Thursday, August 7, 2025
  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Mobile Phones iPhone

“Masque Attack” Vulnerability on iOS Can Mask Itself as Legitimate Apps to Steal Information

by Huei Song
November 12, 2014
Share on FacebookShare on Twitter

iOS Masque Attack

Just about a week after the Wirelurker malware in iOS was discovered, Apple’s mobile operating system is now facing yet another vulnerability called “Masque Attack”. As its name suggests, when infected, the attack will mask itself as an existing app, making it almost impossible to discover while it sits there quietly collecting all your personal information and even banking data.

The attack was discovered by a security research company called FireEye and it works by trying to make users install an app outside of the App Store. As shown in the demo video below, the user received an SMS telling them to try out a “New Flappy Bird” game and once clicked, he/she will be prompted to install an app. The app isn’t Flappy Bird of course, instead, it’s a fake Gmail app that installs directly over the real Gmail app.

Masque Attack can replace apps installed from the App Store like banking and email apps. This means that it will stay on your phone undetected, collecting confidential information such as banking details, emails, addresses and such. According to FireEye, the attack works on iOS 7.1.1, 7.1.2, 8.0, 8.1 and even the beta version of iOS 8.1.1.

Of course, in order for Masque Attack to work, the user will have to install iOS provisioning profiles, which are commonly used for beta testing or for companies to distribute apps to their employees. This means that you should never ever install profiles onto your iOS device, unless you are completely sure that it’s legitimate.

Do you have a profile installed on your iOS device? Open up the Settings app, hit General, scroll down to Profile to see what configuration profile you have installed, and remove all the unnecessary ones – unless you do beta testing for apps or your company requires you to install certain apps from the company, I don’t see a reason to have a profile installed. Even then, make sure that it’s verified.

(Source: FireEye via: MacRumors)

Filed Under iOS malware
Updated 12:48 pm, Wed, 12 November 14
https://lowy.at/7989z
Share1Tweet1SendShare

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    News

    You Can Now Apply To Switch To TNB ToU Billing Via myTNB Portal

  2. 2
    How-To's

    RM100 SARA: How To Redeem, And Everything Else You Need To Know

  3. 3
    Transportation

    KTM Komuter Services To KL Sentral Disrupted On Sundays Until Late September

  4. 4
    Accessories

    CUKTECH Launches Power Bank, Mini Fan; Priced From RM47

  5. 5
    Mobile Phones

    Xiaomi Malaysia Teases Redmi 15 5G With 7,000 mAh Battery

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Contact Us
  • Editorial Policy
  • Terms & Conditions

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.