iPhone Hit with New Exploit - Olmec Skip to main content

iPhone Hit with New Exploit

By April 4, 2016March 2nd, 2023Blog, Cybersecurity

android_hit_with_new_exploitThere’s another new attack vector to beware of if you own an iPhone. This new attack, called AceDeceiver MITM is quite possibly the most convoluted attack the hackers have come up with yet, and stands as an excellent example of just how far the hackers will go to get to your personal information.

To set the stage for this attack, the hackers purchase an app from the Apple store, taking advantage of a flaw in Apple’s DRM protection module known as FairPlay. They save the authorization code, then design software that simulates the iTunes client behavior sufficiently to trick iOS into believing that the app was purchased by the target victim. This enables the app to be installed on the phone without the user’s knowledge or consent. Once installed, the app is used as a launch pad to install whatever else the hackers desire. Other apps, snooping protocols, and the like.

Convoluted or not, it’s a stunningly creative and effective attack that’s virtually impossible to stop. The only outward sign that you’re being targeted will be new icons for Apps that you don’t remember installing.

As bad as this sounds, there is a bit of a silver lining. For the moment, at least, these attacks have been restricted to users in China, so unless you’re there, odds are that you won’t run afoul of this attack. The hope, of course, is that Apple will be able to close the security loophole that makes this attack possible before it becomes more widespread, although at this point, there has been no word from Apple regarding a timeframe for the fix.

This latest attack clearly demonstrates just how difficult it is for any tech vendor to completely secure their equipment. The hackers are simply testing scenarios that the design team never envisioned, and it’s working. 2016 is shaping up to be a very busy year in the field of internet security.

Chris Forte

Chris Forte, President and CEO of Olmec Systems, has been in the MSP workspace for the past 25 years. Chris earned his Master’s Degree from West Virginia University, graduating Magna Cum Laude. He was a past member of the Entrepreneurs’ Organization, a current member of the New Jersey Power Partners and Executive Association of New Jersey, where he has previously served on its board of directors. In his spare time, Chris enjoys traveling with his family. He also admits to being a struggling golfer and avid watcher of college football and basketball. He currently lives in Boonton Township, NJ with his wife, two daughters, son, and black lab Luna.