What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AceDeceiver was an iOS malware family that used flaws in Apple’s FairPlay purchase-authorization process to install malicious apps even on devices that were not jailbroken. Reported by Palo Alto Networks Unit 42 in March 2016, it involved three wallpaper-themed apps that had appeared in the official App Store and PC software that replayed captured authorization material.

What was AceDeceiver?

AceDeceiver was a malware campaign documented by Palo Alto Networks Unit 42 on March 16, 2016. Rather than relying on a jailbreak or the enterprise certificates used by some earlier iOS malware, its installation method abused design flaws in FairPlay, Apple’s digital-rights-management system. Unit 42 described it as the first iOS malware it had seen use those FairPlay flaws to install malicious apps on jailbroken and non-jailbroken devices alike. Unit 42’s report is the primary account.

How did the FairPlay attack work?

In Apple’s normal computer-assisted app installation flow, an iOS device checks that an app was purchased. AceDeceiver’s operators took advantage of that authorization exchange: they bought an app, intercepted and saved its authorization code, then used PC software designed to imitate iTunes. The software could make a device accept an app as though the victim had purchased it.

Because the trick targeted purchase authorization rather than a jailbreak or enterprise certificate, a device did not have to be jailbroken for this described installation path to work. The weakness was in how the authorization process could be manipulated—not proof that every iPhone was infected or that every installation of an app was unsafe. Unit 42 explained the FairPlay man-in-the-middle technique.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which App Store apps were involved?

Unit 42 identified three apps presented as wallpaper tools. Its report records their release dates, bundle IDs and listed App Store regions as follows:

App name Reported release date Bundle ID Stores listed in the report
壁纸助手 July 10, 2015 com.aisi.aisiring Hong Kong and New Zealand
AS Wallpaper November 7, 2015 com.aswallpaper.mito United States
i4picture January 30, 2016 com.i4.picture United States and United Kingdom

The report says the apps were updated after their initial acceptance and that the campaign bypassed Apple’s code review seven times. That figure describes the review bypasses reported by Unit 42 in 2016, not a count of currently available apps. Unit 42’s app analysis gives the app details.

How did the campaign hide its behavior?

The apps contacted tool.verify.i4[.]cn and could show either a malicious third-party app-store interface or a harmless wallpaper interface, depending on the server response. During Unit 42’s February 2016 analysis, the server returned the malicious interface only to IP addresses in mainland China. The researchers also said reviewers may have been deliberately shown the benign interface.

  • Regional targeting: App Store submissions were limited to selected regions.
  • Device tracking: The apps uploaded device identifiers and remembered devices previously seen outside China.
  • Context-sensitive naming: The displayed app name could vary according to the App Store page, iOS language and device context.
  • Conditional interface: Server responses determined whether the app presented its wallpaper function or a third-party store.

Together, these controls made the malicious behavior less likely to appear in front of reviewers or researchers. Contemporary reporting by MacRumors also described the China-focused campaign and wallpaper disguises.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was AceDeceiver removed from the App Store?

Yes. Unit 42 reported that Apple had removed all three identified apps by the end of February 2016. Removing those App Store listings did not itself eliminate the FairPlay weakness or every copy of the PC-side installation software. The captured authorization material and PC tooling could still be used to install malicious apps outside those listings, according to the report. Unit 42’s account distinguishes removal of the apps from the underlying installation technique.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Historical indicators and what they establish

Unit 42 published historical command-and-control domains including tool.verify.i4[.]cn, auth3.i4[.]cn and buy.app.i4[.]cn, as well as hashes for Windows components and several iOS samples. These are artifacts from the 2016 investigation. They should be checked against a current threat-intelligence feed before being used for blocking or incident response; their publication does not establish that the infrastructure is active today. The report lists the indicators and sample details.

The available reporting establishes AceDeceiver’s historical mechanism, named apps and evasion approach. It does not establish present-day prevalence, current command-and-control activity, the exposure of current iOS versions or any security vendor’s current detection performance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.