Software pirates hijacked Apple technology to put a hacked version of apps on iPhones

Date:

Trending

Software pirates have hijacked technology designed by Apple Inc to distribute hacked versions of Spotify, Angry Birds, Pokemon Go, Minecraft and other popular apps on iPhones, Reuters has found.

- Advertisement -

Illicit software distributors such as TutuApp, Panda Helper, AppValley and TweakBox have found ways to use digital certificates to get access to a program Apple introduced to let corporations distribute business apps to their employees without going through Apple’s tightly controlled App Store.

Using so-called enterprise developer certificates, these pirate operations are providing modified versions of popular apps to consumers, enabling them to stream music without ads and to circumvent fees and rules in games, depriving Apple and legitimate app makers of revenue.

- Advertisement -

By doing so, the pirate app distributors are violating the rules of Apple’s developer programs, which only allow apps to be distributed to the general public through the App Store. Downloading modified versions violates the terms of service of almost all major apps.

TutuApp, Panda Helper, AppValley and TweakBox did not respond to multiple requests for comment.

Apple has no way of tracking the real-time distribution of these certificates, or the spread of improperly modified apps on its phones, but it can cancel the certificates if it finds misuse.

“Developers that abuse our enterprise certificates are in violation of the Apple Developer Enterprise Program Agreement and will have their certificates terminated, and if appropriate, they will be removed from our Developer Program completely,” an Apple spokesperson told Reuters. “We are continuously evaluating the cases of misuse and are prepared to take immediate action.”

After Reuters initially contacted Apple for comment last week, some of the pirates were banned from the system, but within days they were using different certificates and were operational again.

“There’s nothing stopping these companies from doing this again from another team, another developer account,” said Amine Hambaba, head of security at software firm Shape Security.

Apple confirmed a media report on Wednesday that it would require two-factor authentication – using a code sent to a phone as well as a password – to log into all developer accounts by the end of this month, which could help prevent certificate misuse.

Major app makers Spotify Technology SA, Rovio Entertainment Oyj and Niantic Inc have begun to fight back.

Spotify declined to comment on the matter of modified apps, but the streaming music provider did say earlier this month that its new terms of service would crack down on users who are “creating or distributing tools designed to block advertisements” on its service.

Rovio, the maker of Angry Birds mobile games, said it actively works with partners to address infringement “for the benefit of both our player community and Rovio as a business.”

Niantic, which makes Pokemon Go, said players who use pirated apps that enable cheating on its game are regularly banned for violating its terms of service. Microsoft Corp, which owns the creative building game Minecraft, declined to comment.

SIPHONING OFF REVENUE

It is unclear how much revenue the pirate distributors are siphoning away from Apple and legitimate app makers.

TutuApp offers a free version of Minecraft, which costs $6.99 in Apple’s App Store. AppValley offers a version of Spotify’s free streaming music service with the advertisements stripped away.

The distributors make money by charging $13 or more per year for subscriptions to what they calls “VIP” versions of their services, which they say are more stable than the free versions. It is impossible to know how many users buy such subscriptions, but the pirate distributors combined have more than 600,000 followers on Twitter.

Security researchers have long warned that misuse of enterprise developer certificates, which act as digital keys that tell an iPhone a piece of software downloaded from the internet can be trusted and opened. They are the centerpiece of Apple’s program for corporate apps and enable consumers to install apps onto iPhones without Apple’s knowledge.

Apple last month briefly banned Facebook Inc and Alphabet Inc from using enterprise certificates after they used them to distribute data-gathering apps to consumers.

The distributors of pirated apps seen by Reuters are using certificates obtained in the name of legitimate businesses, although it is unclear how. Several pirates have impersonated a subsidiary of China Mobile Ltd. China Mobile did not respond to requests for comment.

Tech news website TechCrunch earlier this week reported that certificate abuse also enabled the distribution of apps for pornography and gambling, both of which are banned from the App Store.

Since the App Store debuted in 2008, Apple has sought to portray the iPhone as safer than rival Android devices because Apple reviews and approves all apps distributed to the devices.

Early on, hackers “jailbroke” iPhones by modifying their software to evade Apple’s controls, but that process voided the iPhone’s warranty and scared off many casual users. The misuse of the enterprise certificates seen by Reuters does not rely on jailbreaking and can be used on unmodified iPhones.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

The Ultimate Guide to Choosing and Using Fonts in Your Design Projects

Fonts play a crucial role in every design project, from branding and web design to print media and beyond. Whether you’re a beginner just...

Predictive Analytics: The Key to Supply Chain Resilience

In today’s interconnected global economy, supply chains are the lifeblood of businesses, weaving intricate networks that span continents, industries, and suppliers. Yet, these networks are inherently vulnerable. For too long, supply chain risk management has been a reactive endeavor—a frantic response to disruptions triggered...

Empowering Growth: Boosting the Robotics Sector with Targeted Support

India's robotics sector is emerging as a key area of technological progress, driving innovation...

Software and Technology Changing the Industry

The advent of software and technological advancements has been a game-changer across various industries....
00:02:53

Canada, Australia Partner to Build $6 Bn Arctic Radar System

In a bid to enhance Arctic and national security, Canada's Prime Minister Mark Carney...

