Apple constantly updates its operating systems with security patches, which hackers often exploit to attack users in many different ways. However, this time, cybersecurity firm Group-IB has reported a new Trojan “GoldDigger” targeting iOS users to steal their bank accounts.
GoldDigger trojan can steal sensitive data from iOS users
according to Detailed report by Group-IB (via Tom's guide), GoldDigger was first created for Android, but has now been successfully ported to attack iPhone and iPad users. The company claims that this is likely the first Trojan created for iOS, and it can be extremely dangerous as it collects facial recognition data, identity documents, and even SMS messages.
With all this data, hackers use AI-based tools to create deep fakes and gain access to victims' bank accounts. By the time victims realize what has happened, it may be too late.
Initially, the Trojan was distributed through Apple's TestFlight, which allows developers to release beta versions of their apps without going through the App Store review process. However, after Apple removed TestFlight, hackers adopted a more sophisticated approach based on the Mobile Device Management (MDM) profile, which is primarily used to manage enterprise devices.
These profiles allow companies to customize and control many aspects of the system according to their needs. But what hackers do is convince users to install the malicious profile in order to download an app from outside the app store. When this happens, they can collect all the data they need.
According to the report, GoldDigger mainly targets people in Vietnam and Thailand. However, it can also be used to attack users in other parts of the world. Group-IB claims that the Trojan is in an “active stage of development.”
So what's next?
At least for now, it seems that even the latest versions of iOS and iPadOS are still vulnerable to this virus. Group-IB says it has notified Apple about the Trojan, so the company is likely already working on a fix. Right now, the best thing you can do to avoid such attacks is not to install apps from sources you don't trust.
You can find More details about the GoldDigger Trojan here.
picture: Unsplash
FTC: We use automatic affiliate links to earn income. more.
“Certified food guru. Internet maven. Bacon junkie. Tv enthusiast. Avid writer. Gamer. Beeraholic.”
More Stories
Nintendo is launching a music app with themes from Mario and Zelda, and more importantly, a Wii Shop channel
The Google Pixel Tablet 3 will take another step towards replacing your laptop
Apple still excels at building the best computers