Software pirates hijacked Apple technology to put a hacked version of apps on iPhones

Date:

Trending

- Advertisement -

Software pirates have hijacked technology designed by Apple Inc to distribute hacked versions of Spotify, Angry Birds, Pokemon Go, Minecraft and other popular apps on iPhones, Reuters has found.

Illicit software distributors such as TutuApp, Panda Helper, AppValley and TweakBox have found ways to use digital certificates to get access to a program Apple introduced to let corporations distribute business apps to their employees without going through Apple’s tightly controlled App Store.

- Advertisement -

Using so-called enterprise developer certificates, these pirate operations are providing modified versions of popular apps to consumers, enabling them to stream music without ads and to circumvent fees and rules in games, depriving Apple and legitimate app makers of revenue.

- Advertisement -

By doing so, the pirate app distributors are violating the rules of Apple’s developer programs, which only allow apps to be distributed to the general public through the App Store. Downloading modified versions violates the terms of service of almost all major apps.

TutuApp, Panda Helper, AppValley and TweakBox did not respond to multiple requests for comment.

- Advertisement -

Apple has no way of tracking the real-time distribution of these certificates, or the spread of improperly modified apps on its phones, but it can cancel the certificates if it finds misuse.

“Developers that abuse our enterprise certificates are in violation of the Apple Developer Enterprise Program Agreement and will have their certificates terminated, and if appropriate, they will be removed from our Developer Program completely,” an Apple spokesperson told Reuters. “We are continuously evaluating the cases of misuse and are prepared to take immediate action.”

After Reuters initially contacted Apple for comment last week, some of the pirates were banned from the system, but within days they were using different certificates and were operational again.

“There’s nothing stopping these companies from doing this again from another team, another developer account,” said Amine Hambaba, head of security at software firm Shape Security.

Apple confirmed a media report on Wednesday that it would require two-factor authentication – using a code sent to a phone as well as a password – to log into all developer accounts by the end of this month, which could help prevent certificate misuse.

Major app makers Spotify Technology SA, Rovio Entertainment Oyj and Niantic Inc have begun to fight back.

Spotify declined to comment on the matter of modified apps, but the streaming music provider did say earlier this month that its new terms of service would crack down on users who are “creating or distributing tools designed to block advertisements” on its service.

Rovio, the maker of Angry Birds mobile games, said it actively works with partners to address infringement “for the benefit of both our player community and Rovio as a business.”

Niantic, which makes Pokemon Go, said players who use pirated apps that enable cheating on its game are regularly banned for violating its terms of service. Microsoft Corp, which owns the creative building game Minecraft, declined to comment.

SIPHONING OFF REVENUE

It is unclear how much revenue the pirate distributors are siphoning away from Apple and legitimate app makers.

TutuApp offers a free version of Minecraft, which costs $6.99 in Apple’s App Store. AppValley offers a version of Spotify’s free streaming music service with the advertisements stripped away.

The distributors make money by charging $13 or more per year for subscriptions to what they calls “VIP” versions of their services, which they say are more stable than the free versions. It is impossible to know how many users buy such subscriptions, but the pirate distributors combined have more than 600,000 followers on Twitter.

Security researchers have long warned that misuse of enterprise developer certificates, which act as digital keys that tell an iPhone a piece of software downloaded from the internet can be trusted and opened. They are the centerpiece of Apple’s program for corporate apps and enable consumers to install apps onto iPhones without Apple’s knowledge.

Apple last month briefly banned Facebook Inc and Alphabet Inc from using enterprise certificates after they used them to distribute data-gathering apps to consumers.

The distributors of pirated apps seen by Reuters are using certificates obtained in the name of legitimate businesses, although it is unclear how. Several pirates have impersonated a subsidiary of China Mobile Ltd. China Mobile did not respond to requests for comment.

Tech news website TechCrunch earlier this week reported that certificate abuse also enabled the distribution of apps for pornography and gambling, both of which are banned from the App Store.

Since the App Store debuted in 2008, Apple has sought to portray the iPhone as safer than rival Android devices because Apple reviews and approves all apps distributed to the devices.

Early on, hackers “jailbroke” iPhones by modifying their software to evade Apple’s controls, but that process voided the iPhone’s warranty and scared off many casual users. The misuse of the enterprise certificates seen by Reuters does not rely on jailbreaking and can be used on unmodified iPhones.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -
Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

Closing India’s Employability Gap with Tech-First Hiring Models

India’s employability challenge is often framed as a skill gap problem. But that’s only half the story. The real gap lies in reach and engagement. As...

Vanguard Group Reports Nvidia Stock Below 5 Percent

The Vanguard Group has reported that it now holds less than a 5% stake in NVIDIA Crop (NASDAQ:NVDA), following an internal realignment of its business structure. The disclosure was made in a regulatory filing dated March 13, 2026, which showed that Vanguard no longer reports...

Vanguard Reports Stake Below 5% in Google’s Alphabet

The Vanguard Group has reported that it now holds less than a 5 percent...

Vanguard Group Reports Ownership Below 5% in Apple Following Internal Realignment

The Vanguard Group has reported that it now holds less than a 5% stake...

