CNET reports on the discovery of Windows malware embedded within an iPhone application available through the App Store. But rather than a directed attack at Windows users, the malware appears to have been accidentally included from an infected developer's system. The malware is also relatively old and easily detected by most antivirus software for Windows once the App Store package has been unwrapped.

The malware was first discovered by a user posting in the Apple support forums who noted that a download of Instaquotes-Quotes Cards For Instagram from developer Ilyas Hassani triggered warnings from the ClamXav antivirus software for Mac. While the Windows malware obviously could not harm the user's OS X installation, it was flagged as an infected file posing a danger to Windows systems. After learning about the discovery, CNET performed additional testing on the download to confirm that it was not a false positive.

Since the downloaded .ipa file is a package, these executables could be extracted using the package manager Pacifist, and then more accurately scanned. Afterward, other malware programs like Sophos that initially missed detecting the malware instantly picked it up and described it as "Mal/CoiDung-A," a worm written in visual basic that installs files within the Windows system directory and then modifies the Windows registry to execute the malware when the system is restarted.

Copying the malware to a Windows virtual machine running the latest version of Microsoft Security Essentials resulted in the malware being immediately detected and removed from the system.

instaquotes iantivirus scanIt is unclear exactly how or why the malware came to be included in the App Store package, but it seems almost certain to have been an accidental inclusion. As delivered inside the application package, it appears to pose no harm to Windows users, who would have to decompress the package and manually run the infected file in order to expose themselves to the malware.

The infected application debuted in the App Store on July 19 and is currently still available for download after a temporary price drop from $0.99 to free over the weekend.

Top Rated Comments

outphase Avatar
173 months ago
This serves as a reminder that antivirus software for Mac (and Linux) is primarily for stopping the spread of Windows viruses.
Score: 16 Votes (Like | Disagree)
nuckinfutz Avatar
173 months ago
Get a Mac!!!


I keep reading that Windows doesn't collect virus anymore yet continually I see the
ramifications of believing this.
Score: 13 Votes (Like | Disagree)
sulliweb Avatar
173 months ago
I have to admit I'm more curious than concerned. I thought app development had to be done in X-Code, which only runs on a Mac. If so, the coding and work had to be done on a Mac. That being the case, how would Windows malware, even acidentally, end up in the app itself?

Obviously, I'm not a developer, so I'm sure I'm missing something, just curious as to what...
Score: 7 Votes (Like | Disagree)
haincha Avatar
173 months ago
I am just curious how that happens? The only thing I can think of is that he has BootCamp or something with software to open up mac folder system on Windows. Because, even if the exe filed came on the mac side, it wouldn't be able to replicate itself or put itself into any random folders.

Then, why choose that particular folder? It isn't showing up in every folder path. Even if he says it wasn't deliberate, is it possible to get there, and only there, without it being on purpose?
Score: 4 Votes (Like | Disagree)
AriX Avatar
173 months ago
Sounds like Apple should run a virus check on App Store packages before approving them!

But .ipa files are not packages, as the article indicates, they're just renamed ZIP files. Pacifist should not be necessary to open them; just rename the file to something.zip and double click it.
Score: 3 Votes (Like | Disagree)
Amazing Iceman Avatar
173 months ago
It is very suspicious how it bundled itself in an .ipa file.
Windows viruses usually attach to Windows files known to be executables or have vulnerabilities that allow it to execute.
An .ipa file is totally foreign to Windows, and the locations where the virus installed itself are too much to be a mere coincidence.
Weird... just weird...
Score: 3 Votes (Like | Disagree)

Popular Stories

iOS 26

iOS 26.1 Coming Soon: New Features for Your iPhone and Release Date

Monday October 27, 2025 7:55 am PDT by
The upcoming iOS 26.1 update includes a handful of new features and changes for iPhones, including a toggle for changing the appearance of the Liquid Glass design, "slide to stop" for alarms in the Clock app, and more. Below, we outline key details about iOS 26.1. Release Date Given that Apple has yet to seed an iOS 26.1 Release Candidate, which is typically the final beta version, the...
iOS 26

