Apple withdraws some China apps after malware found

BEIJING (AP) — Apple Inc. has removed some applications from its App Store after developers in China were tricked into using software tools that added malicious code in an unusual security breach.

Apple gave no details of which companies were affected. But Tencent Ltd. said its popular WeChat app was affected and the company released a new version after spotting the malicious code. Chinese news reports said others affected included banks, an airline and a popular music service.

The malicious code spread through a counterfeit version of Apple’s Xcode tools used to create apps for its iPhones and iPads, according to the company. It said the counterfeit tools spread when developers obtained them from “untrusted sources” rather than directly from the company.

The malicious software collects information from infected devices and uploads it to outside servers, according to Palo Alto Networks, a U.S.-based security firm, which investigated the malware. It was first publicized last week by researchers at Alibaba Group, the e-commerce giant, who dubbed it XcodeGhost.

Cybersecurity experts say the episode shows that any device, including those running Apple’s iOS software, can be vulnerable to hackers even though Apple is known for rigorously scrutinizing apps that are offered in its store.

“I wouldn’t say that the floodgates for iOS malware are open now, but this vector is probably something that other attackers are going to try to replicate in the future,” said Ryan Olson, director of threat intelligence for Palo Alto Networks, in an interview. He said Apple is undoubtedly working on improving its ability to block similar attempts.

Hackers are increasingly looking for new ways to target mobile apps and devices, including iPhones, because they are so widely used by many consumers, added Darren Hayes, a cyber-security expert at Pace University in New York.

The creators of this malware took advantage of public frustration with Beijing’s Internet filters, which hamper access to Apple and other foreign websites. That prompts some people to use copies of foreign software or documents that are posted on websites within China to speed up access.

“Sometimes network speeds are very slow when downloading large files from Apple’s servers,” wrote Claud Xiao, a Palo Alto Networks researcher, on its website. Due to the large size of the Xcode file, “some Chinese developers choose to download the package from other sources or get copies from colleagues.”

Companies with apps that were affected include taxi-hailing service Didi Kuaidi, Citic Industrial Bank, China Southern Airlines and the music service of NetEase, a popular Web portal, according to the newspaper Yangcheng Evening News.

The incident is the only the sixth time malicious software is known to have made it through Apple’s screening process for products on its App Store, according to Xiao.

___

AP Technology Writer Brandon Bailey in San Francisco contributed to this report.

More in News

(Juneau Empire file photo)
Aurora forecast through the week of Dec. 22

These forecasts are courtesy of the University of Alaska Fairbanks’ Geophysical Institute… Continue reading

The U.S. Capitol in Washington, Dec. 18, 2024. The Senate passed bipartisan legislation early Saturday that would give full Social Security benefits to a group of public sector retirees who currently receive them at a reduced level, sending the bill to President JOE Biden. (Kenny Holston/The New York Times)
Congress OKs full Social Security benefits for public sector retirees, including 15,000 in Alaska

Biden expected to sign bill that eliminates government pension offset from benefits.

Pauline Plumb and Penny Saddler carry vegetables grown by fellow gardeners during the 29th Annual Juneau Community Garden Harvest Fair on Saturday, Aug. 19, 2023. (Mark Sabbatini / Juneau Empire file photo)
Dunleavy says he plans to reestablish state Department of Agriculture via executive order

Demoted to division status after statehood, governor says revival will improve food production policies.

Alan Steffert, a project engineer for the City and Borough of Juneau, explains alternatives considered when assessing infrastructure improvements including utilities upgrades during a meeting to discuss a proposed fee increase Thursday night at Thunder Mountain Middle School. (Mark Sabbatini / Juneau Empire)
Hike of more than 60% in water rates, 80% in sewer over next five years proposed by CBJ utilities

Increase needed due to rates not keeping up with inflation, officials say; Assembly will need to OK plan.

Gov. Mike Dunleavy and President-elect Donald Trump (left) will be working as chief executives at opposite ends of the U.S. next year, a face constructed of rocks on Sandy Beach is seen among snow in November (center), and KINY’s prize patrol van (right) flashes its colors outside the station this summer. (Photos, from left to right, from Gov. Mike Dunleavy’s office, Elliot Welch via Juneau Parks and Recreation, and Mark Sabbatini via the Juneau Empire)
Juneau’s 10 strangest news stories of 2024

Governor’s captivating journey to nowhere, woman who won’t leave the beach among those making waves.

Police calls for Wednesday, Dec. 18, 2024

This report contains public information from law enforcement and public safety agencies.

The U.S. Capitol on Wednesday. Funding for the federal government will lapse at 8:01 p.m. Alaska time on Friday if no deal is reached. (Kenny Holston/The New York Times)
A federal government shutdown may begin tonight. Here’s what may happen.

TSA will still screen holiday travelers, military will work without paychecks; food stamps may lapse.

The cover image from Gov. Mike Dunleavy’s “Alaska Priorities For Federal Transition” report. (Office of the Governor)
Loch Ness ducks or ‘vampire grebes’? Alaska governor report for Trump comes with AI hallucinations

A ChatGPT-generated image of Alaska included some strange-looking waterfowl.

Bartlett Regional Hospital, along with Juneau’s police and fire departments, are partnering in a new behavioral health crisis response program announced Thursday. (Bartlett Regional Hospital photo)
New local behavioral health crisis program using hospital, fire and police officials debuts

Mobile crisis team of responders forms five months after hospital ends crisis stabilization program.

Most Read