Meta Chief Legal Officer Jennifer Newstead Offloads Shares as Part of Trading Plan

According to regulatory filings, Jennifer Newstead, Chief Legal Officer at Meta Platforms, Inc. (NASDAQ:...

Alphabet Board Member Frances Arnold Increases Stake Following Dividend Allocation

According to a recent regulatory filing, Frances Arnold, a board member at Alphabet Inc.,...

Alphabet COA Amie Thuener O’Toole Increases Stock Holdings

In a filing with the U.S. Securities and Exchange Commission (SEC), Alphabet Inc.’s (NASDAQ...

Jensen Huang Offloads $49.8Mn in Nvidia Shares

Nvidia (NASDAQ: NVDA) CEO and President Jen-Hsun Huang has disclosed the sale of 431,611 company shares, valued at $49.8 million. According to a regulatory filing...

Elon Musk’s X Sues Indian Govt Over Content Regulation Clash

X Corp, an Elon Musk-owned social media firm, sued the Indian government in the...

Why Smart Cities Are the Future of Water Conservation

Water conservation has become an important factor due to climate change and worsened water...

IIT Madras and SPF Partners to Enhance Policy Framework for Indian Startups

Indian Institute of Technology Madras (IIT Madras) has entered into a Memorandum of Understanding...

Alphabet CEO Sundar Pichai Increases Stocks Holdings Amid Dividend Adjustment

According to a regulatory filing with the U.S. Securities and Exchange Commission (SEC), Alphabet...

Layer PR Wins SME News UK Awards, Expands to Bengaluru

Layer PR, a global public relations firm owned by TechGraph, has secured two major awards at the SME News UK Awards as "Most Innovative...

Google Acquires Wiz for $32 Billion in All-Cash Deal

Google LLC, a subsidiary of Alphabet Inc. (NASDAQ: GOOG, GOOGL) has signed a deal to buy Wiz, a New York-based cloud security company, for $32 billion in an all-cash deal. The deal, which needs regulatory approval and standard closing conditions, will bring Wiz into Google...

The Sustainability Imperative: How IT Distribution Is Driving Green Tech Adoption

In today's day and time sustainability is no longer just a corporate commitment, it...

The Future of Digital Payments and Cybersecurity Challenges

The future of digital payments is evolving rapidly, driven by technological advancements, changes in...

The Role of Edge Computing in AI-Powered Cloud Solutions

With businesses including artificial intelligence (AI) in their operations, cloud computing has grown in...

From Startup to Success: Essential Steps for Landscaping Entrepreneurs

Starting a landscaping business is so exciting, blending creativity with the reward of transforming...

‘Canada Ripping Us’: US President Trump Criticizes High Tariffs on Dairy and Lumber

U.S. President Donald Trump on Friday slammed Canada’s high tariffs on American dairy and...

Trump Defends Elon Musk Plan for Federal Job Cuts; Govt Spending ‘Bloated’

Following a meeting with Elon Musk and senior cabinet members, U.S. President Donald Trump...

Demand for plumbers in Oman: which specialists are most in demand?

The demand for skilled plumbers in Oman is steadily increasing due to the country's...

Meta Executive Chris Cox to Sell $13.5 Million in Shares

Meta Platforms (NASDAQ: META) Chief Product Officer Christopher Cox has filed to sell 20,000...

Empowering Communities with Water Tech

This is a major problem worldwide; it affects billions of people in homes, villages,...

IIT Madras and SPF Partners to Enhance Policy Framework for Indian Startups

Indian Institute of Technology Madras (IIT Madras) has entered into a Memorandum of Understanding...

How a Money Back Policy Can Be a Smart Financial Choice?

Creating financial security involves strategic planning because investment decisions form one of the essential...

“We Are Not America”: Canada’s New PM Mark Carney On Trump’s Comment On Making it 51st state

In his first public remarks, Canada's New Prime Minister, Mark Carney, reaffirmed Canada's independence...
00:01:37

UK PM Kier Starmer Abolishes NHS England To Bring Health Services Under Govt Control

British Prime Minister Keir Starmer has announced plans to abolish NHS England and bring...
00:01:09

VIDEO: US President Donald Trump Calls NBC A ‘Worst Network’ On Television

During a press meeting at the Oval Office on Wednesday, US President Donald Trump...

Alphabet CEO Sundar Pichai Increases Stocks Holdings Amid Dividend Adjustment

According to a regulatory filing with the U.S. Securities and Exchange Commission (SEC), Alphabet...

Meta Executive Chris Cox to Sell $13.5 Million in Shares

Meta Platforms (NASDAQ: META) Chief Product Officer Christopher Cox has filed to sell 20,000...

Logistic Startup Picckup Secures $500K in Seed Funding to Expand Electric Fleet

A Mohali-based mid-mile and last-mile logistic startup, Picckup, on Thursday, raised $500K in series...

Empowering Communities with Water Tech

This is a major problem worldwide; it affects billions of people in homes, villages,...