What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
AceDeceiver was an iOS malware family that used flaws in Apple’s FairPlay purchase-authorization process to install malicious apps even on devices that were not jailbroken. Reported by Palo Alto Networks Unit 42 in March 2016, it involved three wallpaper-themed apps that had appeared in the official App Store and PC software that replayed captured authorization material.
What was AceDeceiver?
AceDeceiver was a malware campaign documented by Palo Alto Networks Unit 42 on March 16, 2016. Rather than relying on a jailbreak or the enterprise certificates used by some earlier iOS malware, its installation method abused design flaws in FairPlay, Apple’s digital-rights-management system. Unit 42 described it as the first iOS malware it had seen use those FairPlay flaws to install malicious apps on jailbroken and non-jailbroken devices alike. Unit 42’s report is the primary account.
How did the FairPlay attack work?
In Apple’s normal computer-assisted app installation flow, an iOS device checks that an app was purchased. AceDeceiver’s operators took advantage of that authorization exchange: they bought an app, intercepted and saved its authorization code, then used PC software designed to imitate iTunes. The software could make a device accept an app as though the victim had purchased it.
Because the trick targeted purchase authorization rather than a jailbreak or enterprise certificate, a device did not have to be jailbroken for this described installation path to work. The weakness was in how the authorization process could be manipulated—not proof that every iPhone was infected or that every installation of an app was unsafe. Unit 42 explained the FairPlay man-in-the-middle technique.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
Which App Store apps were involved?
Unit 42 identified three apps presented as wallpaper tools. Its report records their release dates, bundle IDs and listed App Store regions as follows:
| App name | Reported release date | Bundle ID | Stores listed in the report |
|---|---|---|---|
| 壁纸助手 | July 10, 2015 | com.aisi.aisiring |
Hong Kong and New Zealand |
| AS Wallpaper | November 7, 2015 | com.aswallpaper.mito |
United States |
| i4picture | January 30, 2016 | com.i4.picture |
United States and United Kingdom |
The report says the apps were updated after their initial acceptance and that the campaign bypassed Apple’s code review seven times. That figure describes the review bypasses reported by Unit 42 in 2016, not a count of currently available apps. Unit 42’s app analysis gives the app details.
Rank #2
How did the campaign hide its behavior?
The apps contacted tool.verify.i4[.]cn and could show either a malicious third-party app-store interface or a harmless wallpaper interface, depending on the server response. During Unit 42’s February 2016 analysis, the server returned the malicious interface only to IP addresses in mainland China. The researchers also said reviewers may have been deliberately shown the benign interface.
- Regional targeting: App Store submissions were limited to selected regions.
- Device tracking: The apps uploaded device identifiers and remembered devices previously seen outside China.
- Context-sensitive naming: The displayed app name could vary according to the App Store page, iOS language and device context.
- Conditional interface: Server responses determined whether the app presented its wallpaper function or a third-party store.
Together, these controls made the malicious behavior less likely to appear in front of reviewers or researchers. Contemporary reporting by MacRumors also described the China-focused campaign and wallpaper disguises.
Was AceDeceiver removed from the App Store?
Yes. Unit 42 reported that Apple had removed all three identified apps by the end of February 2016. Removing those App Store listings did not itself eliminate the FairPlay weakness or every copy of the PC-side installation software. The captured authorization material and PC tooling could still be used to install malicious apps outside those listings, according to the report. Unit 42’s account distinguishes removal of the apps from the underlying installation technique.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Historical indicators and what they establish
Unit 42 published historical command-and-control domains including tool.verify.i4[.]cn, auth3.i4[.]cn and buy.app.i4[.]cn, as well as hashes for Windows components and several iOS samples. These are artifacts from the 2016 investigation. They should be checked against a current threat-intelligence feed before being used for blocking or incident response; their publication does not establish that the infrastructure is active today. The report lists the indicators and sample details.
Rank #4
The available reporting establishes AceDeceiver’s historical mechanism, named apps and evasion approach. It does not establish present-day prevalence, current command-and-control activity, the exposure of current iOS versions or any security vendor’s current detection performance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

