After the XcodeGhost malware shook the Apple ecosystem, Palo Alto Networks has identified a new Apple iOS malware and christened it ‘YiSpecter’. So far, it has been found affecting iOS users in China and Taiwan.
The security firm said that the malware attacks both jailbroken and non-jailbroken iOS devices and is the first one that abuses private APIs in the iOS system to “implement malicious functionalities.”
“On infected iOS devices, YiSpecter can download, install and launch arbitrary iOS apps, replace existing apps with those it downloads, hijack other apps’ execution to display advertisements, change Safari’s default search engine, bookmarks and opened pages, and upload device information to the C2 [command and control] server”, Palo Alto Networks explained.
It lists some characteristics about the malware:
- Whether an iPhone is jailbroken or not, the malware can be successfully downloaded and installed
- Even if you manually delete the malware, it will automatically re-appear
- Using third-party tools you can find some strange additional “system apps” on infected phones
- On infected phones, in some cases when the user opens a normal app, a full screen advertisement will show
The researchers found that YiSpecter was spread by Lingdun worm and that main YiSpecter apps were also published on multiple underground app distribution websites. Moreover, it was also detected that the malware’s author tried to directly promote their malicious apps on social networks and in public communities.
Apple says it is aware of the vulnerability and fixed it in iOS 8.4. “This issue only impacts users on older versions of iOS who have also downloaded malware from untrusted sources. We addressed this specific issue in iOS 8.4 and we have also blocked the identified apps that distribute this malware,” Apple told TechWeekEurope. “We encourage customers to stay current with the latest version of iOS for the latest security updates. We also encourage them to only download from trusted sources like the App Store and pay attention to any warnings as they download apps.”
Palo Alto Networks has released IPS and DNS signatures to block YiSpecter’s malicious traffic.


Google Disrupts Major Residential Proxy Network IPIDEA
Meta Stock Surges After Q4 2025 Earnings Beat and Strong Q1 2026 Revenue Outlook Despite Higher Capex
Elon Musk’s SpaceX Acquires xAI in Historic Deal Uniting Space and Artificial Intelligence
Amazon Stock Dips as Reports Link Company to Potential $50B OpenAI Investment
Microsoft AI Spending Surge Sparks Investor Jitters Despite Solid Azure Growth
Palantir Stock Jumps After Strong Q4 Earnings Beat and Upbeat 2026 Revenue Forecast
Federal Judge Signals Possible Dismissal of xAI Lawsuit Against OpenAI
SoftBank and Intel Partner to Develop Next-Generation Memory Chips for AI Data Centers
SpaceX Updates Starlink Privacy Policy to Allow AI Training as xAI Merger Talks and IPO Loom
SpaceX Reports $8 Billion Profit as IPO Plans and Starlink Growth Fuel Valuation Buzz
Elon Musk’s Empire: SpaceX, Tesla, and xAI Merger Talks Spark Investor Debate
Apple Earnings Beat Expectations as iPhone Sales Surge to Four-Year High
Rewardy Wallet and 1inch Collaborate to Simplify Multi-Chain DeFi Swaps with Native Token Gas Payments
Nvidia’s $100 Billion OpenAI Investment Faces Internal Doubts, Report Says
Samsung Electronics Posts Record Q4 2025 Profit as AI Chip Demand Soars
Pentagon and Anthropic Clash Over AI Safeguards in National Security Use
Apple Faces Margin Pressure as Memory Chip Prices Surge Amid AI Boom 



