In a nutshell, hackers infected a legitimate copy of Xcode, then made that tainted copy available for download on Baidu in China. Developers sometimes turn to Baidu when Apple’s servers in China are slow.
The developers used their tainted copy of Xcode to build unknowingly infected apps, then uploaded those infected apps to the Chinese App Store. Some of those apps made their way to app stores in other countries.
From this report from Palo Alto Networks:
We checked these apps and list them below in this report. As of this writing, we see 39 iOS apps being infected, some of which are extremely popular in China and in other countries around the world, comprising hundreds of millions users.
The infected iOS apps include IMs, banking apps, mobile carrier’s app, maps, stock trading apps, SNS apps, and games. Among the more well-known apps are WeChat (developed by Tencent); Didi Chuxing (developed by Didi Kuaidi) the most popular Uber-like app in China; Railway 12306, the only official app used for purchasing train tickets in China; China Unicom Mobile Office, which is in use by the biggest mobile carrier in China; and Tonghuashun, one of most popular stock trading apps.
Some apps are also available from the App Store in other countries. For example, CamCard, developed by a Chinese company, is the most popular business card reader and scanner in many countries (including the US) around the world. WeChat is the most popular IM app not only in China but also in many countries or regions in Asia Pacific. Version 6.2.5 of WeChat is what we have verified to be infected. Tencent has updated to 6.2.6, which removed the malicious code.
The report links known infected apps.
The hackers embedded the malicious code in these apps by convincing developers of legitimate software to use a tainted, counterfeit version of Apple’s software for creating iOS and Mac apps, which is known as Xcode, Apple said.
“We’ve removed the apps from the App Store that we know have been created with this counterfeit software,” Apple spokeswoman Christine Monaghan said in an email. “We are working with the developers to make sure they’re using the proper version of Xcode to rebuild their apps.”
She did not say what steps iPhone and iPad users could take to determine whether their devices were infected.
The method that was used to taint Xcode sounds just like what the CIA and/or NSA have been trying to do to hack into the OS and software on Apple’s devices, as revealed by Edward Snowden: https://theintercept.com/2015/03/10/ispy-cia-campaign-steal-apples-secrets/
It may be that this was a copycat attack by bad actors in China. It may even be that it was actually done by the CIA or NSA to try to hack into the iPhones/iPads of Chinese officials!
Either way, now that this has been revealed, developers are probably going to be much more careful about getting their copies of Xcode directly from Apple. Also, Apple themselves are likely to add some kind of checksumming to Xcode so that it’ll warn you on launch if it’s tainted. They may even add in something in a future iOS update that could detect apps built by this tainted copy of Xcode and quarantine them.
I’ve read the explanation, why they did not use the official Apple server: It was “too slow”. Now that’s a lame excuse (pun intended).
According to an article on MacNN, Rovio’s Angry Birds 2 is infected. I can understand small devs wanting to save on bandwidth but Rovio? Come on now…
OFFS. Are all of these coming through via replies to comments? If so, maybe there is a backdoor for spam through a reply somehow?
It sounds like part of the problem is the “great firewall of China” which keeps a strict eye on traffic in and out of the country, and makes accessing sites outside of China very slow. Maybe Apple needs to have an internal download site for Chinese developers?
Rovio says that only the Chinese version of Angry Birds 2 was affected. And it sounds like the bandwidth issue has nothing to do with the developer, but is caused by restricted “pipes” going in and out of China. Even if Rovio’s Chinese office had amazing bandwidth, it would still have been much faster to download from one of these fake mirror sites.
That being said, being a developer myself, I would NEVER trust downloading something like Xcode from anything other than Apple’s server.
Why do I get the strange feeling that the main target of the hack are Chinese developers distributing Chinese apps with a backdoor that can be used by the government to spy on their own people? Just a gut feeling.
IDGI I mean I always run the latest PRC approved hackintosh and Xcode+ for all my projects, who wouldn’t trust Baidu and the Chinese government over apples servers?! /s