Software pirates hijacked Apple technology to put a hacked version of apps on iPhones

Date:

Trending

Software pirates have hijacked technology designed by Apple Inc to distribute hacked versions of Spotify, Angry Birds, Pokemon Go, Minecraft and other popular apps on iPhones, Reuters has found.

Illicit software distributors such as TutuApp, Panda Helper, AppValley and TweakBox have found ways to use digital certificates to get access to a program Apple introduced to let corporations distribute business apps to their employees without going through Apple’s tightly controlled App Store.

Using so-called enterprise developer certificates, these pirate operations are providing modified versions of popular apps to consumers, enabling them to stream music without ads and to circumvent fees and rules in games, depriving Apple and legitimate app makers of revenue.

By doing so, the pirate app distributors are violating the rules of Apple’s developer programs, which only allow apps to be distributed to the general public through the App Store. Downloading modified versions violates the terms of service of almost all major apps.

TutuApp, Panda Helper, AppValley and TweakBox did not respond to multiple requests for comment.

Apple has no way of tracking the real-time distribution of these certificates, or the spread of improperly modified apps on its phones, but it can cancel the certificates if it finds misuse.

“Developers that abuse our enterprise certificates are in violation of the Apple Developer Enterprise Program Agreement and will have their certificates terminated, and if appropriate, they will be removed from our Developer Program completely,” an Apple spokesperson told Reuters. “We are continuously evaluating the cases of misuse and are prepared to take immediate action.”

After Reuters initially contacted Apple for comment last week, some of the pirates were banned from the system, but within days they were using different certificates and were operational again.

“There’s nothing stopping these companies from doing this again from another team, another developer account,” said Amine Hambaba, head of security at software firm Shape Security.

Apple confirmed a media report on Wednesday that it would require two-factor authentication – using a code sent to a phone as well as a password – to log into all developer accounts by the end of this month, which could help prevent certificate misuse.

Major app makers Spotify Technology SA, Rovio Entertainment Oyj and Niantic Inc have begun to fight back.

Spotify declined to comment on the matter of modified apps, but the streaming music provider did say earlier this month that its new terms of service would crack down on users who are “creating or distributing tools designed to block advertisements” on its service.

Rovio, the maker of Angry Birds mobile games, said it actively works with partners to address infringement “for the benefit of both our player community and Rovio as a business.”

Niantic, which makes Pokemon Go, said players who use pirated apps that enable cheating on its game are regularly banned for violating its terms of service. Microsoft Corp, which owns the creative building game Minecraft, declined to comment.

SIPHONING OFF REVENUE

It is unclear how much revenue the pirate distributors are siphoning away from Apple and legitimate app makers.

TutuApp offers a free version of Minecraft, which costs $6.99 in Apple’s App Store. AppValley offers a version of Spotify’s free streaming music service with the advertisements stripped away.

The distributors make money by charging $13 or more per year for subscriptions to what they calls “VIP” versions of their services, which they say are more stable than the free versions. It is impossible to know how many users buy such subscriptions, but the pirate distributors combined have more than 600,000 followers on Twitter.

Security researchers have long warned that misuse of enterprise developer certificates, which act as digital keys that tell an iPhone a piece of software downloaded from the internet can be trusted and opened. They are the centerpiece of Apple’s program for corporate apps and enable consumers to install apps onto iPhones without Apple’s knowledge.

Apple last month briefly banned Facebook Inc and Alphabet Inc from using enterprise certificates after they used them to distribute data-gathering apps to consumers.

The distributors of pirated apps seen by Reuters are using certificates obtained in the name of legitimate businesses, although it is unclear how. Several pirates have impersonated a subsidiary of China Mobile Ltd. China Mobile did not respond to requests for comment.

Tech news website TechCrunch earlier this week reported that certificate abuse also enabled the distribution of apps for pornography and gambling, both of which are banned from the App Store.

Since the App Store debuted in 2008, Apple has sought to portray the iPhone as safer than rival Android devices because Apple reviews and approves all apps distributed to the devices.

Early on, hackers “jailbroke” iPhones by modifying their software to evade Apple’s controls, but that process voided the iPhone’s warranty and scared off many casual users. The misuse of the enterprise certificates seen by Reuters does not rely on jailbreaking and can be used on unmodified iPhones.

THE SNAPSHOTS, IN YOUR INBOX

Get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

Web3 in Supply Chain: Qila’s CEO Siddharth Ugrankar On Simplifying Blockchain Adoption for Business

Speaking to TechGraph, Siddharth Ugrankar, CEO of Qila.io highlighted the potential of the company's permissioned blockchain workflows and customizable SaaS platform, and how these...

GAMES: Lucky Green Casino Experience

If you’re in search of an exhilarating gaming platform that balances high-stakes thrills with player well-being, Lucky Green Casino has your back. Known for its extensive library of over 500 pokies and an unwavering commitment to fair play, this Australian favorite delivers unmatched online...

Securing the Future of AI: Nuvepro CEO Giridhar LV on Generative AI & a Human-First Approach

During a conversation with TechGraph, Nuvepro Co-founder and CEO Giridhar LV discussed the company's...

Reshaping India’s Farming Future: Balwaan Krishi’s Rohit Bajaj On Driving Agricultural Change

Speaking to TechGraph, Rohit Bajaj, Co-Founder of Balwaan Krishi, discusses the company’s commitment to...

