑客攻破了,原因有点滑稽
September 21, 2015 12:22 PM
Malware-Laden Apps Pulled From Apple's iOS App Store | Laptop Charger USA
September 21, 2015 12:31 PM
New Report Details Apps With XcodeGhost | Smartphone Tips n Tricks
September 21, 2015 12:38 PM
Malware-Laden Apps Pulled From Apple's iOS App Store - 4PC News
September 21, 2015 12:57 PM
Apple App Store Hit By First Ever Malware Cyber Attack - Capital Technologies
September 21, 2015 1:24 PM
Alert: First Major iOS App Store Breach | BankVault
September 21, 2015 1:29 PM
XcodeGhost Infected Apps - Complete List of iOS Apps
September 21, 2015 1:31 PM
Las aplicaciones infectadas que debes borrar de tu iPhone: WeChat, Angry Birds 2, InstaFollower y otras
September 21, 2015 1:32 PM
Las aplicaciones infectadas que debes borrar de tu iPhone: WeChat, Angry Birds 2, InstaFollower y otras | Cnn Hit New
September 21, 2015 1:51 PM
Las aplicaciones infectadas que debes borrar de tu iPhone: WeChat, Angry Birds 2, InstaFollower y otras | Bienestar Institucional
September 21, 2015 1:58 PM
iCloud phishing attack hooks 39 iOS apps and WeChat
September 21, 2015 2:29 PM
Apple pulls infected apps after malware strikes App Store | Apple Admin
September 21, 2015 2:30 PM
Apple Cleans House after App Store Suffers Malware Attack - Ultimate Mac
September 21, 2015 2:30 PM
Apple descubre malware en aplicaciones de la App Store - ..:: SINETEC ::..
September 21, 2015 2:35 PM
What happens when convenience wins over security | Safe and Savvy Blog by F-Secure
September 21, 2015 2:37 PM
Apple Removes 40 Malware-Infected Apps From App Store - The Financial
September 21, 2015 2:59 PM
Smažte z iOS aplikace, které mohou být napadené XcodeGhost
September 21, 2015 3:09 PM
Unbuensitio Blog | Diseño y programación Web – Las aplicaciones infectadas que debes borrar de tu iPhone: WeChat, Angry Birds 2, InstaFollower y otras
September 21, 2015 3:37 PM
Loja virtual da Apple oferecia aplicativos infectados com malware | Tech News
September 21, 2015 3:38 PM
Loja virtual da Apple oferecia aplicativos infectados com malware | TV Pimenta
September 21, 2015 3:52 PM
Everything you need to know about the App Store malware – Dragon Insider
September 21, 2015 4:06 PM
Millions of Chinese Users Affected by App Store Hack
September 21, 2015 4:26 PM
Everything you need to know about App Store malware | High Tech News
September 21, 2015 5:13 PM
XcodeGhost: Is Your Apple iPhone Or iPad Infected? – International Business Times | Lanka Phones HQ
September 21, 2015 5:57 PM
Apple Removes iPhone, iPad Apps From Stores Infected By Malware - MITechNews
September 21, 2015 6:05 PM
【注意】iPhoneアプリ、数億人にパスワード盗難の恐れ | バズニュース速報
September 21, 2015 6:44 PM
AppStore XCodeGhost Tehlikesi | CydiaTR : Türkçe Cydia
September 21, 2015 7:05 PM
Falha grave permite entrada de malwares na App Store; Apple reconhece e faz limpeza – MacMagazine.com.br