6 New Things Your iPhone Can Do in iOS 26.1

Wednesday October 29, 2025 4:22 am PDT by
Apple is about to drop iOS 26.1, the first major point release since iOS 26 was rolled out in September, and there are at least six notable changes and improvements to look forward to. We've rounded them up below. Apple has already provided developers and public beta testers with the release candidate version of iOS 26.1, which means Apple will likely roll out the update to all compatible...
maxresdefault

Apple TV 4K Could Still Launch Before 2025 Ends: All the Rumored Features

Monday October 27, 2025 4:51 pm PDT by
Apple is designing an updated version of the Apple TV 4K, and rumors suggest that it could come out sometime in the next couple of months. We're not expecting a major overhaul with design changes, but even a simple chip upgrade will bring major improvements to Apple's set-top box. Subscribe to the MacRumors YouTube channel for more videos. We've rounded up all the latest Apple TV rumors. ...
iOS 26

Apple Seeds iOS 26.1, iPadOS 26.1, and macOS Tahoe 26.1 Release Candidates

Tuesday October 28, 2025 1:07 pm PDT by
Apple today provided developers and public beta testers with the release candidate versions of upcoming iOS 26.1, iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, watchOS 26.1, and visionOS 26.1 updates for testing purposes. The RCs betas come a week after Apple released the fourth betas. The new betas can be downloaded from the Settings app on a compatible device by going to General > Software...
M6 MacBook Pro Feature 1

M6 MacBook Pro: Release Date, Pricing, and What to Expect

Monday October 27, 2025 9:15 am PDT by
Apple this month refreshed the 14-inch MacBook Pro base model with its new M5 chip, and higher-end 14-inch and 16-inch MacBook Pro models with M5 Pro and M5 Max chips are expected to follow in early 2026. However, these machines will represent the final update to the current design, with Apple reportedly developing a completely new version of the MacBook Pro packed with next-generation hardware...
iPhone 17 Pro Cosmic Orange

8 Reasons to Wait for Next Year's iPhone 18 Pro

Thursday October 30, 2025 4:42 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models at the same time, which is why we often get rumored features months ahead of launch. The iPhone 18 series is no different, and we already have a good idea of what to expect for the iPhone 18 Pro and iPhone 18 Pro Max. One thing worth...
macos tahoe

Here Are Apple's Release Notes for macOS Tahoe 26.1

Tuesday October 28, 2025 1:21 pm PDT by
Apple today provided developers and public beta testers with the release candidate version of macOS Tahoe 26.1, which means the update will likely see a public launch next week. The release candidate includes notes on what's in the update, so we have a full picture of the new features that Apple has included. macOS Tahoe 26.1 adds AutoMix support over AirPlay, improved FaceTime audio...
ipad mini 7 feature blue

OLED iPad Mini: Release Date, Pricing, and What to Expect

Wednesday October 29, 2025 7:13 am PDT by
Rumors are stoking excitement for the next-generation iPad mini that Apple is reportedly close to launching. So what should we expect from the successor to the iPad mini 7 that Apple released over a year ago? Read on to find out. Processor and Performance Apple is working on a next-generation version of the iPad mini (codename J510/J511) that features the A19 Pro chip, according to...
iPhone Car Key Kia

Another Vehicle Brand Gaining iPhone Car Keys Support

Tuesday October 28, 2025 5:27 am PDT by
Apple is preparing to bring support for its digital car key feature to Jetour vehicles, according to evidence uncovered on Apple's backend by MacRumors contributor Aaron Perris. Introduced in 2022, Car Keys allows an iPhone or Apple Watch to unlock a vehicle through the Wallet app. A digital version of a car key is stored in Wallet, and unlocking can be done by holding an Apple Watch or...