Software pirates hijacked Apple technology to put a hacked version of apps on iPhones

Date:

Trending

- Advertisement -

Software pirates have hijacked technology designed by Apple Inc to distribute hacked versions of Spotify, Angry Birds, Pokemon Go, Minecraft and other popular apps on iPhones, Reuters has found.

Illicit software distributors such as TutuApp, Panda Helper, AppValley and TweakBox have found ways to use digital certificates to get access to a program Apple introduced to let corporations distribute business apps to their employees without going through Apple’s tightly controlled App Store.

Using so-called enterprise developer certificates, these pirate operations are providing modified versions of popular apps to consumers, enabling them to stream music without ads and to circumvent fees and rules in games, depriving Apple and legitimate app makers of revenue.

By doing so, the pirate app distributors are violating the rules of Apple’s developer programs, which only allow apps to be distributed to the general public through the App Store. Downloading modified versions violates the terms of service of almost all major apps.

TutuApp, Panda Helper, AppValley and TweakBox did not respond to multiple requests for comment.

- Advertisement -

Apple has no way of tracking the real-time distribution of these certificates, or the spread of improperly modified apps on its phones, but it can cancel the certificates if it finds misuse.

“Developers that abuse our enterprise certificates are in violation of the Apple Developer Enterprise Program Agreement and will have their certificates terminated, and if appropriate, they will be removed from our Developer Program completely,” an Apple spokesperson told Reuters. “We are continuously evaluating the cases of misuse and are prepared to take immediate action.”

After Reuters initially contacted Apple for comment last week, some of the pirates were banned from the system, but within days they were using different certificates and were operational again.

“There’s nothing stopping these companies from doing this again from another team, another developer account,” said Amine Hambaba, head of security at software firm Shape Security.

- Advertisement -

Apple confirmed a media report on Wednesday that it would require two-factor authentication – using a code sent to a phone as well as a password – to log into all developer accounts by the end of this month, which could help prevent certificate misuse.

Major app makers Spotify Technology SA, Rovio Entertainment Oyj and Niantic Inc have begun to fight back.

Spotify declined to comment on the matter of modified apps, but the streaming music provider did say earlier this month that its new terms of service would crack down on users who are “creating or distributing tools designed to block advertisements” on its service.

Rovio, the maker of Angry Birds mobile games, said it actively works with partners to address infringement “for the benefit of both our player community and Rovio as a business.”

Niantic, which makes Pokemon Go, said players who use pirated apps that enable cheating on its game are regularly banned for violating its terms of service. Microsoft Corp, which owns the creative building game Minecraft, declined to comment.

SIPHONING OFF REVENUE

It is unclear how much revenue the pirate distributors are siphoning away from Apple and legitimate app makers.

TutuApp offers a free version of Minecraft, which costs $6.99 in Apple’s App Store. AppValley offers a version of Spotify’s free streaming music service with the advertisements stripped away.

The distributors make money by charging $13 or more per year for subscriptions to what they calls “VIP” versions of their services, which they say are more stable than the free versions. It is impossible to know how many users buy such subscriptions, but the pirate distributors combined have more than 600,000 followers on Twitter.

Security researchers have long warned that misuse of enterprise developer certificates, which act as digital keys that tell an iPhone a piece of software downloaded from the internet can be trusted and opened. They are the centerpiece of Apple’s program for corporate apps and enable consumers to install apps onto iPhones without Apple’s knowledge.

Apple last month briefly banned Facebook Inc and Alphabet Inc from using enterprise certificates after they used them to distribute data-gathering apps to consumers.

The distributors of pirated apps seen by Reuters are using certificates obtained in the name of legitimate businesses, although it is unclear how. Several pirates have impersonated a subsidiary of China Mobile Ltd. China Mobile did not respond to requests for comment.

Tech news website TechCrunch earlier this week reported that certificate abuse also enabled the distribution of apps for pornography and gambling, both of which are banned from the App Store.

Since the App Store debuted in 2008, Apple has sought to portray the iPhone as safer than rival Android devices because Apple reviews and approves all apps distributed to the devices.

Early on, hackers “jailbroke” iPhones by modifying their software to evade Apple’s controls, but that process voided the iPhone’s warranty and scared off many casual users. The misuse of the enterprise certificates seen by Reuters does not rely on jailbreaking and can be used on unmodified iPhones.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -
Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

From IP to Global Leadership: Aum Ventures’ Chetan Mehta on India’s Next Deeptech Breakout Companies

Speaking with TechGraph, Chetan Mehta, Founding Partner at Aum Ventures, outlined why deeptech remains one of the most underpriced opportunities in India’s startup ecosystem...

How Machine Learning Is Redefining Short-Term Borrowing for Tech-Savvy Consumers

Short-term lending has long relied on limited snapshots of a borrower’s history. That approach often left gaps, especially for people with thin credit files or recent financial shifts. Machine learning changes the equation by pulling in wider signals such as payment patterns from utility...

Why Players Buy LoL Boost and How the Process Works

If you’re researching why players buy lol boost, you’re usually trying to understand two...

