You may have seen news today that the Apple App Store in China has been infected with malware. John Smith, principal solutions architect at Veracode commented on the hackers infiltrated the vaunted Apple ecosystem by injecting malicious software into popular Chinese mobile apps.
[su_note note_color=”#ffffcc” text_color=”#00000″]John Smith, Principal Solutions Architect at Veracode :
“In recent years it has seemed that the problem of Mobile Malware was bigger for Android than for iOS. The more rigorous testing regime required before an iOS app can be published has always been considered to be the reason for this difference, but in this case it seems to have fallen short. One very interesting aspect of this incident is that that the developers of the apps had no knowledge that their own code was being used to carry malware – it was the modified development environment (Xcode) that introduced the payload.
This case highlights the importance of testing what you actually provide to your customers, rather than what you think you are providing. Analysing the compiled code for vulnerabilities and malware using technologies such as Binary Static Analysis and App Reputation Testing could have prevented these dangerous apps from ever being published.”[/su_note][su_box title=”About Veracode” style=”noise” box_color=”#336588″]
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.