NIELIT, SKD University Sign MoU to Expand AI, Cyber Security and Data Science Education in Rajasthan

The National Institute of Electronics and Information Technology (NIELIT) and Shri Khushal Das University...

VES College of Architecture’s Dr. Prof. Anand Achari on Preparing Students for Real Urban Challenges with AI and Design Thinking

Speaking with TechGraph, Principal of VES College of Architecture (VESCOA), Dr. Prof. Anand Achari,...

How NBBL’s New Technology Stack Is Transforming the Future of Payments

India’s digital payments ecosystem has reached a scale that very few countries in the...

NVIDIA CEO Jensen Huang Reports 437,908 Shares Disposal at $181.93 Each

Jensen Huang, President and CEO of Nvidia Corporation (NASDAQ:NVDA), has reported a series of...

Concord Control Systems Secures INR 84 Cr Order From Indian Railways For Loco Wireless Control Systems

Concord Control Systems Limited (BSE: CNCRD), a manufacturer of embedded electronic systems and a critical electronic solutions company, has secured an order worth ₹84.68...

The Future of Shopping: How Apps Are Merging Beauty with Basics

Shopping in India is evolving very fast. Instead of opening different apps for different...

How Anganwadi’s Can Transform India’s Education Foundation

If you step into an Anganwadi on any given morning, what you’ll see is...

Business Structure for Modern Entrepreneurs: What No One Explains Clearly

Modern entrepreneurs often obsess over product-market fit while neglecting the structural bones of their...

Deeptech Startup Newtrace Secures $6.3 Mn in Pre-Series A Round

Bengaluru-based deeptech startup Newtrace has raised $6.3 million (INR 56.93 crore) in a pre-Series...

Mozark Snaps $40 Mn In Series B Round Led by IFC and RMB Capitalworks

Mozark, a Singapore-based company specializing in digital experience testing and measurement, has raised $40 million in a Series B round led by International Finance...

Role of Agentic AI in transforming the real estate landscape

The real estate industry involves a high-stakes ecosystem driven by shifting supply-demand dynamics, regulatory changes, and several other economic factors. Every stage from evaluating land to designing projects, projecting cash flows, managing construction, marketing properties, and supporting post-sales operations involves interdependent decisions that can...

How to Extend Vehicle Lifespan With Proper Maintenance

Extending the lifespan of your vehicle is not only cost-effective but also beneficial for...

Geospatial Intelligence Is Powering India’s Next Wave of Smart Infrastructure

Every day, nearly 500 families in India receive news that will change their lives...

Is India Ready for a Smart Treasury? A Look at Adoption Barriers and Opportunities

Across India, businesses hold thousands of crores in current accounts that earn no interest....

Fraud or Finance? How to Identify Trustworthy Digital Lending Platforms

Digital lending has changed how credit flows in India. According to the IBEF, fintech-led...

What Modern Enterprises Can Expect from CPaaS Platforms in 2026

Over the past two decades, enterprise communication technology has advanced rapidly. Yet the gap...

Choosing glass for perfume bottles? Watch for breakage and leaks

You want your perfume bottle to look great and arrive safely. That’s easiest when...

B2B Logistics platform Mojro Draws $3Mn for IAN Alpha Fund & Others

Bengaluru-based B2B logistics platform Mojro has raised $3 million in a Series A funding...

Peak XV Partners Closes $1.3 Bn in Fresh Capital to Back Startups Across India and APAC

Peak XV Partners (formerly Sequoia Capital India & SEA) has closed $1.3 billion in...

LTM partners with the Indian Institute of Creative Technologies to strengthen creative technology skilling

LTM, a Larsen & Toubro Group company, and the Indian Institute of Creative Technologies...

Business Structure for Modern Entrepreneurs: What No One Explains Clearly

Modern entrepreneurs often obsess over product-market fit while neglecting the structural bones of their...

Understanding Common Car Problems and How to Prevent Them

Keeping your vehicle in top condition requires more than just regular washing or occasional...

From Browsing to Buying: How Multi-Modal AI Is Turning Discovery Into Decision-Making

The digital journey, starting from discovery to decision, has been notably discontinuous through time....

From vineyard to bottle: How blockchain improves trust and sensing in the wine value chain

The wine sector faces increasing consumer demand for transparency, authenticity, and reliable information about...

Why India’s Next Cloud Boom Is Coming from Tier-2 Cities

Historically, the story of India's cloud adoption has been focused on the metro cities...

Deeptech Startup Newtrace Secures $6.3 Mn in Pre-Series A Round

Bengaluru-based deeptech startup Newtrace has raised $6.3 million (INR 56.93 crore) in a pre-Series...

Peak XV Partners Closes $1.3 Bn in Fresh Capital to Back Startups Across India and APAC

Peak XV Partners (formerly Sequoia Capital India & SEA) has closed $1.3 billion in...

Inflection Point Ventures leads INR 4 Cr seed round in Fintech Startup Roopya

West Bengal based no-code ‘lending-as-a-service’ platform Roopya has raised INR 4 Crore in a...

LTM partners with the Indian Institute of Creative Technologies to strengthen creative technology skilling

LTM, a Larsen & Toubro Group company, and the Indian Institute of Creative Technologies...