CasinoBonusesFinder UK: how filters, Telegram alerts and real bonus matching work in practice

Anyone who has spent serious time on casino bonus hunting knows the drill. You...

The Importance of Keeping Up to Date With Auto Maintenance

Auto maintenance is one of the most important responsibilities that comes with owning a...

PatexOne: Could This Platform Be Smarter Than Your Impulses?

Australian investors are used to platforms that shout about leverage and “opportunity”. PatexOne takes...

India’s Air Crisis Needs a Deeptech Answer, Not a Consumer Gadget

Twenty years ago, an air conditioner in an Indian home was a luxury. Today...

India’s Cloud Cost Crisis: Why Startups Are Rethinking Their Tech Stack

Over the last ten years, startups in India have experienced an incredible boom driven...

The Detroit Region’s Role in Modern Global Supply Chains

As global commerce continues to expand its reach, the Detroit region has emerged as a pivotal player in modern supply chains. Strategically positioned along...

Top No-KYC Crypto Casino Sites in 2026

Most online casinos demand a lot of personal information from you before you can...

Redrob AI Launches Professional AI Platform for India’s Workforce

In a bid to help students and professionals navigate an increasingly fragmented digital work...

The Business of Recycling: Profit, Waste, and Sustainability

The business of recycling stands at the intersection of environmental responsibility and economic opportunity....

Why Resume-Based Hiring Is Failing India’s Workforce

India needs a shift from credential-first hiring to skill-first validation

Why BFSI Is Moving from AI Experiments to AI Systems

For the past few years, Artificial Intelligence in banking, financial services, and insurance has been all about trying new things. Organizations started projects to...

Capabilities Over Credentials: Scrabble’s Naveen Tiwari on the Changing Nature of Leadership Hiring

Speaking with TechGraph, Naveen Tiwari, Co-Founder of Scrabble, discussed how leadership hiring is shifting from a credentials-led approach to one focused on demonstrated capabilities, and how organisations are increasingly seeking executives who can create measurable impact from the outset. Tiwari also highlighted how Scrabble uses...

From Intuition to Analysis: How AI Is Becoming Every CEO’s Second Brain

Most CEOs are making important decisions with partial information. The challenge is not just...

Rethinking Executive Search: Venator Search Partners’ Deepraditya Datta on Leadership Hiring in a Changing Talent Market

In an interview with TechGraph, Deepraditya Datta, Founder and Managing Director of Venator Search...

AI and Fake Content: Can Technology Win the Battle Against Misinformation?

Artificial Intelligence has transformed how content is created, manipulated, and distributed at scale. News,...

Why Micro Learning at 3 Minutes Works Better Than Lectures at 3 Hours

In the fast-moving world of digital education, there is one myth that continues to...

More Than Just a Scratch: The Importance of Windshield Care

Maintaining your vehicle’s windshield often appears as a seemingly minor task that can easily...

The world’s largest crypto market is building in the dark

India remains one of the few significant economies without a comprehensive crypto and stablecoin...

Beyond Nvidia: The Hidden Winners of the AI Stock Rally

Nvidia stock (NASDAQ:NVDA) has returned roughly 1,200% since ChatGPT launched in late 2022. Most...

What PM Modi’s Appeal to Avoid Gold Buying Could Mean for India’s Jewellery Economy

When Prime Minister Narendra Modi recently urged citizens to avoid purchasing gold for a...

Serhii Tokarev Spoke About The Third Season Of The Generation H Accelerator

Serhii Tokarev spoke about the Generation H 3.0 HealthTech accelerator, which is opening applications...

The Business of Recycling: Profit, Waste, and Sustainability

The business of recycling stands at the intersection of environmental responsibility and economic opportunity....

“Budget should focus on reducing taxes on capital gains,” Says Abhishek Gupta of Hex N Bit

Speaking in the upcoming Union Budget 2021, Abhishek Gupta, Founder, and CEO, Hex N...

“China is a Global thief” Rep. Tom Rice on Uyghur Forced Labor Prevention Act

Speaking at the House on Uyghur Forced Labor Prevention Act, Rep. Tom Rice (R-SC)...

How AI is Rewriting the Economics of India’s $300 Bn IT Services Sector

When Microsoft CEO Satya Nadella recently disclosed that artificial intelligence now generates nearly 30...

Why India Must Own Its Education Intelligence Stack

India has rapidly digitised large parts of its education ecosystem over the last decade....

Why Resume-Based Hiring Is Failing India’s Workforce

India needs a shift from credential-first hiring to skill-first validation

Alphabet Discloses $2.14 Billion in Public Equity Holdings as of June 30

Alphabet Inc. disclosed $2.14 billion in equity securities held across 39 positions as of...

The Role of Edtech in Addressing Equity Gaps in Higher Education

In the fast-paced world of EdTech today, the opportunity to bridge educational gaps and...

India to generate $100 bn from telephonic investments

India expects to attract $100 billion in investments in the telecom sector, a union...