After the XcodeGhost malware shook the Apple ecosystem, Palo Alto Networks has identified a new Apple iOS malware and christened it ‘YiSpecter’. So far, it has been found affecting iOS users in China and Taiwan.
The security firm said that the malware attacks both jailbroken and non-jailbroken iOS devices and is the first one that abuses private APIs in the iOS system to “implement malicious functionalities.”
“On infected iOS devices, YiSpecter can download, install and launch arbitrary iOS apps, replace existing apps with those it downloads, hijack other apps’ execution to display advertisements, change Safari’s default search engine, bookmarks and opened pages, and upload device information to the C2 [command and control] server”, Palo Alto Networks explained.
It lists some characteristics about the malware:
- Whether an iPhone is jailbroken or not, the malware can be successfully downloaded and installed
- Even if you manually delete the malware, it will automatically re-appear
- Using third-party tools you can find some strange additional “system apps” on infected phones
- On infected phones, in some cases when the user opens a normal app, a full screen advertisement will show
The researchers found that YiSpecter was spread by Lingdun worm and that main YiSpecter apps were also published on multiple underground app distribution websites. Moreover, it was also detected that the malware’s author tried to directly promote their malicious apps on social networks and in public communities.
Apple says it is aware of the vulnerability and fixed it in iOS 8.4. “This issue only impacts users on older versions of iOS who have also downloaded malware from untrusted sources. We addressed this specific issue in iOS 8.4 and we have also blocked the identified apps that distribute this malware,” Apple told TechWeekEurope. “We encourage customers to stay current with the latest version of iOS for the latest security updates. We also encourage them to only download from trusted sources like the App Store and pay attention to any warnings as they download apps.”
Palo Alto Networks has released IPS and DNS signatures to block YiSpecter’s malicious traffic.


China Reviews Meta’s $2 Billion AI Deal With Manus Amid Technology Control Concerns
Samsung Electronics Hits Record High as AI Momentum Fuels Investor Optimism
Hyundai Motor Shares Surge on Nvidia Partnership Speculation
Ford Targets Level 3 Autonomous Driving by 2028 with New EV Platform and AI Innovations
Nvidia Unveils Rubin Platform to Power Next Wave of AI Infrastructure
TSMC Shares Hit Record High as Goldman Sachs Raises Price Target on AI Demand Outlook
Elon Musk Says X Will Open-Source Its Algorithm Amid EU Scrutiny
Supreme Court to Hear Cisco Appeal on Alien Tort Statute and Human Rights Liability
FCC Approves Expansion of SpaceX Starlink Network With 7,500 New Satellites
Dell Revives XPS Laptop Lineup With New XPS 14 and XPS 16 to Boost Premium PC Demand
Samsung to Double AI-Powered Mobile Devices with Google Gemini in Global AI Race
China’s AI Sector Pushes to Close U.S. Tech Gap Amid Chipmaking Challenges
Samsung Forecasts Strong Q4 Profit on AI-Driven Memory Chip Boom
FCC Exempts Select Foreign-Made Drones From U.S. Import Ban Until 2026
Baidu’s AI Chip Unit Kunlunxin Prepares for Hong Kong IPO to Raise Up to $2 Billion
FDA Limits Regulation of Wearable Devices and Wellness Software, Boosting Health Tech Industry
Lenovo Unveils AI Cloud Gigafactory With NVIDIA and Launches New AI Platform at CES 2026 



