iOS/AdThief.A!tr

description-logoAnalysis

iOS/AdThief.A!tr targets jailbroken iOS mobile phones or targets. The malware redirects the revenue of advertisement viewed on the infected device to the attacker. It does not cause any hard to the end-user, but steals revenue which is intended to application developers.

Technical Details
iOS/AdThief.A!tr only works on jailbroken iOS platforms. It implements a Cydia substrate extension which steals/hijacks advertisement revenues. Cydia Substrate is a platform to easily modify software, even without its source code. A substrate 'extension' basically loads hooks into the processes to modify.
The malware consists of two files:

  • spad.dylib: a dynamic library, which implements the substrate extension.
  • spad.plist: to inject the extension in all applications using com.apple.UIKit

To modify a given component, Cydia Substrate exports a function named MSHookMessageEx. The malware calls MSHookMessageEx and implements hooks for numerous advertisement kits. The hooks modify the partner/delegate/publisher identifier so that viewing that ad does not generate revenue for the legitimate person, but to the new person (attacker) referenced by the modified identifier.
The malware hijacks the following ad kits:
  • YouMi
  • Sina Weibo
  • VPON
  • UMeng
  • MobClick
  • AdSage
  • MdotM
  • InMobi
  • Domob
  • AdWhirl
  • AdsMogo
  • Google Mobile Ads
  • AderMob
  • Komli Mobil
  • GuoHeAD

recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
    FortiClient Systems
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extreme
FortiClient
Extended
FortiMail
Extended
FortiSandbox
Extended
FortiWeb
Extended
Web Application Firewall
Extended
FortiIsolator
Extended
FortiDeceptor
Extended
FortiEDR