HKCERT, November 17, 2015
In the Sep-2015, a security researcher discovered iOS malware XcodeGhost in official Apple Store. Over hundred applications were affected, including “WeChat”, “TTPod”, “Di Di”, “Hexin Financial” common application and “Angry Birds 2” famous game. Apple officially announced, the infected app were under the removal process in the App Store. The affected apps’ developers would update their apps and submit to the App Store again. There is still a risk of data leakage if users does not remove or update the affected apps. HKCERT analyzed the data from the Shadowserver. We discovered that average 14,147 unique IPs per day still made connection to the C2 server of XcodeGhost in the first week of October. This figure is about 30 times of other botnets infection.