Experts at Kaspersky have discovered infected versions of popular iOS apps distributed through a Russian-language Telegram channel. The attackers embedded a malicious module into modified versions of legitimate apps, capable of collecting device information, geolocation, and taking screenshots. Among the apps found were, for example, an online marketplace for selling goods, a photo editor, and a video streaming service. Some other modified apps do not contain malicious code, but they include a link to the Telegram channel through which such apps are distributed.
How installation occurs. The attackers publish iOS app installation files (IPA) on Telegram and offer users to purchase a developer certificate from them. After that, the certificate is imported into special tools for installing third-party apps on iOS, such as eSign or Scarlet. With their help, the app is signed with the certificate and installed on the device via private mechanisms of the operating system. It is also possible to install such an app without purchasing a certificate—for example, from a computer or on a jailbroken device, which allows making changes to the system bypassing security functions.
What the malware can do. The embedded module cannot work in the background, so after closing the infected app, it cannot continuously monitor user actions. While the app is open, the malware can collect device information (such as device name, battery level, regional settings, memory information, and jailbreak status), geolocation, mobile operator code, device identifiers, and also take screenshots and transmit this data to the attackers.
“Users may download apps from third-party sources to get modified versions of popular programs—without ads, with unlocked paid features, or other changes. Apps that are not available in official stores may also be published there. Attackers take advantage of this: they distribute modified versions of popular programs through third-party channels, some of which may contain malicious code. Therefore, it is important to remember that apps should only be installed from trusted sources, and if they are not available in the official store, check the developer’s website for installation methods,” says Sergey Puzan, cybersecurity expert at Kaspersky.


