Spyware targets Hong Kong protestors using Android, jailbroken iPhones or iPads

  • Thread starter Thread starter Rene Ritchie
  • Start date Start date
R

Rene Ritchie



There's a new kind of spyware going around called Xsser that's reportedly targeting protestors in Hong Kong. The spyware — which appears to have ties to Android malware discovered last week — is installed via a Debian package and requires a victim's iPhone or iPad to be jailbroken. Breaking the root jail of iOS can provide for functionality beyond what Apple currently ships, but also strips away Apple's built-in iOS security. The same way jailbroken software can be loaded, malicious software can be loaded. (Same goes with bypassing Android's default security settings, as well as when you open up a phone to root access.) So what's going on with Xsser and how can you protect yourself?

Reuters has a quasi-report up that mislabels Xsser as a virus, doesn't link back to its source, and neglects to mention that only jailbroken iOS devices seem to be vulnerable, but does provide the following overview:


The malicious software, known as Xsser, is capable of stealing text messages, photos, call logs, passwords and other data from Apple mobile devices, researchers with Lacoon Mobile Security said on Tuesday. They uncovered the spyware while investigating similar malware for Google Inc's Android operating system last week that also targeted Hong Kong protesters. Anonymous attackers spread the Android spyware via WhatsApp, sending malicious links to download the program, according to Lacoon.

Lacoon itself is more thorough:


Lacoon hasn't uncovered information regarding the method or vector of attack. The iOS device needs to be jailbroken in order to be infected. Then with Cydia installed, the repository would be need to be added and then the package could be installed. All that's known is that both the iOS and Android attacks share a CnC server. The package itself is a debian .deb package. The package installs an iOS 'launchd' service to make sure the app starts after booting and in addition starts it up immediately.

If you think you're at risk from Xsser, until more is known about how it is being spread, removing your jailbreak by upgrading or restoring to an official version of iOS is the best way to protect yourself.

Nick Arnott contributed to this article.

5883bae68183ac49b2fc1485fc2525cd.gif







8e0c4fe93cca24a3f4536c883ec00d4c._.gif
ff4b20447f183059ae8f271cfffab7a8._.gif


Continue reading...
 
Back
Top