CNET reports on the discovery of Windows malware embedded within an iPhone application available through the App Store. But rather than a directed attack at Windows users, the malware appears to have been accidentally included from an infected developer's system. The malware is also relatively old and easily detected by most antivirus software for Windows once the App Store package has been unwrapped.

The malware was first discovered by a user posting in the Apple support forums who noted that a download of Instaquotes-Quotes Cards For Instagram from developer Ilyas Hassani triggered warnings from the ClamXav antivirus software for Mac. While the Windows malware obviously could not harm the user's OS X installation, it was flagged as an infected file posing a danger to Windows systems. After learning about the discovery, CNET performed additional testing on the download to confirm that it was not a false positive.

Since the downloaded .ipa file is a package, these executables could be extracted using the package manager Pacifist, and then more accurately scanned. Afterward, other malware programs like Sophos that initially missed detecting the malware instantly picked it up and described it as "Mal/CoiDung-A," a worm written in visual basic that installs files within the Windows system directory and then modifies the Windows registry to execute the malware when the system is restarted.

Copying the malware to a Windows virtual machine running the latest version of Microsoft Security Essentials resulted in the malware being immediately detected and removed from the system.

instaquotes iantivirus scanIt is unclear exactly how or why the malware came to be included in the App Store package, but it seems almost certain to have been an accidental inclusion. As delivered inside the application package, it appears to pose no harm to Windows users, who would have to decompress the package and manually run the infected file in order to expose themselves to the malware.

The infected application debuted in the App Store on July 19 and is currently still available for download after a temporary price drop from $0.99 to free over the weekend.

Top Rated Comments

outphase Avatar
176 months ago
This serves as a reminder that antivirus software for Mac (and Linux) is primarily for stopping the spread of Windows viruses.
Score: 16 Votes (Like | Disagree)
nuckinfutz Avatar
176 months ago
Get a Mac!!!


I keep reading that Windows doesn't collect virus anymore yet continually I see the
ramifications of believing this.
Score: 13 Votes (Like | Disagree)
sulliweb Avatar
176 months ago
I have to admit I'm more curious than concerned. I thought app development had to be done in X-Code, which only runs on a Mac. If so, the coding and work had to be done on a Mac. That being the case, how would Windows malware, even acidentally, end up in the app itself?

Obviously, I'm not a developer, so I'm sure I'm missing something, just curious as to what...
Score: 7 Votes (Like | Disagree)
haincha Avatar
176 months ago
I am just curious how that happens? The only thing I can think of is that he has BootCamp or something with software to open up mac folder system on Windows. Because, even if the exe filed came on the mac side, it wouldn't be able to replicate itself or put itself into any random folders.

Then, why choose that particular folder? It isn't showing up in every folder path. Even if he says it wasn't deliberate, is it possible to get there, and only there, without it being on purpose?
Score: 4 Votes (Like | Disagree)
AriX Avatar
176 months ago
Sounds like Apple should run a virus check on App Store packages before approving them!

But .ipa files are not packages, as the article indicates, they're just renamed ZIP files. Pacifist should not be necessary to open them; just rename the file to something.zip and double click it.
Score: 3 Votes (Like | Disagree)
Amazing Iceman Avatar
176 months ago
It is very suspicious how it bundled itself in an .ipa file.
Windows viruses usually attach to Windows files known to be executables or have vulnerabilities that allow it to execute.
An .ipa file is totally foreign to Windows, and the locations where the virus installed itself are too much to be a mere coincidence.
Weird... just weird...
Score: 3 Votes (Like | Disagree)

Popular Stories

iphone 17 models

No iPhone 18 Launch This Year, Reports Suggest

Thursday January 1, 2026 8:43 am PST by
Apple is not expected to release a standard iPhone 18 model this year, according to a growing number of reports that suggest the company is planning a significant change to its long-standing annual iPhone launch cycle. Despite the immense success of the iPhone 17 in 2025, the iPhone 18 is not expected to arrive until the spring of 2027, leaving the iPhone 17 in the lineup as the latest...
duolingo ad live activity

Duolingo Used iPhone's Dynamic Island to Display Ads, Violating Apple Design Guidelines

Friday January 2, 2026 1:36 pm PST by
Language learning app Duolingo has apparently been using the iPhone's Live Activity feature to display ads on the Lock Screen and the Dynamic Island, which violates Apple's design guidelines. According to multiple reports on Reddit, the Duolingo app has been displaying an ad for a "Super offer," which is Duolingo's paid subscription option. Apple's guidelines for Live Activity state that...
Clicks Communicator Feature

'Clicks Communicator' Unveiled — Will You Carry This With Your iPhone?

Friday January 2, 2026 6:35 am PST by
The company behind the BlackBerry-like Clicks Keyboard accessory for the iPhone today unveiled a new Android 16 smartphone called the Clicks Communicator. The purpose-built device is designed to be used as a second phone alongside your iPhone, with the intended focus being communication over content consumption. It runs a custom Android launcher that offers a curated selection of messaging...
Low Cost MacBook Feature A18 Pro

Low-Price 12.9-Inch MacBook With A18 Pro Chip Reportedly Launching Early This Year

Friday January 2, 2026 9:08 am PST by
Apple plans to introduce a 12.9-inch MacBook in spring 2026, according to TrendForce. In a press release this week, the Taiwanese research firm said this MacBook will be aimed at the entry-level to mid-range market, with "competitive pricing." TrendForce did not share any further details about this MacBook, but the information that it shared lines up with several rumors about a more...
Low Cost A18 Pro MacBook Feature Pink

Apple's 2026 Low-Cost A18 Pro MacBook: What We Know So Far

Friday January 2, 2026 4:33 pm PST by
Apple is planning to release a low-cost MacBook in 2026, which will apparently compete with more affordable Chromebooks and Windows PCs. Apple's most affordable Mac right now is the $999 MacBook Air, and the upcoming low-cost MacBook is expected to be cheaper. Here's what we know about the low-cost MacBook so far. Size Rumors suggest the low-cost MacBook will have a display that's around 13 ...
Apple Fitness Plus hero

Apple Announces New Fitness+ Workout Programs, Strava Challenge, and More

Friday January 2, 2026 6:43 am PST by
Apple today announced a number of updates to Apple Fitness+ and activity with the Apple Watch. The key announcements include: New Year limited-edition award: Users can win the award by closing all three Activity Rings for seven days in a row in January. "Quit Quitting" Strava challenge: Available in Strava throughout January, users who log 12 workouts anytime in the month will win an ...
Mac Pro Feature Blue

What's Happening With the Mac Pro?

Wednesday December 31, 2025 9:59 am PST by
Apple hasn't updated the Mac Pro since 2023, and according to recent rumors, there's no update coming in the near future. In fact, Apple might be finished with the Mac Pro. Bloomberg recently said that the Mac Pro is "on the back burner" and has been "largely written off" by Apple. Apple apparently views the more compact Mac Studio as the ideal high-end pro-level desktop, and it has almost...