Skip to main content

Backdoor:iPhoneOS/XCodeGhost

Classification

Category:

Malware

Platform:

iPhoneOS

Type:

Backdoor

Aliases:

  • Backdoor:iPhoneOS/XCodeGhost.[variant]
  • Trojan.MAC.OSX.XcodeGhost.[variant]
  • XcodeGhost.[variant]

Summary

Backdoor:iPhoneOS/XCodeGhost identifies iOS apps that include code introduced when the software was created using a maliciously-modified version of the Xcode app creation framework.

Removal

Technical Details

In late September 2015, security researchers discovered apps containing malicious code were being offered in the iOS App Store. Further investigation revealed that the apps had been unknowingly created by legitimate developers using a version of the popular Xcode app creation platform that had been modified to silently introduce code into the programs it was used to create. The trojanized Xcode software had been distributed by the attackers on forums that developers often frequented.

Once installed on a user's device, the code-tainted apps were able to read and alter information on the device, as well as silently sending data to remote servers. The majority of the affected users were reportedly from China, though researchers have noted that affected apps were downloaded in other regions as well.

Following news of the discovery, the compromised apps were removed from the App Store.

For more information about the incident, see:

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.