What is RTP and How Does It Affect Slots Winnings?

If you’ve ever played a slot game, you’ve likely come across the term "RTP."...

Relata’s Hyper-Realism: CEO Samudragupta Talukdar On Personalized Home Buying Experiences

In an exclusive conversation with TechGraph, Samudragupta Talukdar, Founder and CEO of Relata, a...

Preparing for a Data-Driven Future: How the GRE Assesses Academic and Analytical Readiness

As sectors such as artificial intelligence (AI) and machine learning continue to grow and...

Exploring the broad appeal of football: from fashion to video games

Football, often called the world's game, goes far beyond the pitch. Its influence extends...

Driving ROI Through AI: CEO Dipal Dutta on RedoQ’s Hybrid Approach to Automation

Speaking to TechGraph, Dipal Dutta, CEO and Founder of RedoQ, explained how the company uses AI/ML-driven modular frameworks to ensure scalable automation while preserving...

Neon54 Casino Review: A Vibrant Gaming Experience

When it comes to striking the perfect balance between entertainment and innovation, Neon54 Casino...

BProTrade: Global Expansion Explained

December 2024 marks a pivotal time in the world of online trading. With Bitcoin...

Yoju Casino Online Review: A Comprehensive Guide for Enthusiasts

Welcome to our in-depth review of Yoju Casino, a vibrant online gaming platform that...
00:08:12

Congress-Led Opposition Calls for Vice President Dhankhar Removal

India Congress lead opposition coalition also known as the INDIA bloc, has formally submitted...
00:01:26

‘Historic day for the Middle East’: PM Netanyahu On Syria’s Assad Regime Collapse

Israeli Prime Minister Benjamin Netanyahu, in a video statement released on Sunday, described the collapse of Syrian President Bashar al-Assad’s regime as a pivotal...

Decentralizing Cardiac Care: Sunfox Technologies’ Rajat Jain on the Spandan ECG Impact

During an interview with the TechGraph editorial team, Sunfox Technologies' Founder and CEO, Rajat Jain, discussed how the company’s Spandan ECG device revolutionizes cardiac care by decentralizing diagnostics and empowering local healthcare providers. He also spoke about Sunfox's mission to make cardiac diagnostics more accessible...

Boson Whitewater, Citadines OMR Chennai to Launch First-of-its-Kind Wastewater Recycling System

Boson Whitewater, a water utility company that converts STP-treated water into high-quality potable water,...

Jungle Camps India Limited Sets IPO Price Band at ₹68-₹72 per Share

Jungle Camps India Limited (JCIL), an India-based ecological hospitality service provider on Thursday announced...

Ensuring Fair Play: AIGF CEO Roland Landers on Promoting Skill-Based Gaming in India

During an interview with TechGraph, Roland Landers, CEO of the All India Gaming Federation...

The Evolution of Gaming: From Traditional to Immersive Online Experiences

Gaming has undergone a remarkable transformation over the decades, evolving from basic, tactile forms...

The Role of Health Plans with Preventive Care in Reducing Financial Risk

In an era where healthcare costs are spiraling and chronic conditions are on the...

What’s next for Battery Recycling: Innovations on the Horizon

India is accelerating its shift toward electrification and renewable energy, bringing battery recycling into...

AI and Workplace Equality for Women in the Digital Era

As society heads toward an age dominated by technology, a key question remains: will...

OPPO, Microsoft Teams up To Bring Advanced AI Productivity To ColorOS 15

OPPO has strengthened its partnership with Microsoft to deliver advanced AI productivity features to...

build3 Launches Second Cohort of Impact Startup Academy

build3, an ecosystem championing startups that merge profit with purpose has today announced the...

Yoju Casino Online Review: A Comprehensive Guide for Enthusiasts

Welcome to our in-depth review of Yoju Casino, a vibrant online gaming platform that...

Atmosphere The Store Makers draws INR 5 Cr in seed round

Mumbai based Atmosphere – The Store Makers on Thursday raised INR 5 crore in...

Plan for Change: UK PM Keir Starmer Outlines Six Point Plans for Housing, NHS, Policing, and More

London, UK — The United Kindom PM and Labour Party leader Keir Starmer on...
00:00:20

Benjamin Netanyahu: Thank You President Donald Trump for Calling Hamas to Release Hostages

Israeli Prime Minister Benjamin Netanyahu on Tuesday expressed his gratitude to U.S. President-Elect Donald...

Titan Intech Ltd To Secure Rs 200 Cr via NCDs

Titan Intech Limited, a BSE-listed company specializing in Embedded Manufacturing Services (EMS) for OEM/ODM...
00:08:12

Congress-Led Opposition Calls for Vice President Dhankhar Removal

India Congress lead opposition coalition also known as the INDIA bloc, has formally submitted...

OPPO, Microsoft Teams up To Bring Advanced AI Productivity To ColorOS 15

OPPO has strengthened its partnership with Microsoft to deliver advanced AI productivity features to...

Order for Health (O4H) Snaps INR 1 Cr In Series Seed Round Funding

Order for Health (O4H), a Bengaluru-based healthy food brand, has secured INR 1 crore...

build3 Launches Second Cohort of Impact Startup Academy

build3, an ecosystem championing startups that merge profit with purpose has today announced the...