Apple issues clarification on extent of iOS malware infection

Just when we clever clogs computer fellas think we know every thing ::

Apple has issued a response to the reports of a vulnerability in its iOS operating system, saying the attack affected fewer than a dozen websites that focus on content related to the Uighur community.

Google researchers found that a set of websites hacked in February were being used to attack iPhones, infecting them with malware.

The iPhone malware implant, which has not been given a name, was able to escape the iOS sandbox and run as root, which meant it has bypassed the security mechanisms of iOS and has the highest level of privileges.

It was capable of stealing:

All keychains,


SMS and email messages,

Contacts, notes, and recordings,

It can retrieve the full call history and is capable of doing real-time monitoring of the device location.

It also includes the capability to obtain the unencrypted chat transcripts from a number of major end-to-end encrypted messaging clients, including Messages, Whatsapp, and Telegram.

This means that if you’re infected, all your encrypted messages are not only collected by the attacker, but they’re transferred in clear-text across the Internet.



Worth a read, someone, presumably the Chinese, can fuck with you, from a website. SO, imagine that Thai360 says 'click this to log in' to you, one day...

My limited exposure to the processes that run in the background of Mac OS X gives me to understand that there are multiple security efforts that run, separately in the dark, to keep Apple's stuff relatively clean. I often see, when my desktop slows down, a process, cleaning malware, that is not normally visible to the user.

