Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

iOS Malware detected

Researchers at Trend Micro have detected an Espionage tool acting as a Spyware in iOS devices.

Trend Micro posted a report on a continued investigation on Operation Pawn Storm, which is an active economic and political cyber-espionage operation that targets a wide range of entities, like the military, governments, defense industries, and the media. In this report, the researchers unraveled an iOS Malware responsible for infecting many iOS devices and working as a Spyware for cybercriminals. The pawn tool is built especially for targetted attacks on iOS /Apple users.

According to Trend Micro, this pawn tool is among the advanced malware which is used by the cybercriminals as their next pawn.

"We believe the iOS malware gets installed on already compromised systems, and it is very similar to next stage SEDNIT malware we have found for Microsoft Windows systems." , the report said.

Two suspicious iOS Applications have been found in this regard.

First: XAgent (detected as IOS_XAGENT.A)

Second: a legitimate iOS game, MadCap (detected as IOS_ XAGENT.B)

After an analysis, both apps were found to be related to SEDNIT (operation pawn storm).

Technical Details

The app is designed to collect all kind of information on an iOS device. It is able to perform the following routines:

  • Collect text messages
  • Get contact lists
  • Get pictures
  • Collect geo-location data
  • Start voice recording
  • Get a list of installed apps
  • Get a list of processes
  • Get the Wi-Fi status

Also, the app uses HTTP protocol for sending and receiving messages using POST and GET methods respectively. Malware app produces colored HTML coded logs, to be easily read by human operators.

All other technical details related to both the apps can be found at the Trend Micro official blog.

Operation Pawn Storm

Operation Pawn Storm is an ongoing campaign started by cybercriminals to collect information worldwide. Various espionage tools have been used in this campaign such as SEDNIT. This campaign aims at collecting information from Government, Defense and Military organisations.

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.