• Hype
  • Murai
  • Lipstiq
  • Wanista
  • Varnam
  • Hangat
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Mobile Phones iPhone

“Masque Attack” Vulnerability on iOS Can Mask Itself as Legitimate Apps to Steal Information

by Huei Song
November 12, 2014
Share on FacebookShare on Twitter

iOS Masque Attack

Just about a week after the Wirelurker malware in iOS was discovered, Apple’s mobile operating system is now facing yet another vulnerability called “Masque Attack”. As its name suggests, when infected, the attack will mask itself as an existing app, making it almost impossible to discover while it sits there quietly collecting all your personal information and even banking data.

The attack was discovered by a security research company called FireEye and it works by trying to make users install an app outside of the App Store. As shown in the demo video below, the user received an SMS telling them to try out a “New Flappy Bird” game and once clicked, he/she will be prompted to install an app. The app isn’t Flappy Bird of course, instead, it’s a fake Gmail app that installs directly over the real Gmail app.

YouTube video

Masque Attack can replace apps installed from the App Store like banking and email apps. This means that it will stay on your phone undetected, collecting confidential information such as banking details, emails, addresses and such. According to FireEye, the attack works on iOS 7.1.1, 7.1.2, 8.0, 8.1 and even the beta version of iOS 8.1.1.

Of course, in order for Masque Attack to work, the user will have to install iOS provisioning profiles, which are commonly used for beta testing or for companies to distribute apps to their employees. This means that you should never ever install profiles onto your iOS device, unless you are completely sure that it’s legitimate.

Do you have a profile installed on your iOS device? Open up the Settings app, hit General, scroll down to Profile to see what configuration profile you have installed, and remove all the unnecessary ones – unless you do beta testing for apps or your company requires you to install certain apps from the company, I don’t see a reason to have a profile installed. Even then, make sure that it’s verified.

(Source: FireEye via: MacRumors)

Filed Under iOS malware
Updated 12:48 pm, Wed, 12 November 14
https://lowy.at/7989z
Share1Tweet1SendShare

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    Mobile Phones

    Tecno Camon 50 Ultra Debuts At MWC 2026 With Dimensity 7400 Ultimate, 6,500mAh Battery

  2. 2
    Banking

    Account Lockouts: Maybank Says Challenge Questions Triggered By Fraud Monitoring

  3. 3
    E-commerce

    Shopee Seller Threatens To Dox Buyer After GPU Price Dispute

  4. 4
    Android Phones

    Huawei Mate 80 Pro Launches In Malaysia With RM3,999 Price Tag

  5. 5
    News

    ZDATA’s RM8 Billion Johor AI Data Centre Earns Malaysia’s First GreenRE Platinum Rating

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Wanista
  • Varnam
  • Hangat
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Contact Us
  • Editorial Policy
  • Terms & Conditions

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.