Malware

New iOS malware fakes iPhone shutdown to spy on users

0

Researchers have developed a new technique that fakes a shutdown or reboot of iPhones, preventing malware from being removed and allowing hackers to eavesdrop on microphones and receive sensitive data via a live network connection.

When a malware infects an iOS device, it can be easily removed by restarting the device, which clears the malware from memory.

But, this novel technique hooks the shutdown and reboot process to prevent them from ever happening, allowing malware to achieve persistence as the device is never actually turned off.

This attack named as “NoReboot” does not exploit any flaws on the iOS and depends on human-level deception. So, it cannot be patched by Apple.

Security researchers from ZecOps have developed a trojan proof of concept tool that can inject specially crafted code onto three iOS daemons namely the InCallService, SpringBoard, and Backboardd, to fake a shut down by disabling all audio-visual cues associated with a powered-on device, including the screen, sounds, vibration, the camera indicator, and touch feedback.

The trojan hijacks the shutdown event by hooking the signal sent to the “SpringBoard” (user interface interaction daemon).

The trojan will send a code that will force “SpingBoard” to exit, making the device non-responsive to user input.

Next, the “BackBoardd” daemon is commanded to display the spinning wheel that indicates the shutdown process is underway.

“BackBoardd” is another iOS daemon that logs physical button click and screen touch events with timestamps, so abusing it gives the trojan the power to know when the user attempts to “turn on” the phone.

By monitoring these actions, the user can be deceived to release the off button earlier than they were supposed to, avoiding an actual forced restart.

The user returns to a regular UI with all processes and services running as expected, with no indication that they just went through a simulated reboot.

Zecops has created a video demonstrating the NoReboot technique in action.

Apple introduced a new feature in iOS 15, making it possible for users to locate their iPhones through ‘Find My’ even if they are powered off. This is possible by keeping the Bluetooth LPM chip active and running autonomously even when the iPhone is switched off.

While all user interaction with the device is turned off, the Bluetooth chip continues to show its presence to nearby devices by operating on low-power mode, at intervals larger than the default 15 minutes.

This indicates that you can never trust a device to be entirely powered off, even when you turn off your phone.

Similarly, the “NoReboot” technique makes it impossible to physically detect if an iPhone is off or not as to all outward appearances your device appears to be shut down.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Apple iOS vulnerable to HomeKit doorLock bug

Previous article

Google Docs commenting feature exploited for spear-phishing

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *