Malicious iPhone (Prank) Trojan Is Eye-Opener

執筆者
Ryan Naraine
Ryan Naraine
Published: Jan 9, 2008
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

It may be just an innocuous prank, but the confirmed sighting of a malicious Trojan created for unlocked iPhones is a perfect example of the damage that can be done with a clever social engineering attack.

According to warnings from two different anti-virus vendors, a malicious iPhone software package circulating on the Web could cause legitimate third-party applications to be nuked if the Trojan is uninstalled from iPhones.

The malicious package does not cause any damage beyond the risk of removing legitimate applications but, as F-Secure explains, it is a wake-up call for those who have opened their iPhones using a security hole in the system and then installing unverified software without a second thought to what they are doing.

“This time it was an 11-year-old kid playing with XML files who created the Trojan. Next time it might be someone else with more skills and with a specific target.“

According to Symantec researcher Orla Cox, the dubious package was called “iPhone firmware 1.1.3 prep” and touted an an “important system update.” Instead, it could be an irritant to users who load third-party utilities on unlocked iPhones.

“Some of the applications it overwrites are “Erica’s Utilities” (a collection of command-line utilities for the iPhone) and OpenSSH. If the user chooses to uninstall the bogus package, these applications will also be removed. Affected users will need to reinstall these applications.“

I’ve argued before that zeroing in on the iPhone to raise security alarms is a bit of a non-story because businesses should treat the iPhone like every other device that can store data.

Here’s the best advice, from Matasano’s Dave Goldsmith:

“Every device that walks into your organization is just another way for data to leave. Laptops, iPods, cell phones, PDAs and even the dreaded Furby have all gone through this same set of concerns.Yes, somewhere deep inside of every enterprise is a small team of people that has to worry about data management. And yes, every time something like this comes out, they have to write a bunch of policy blocking it. And then they have to start relaxing that policy as the devices become commonplace.If you are responsible for keeping data inside of your organization, for the love of everything that is holy, please don’t spend too much time on the iPhone. Allow us to remind you about all of the data breaches that are happening thanks to insecure wireless access points, tape backups disappearing, wrapping your newspapers in customers’ personal financial information, and stolen laptops.“

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。