'XcodeGhost' Malware Attack in 2015 Impacted 128 Million iOS Users, According to Trial Documents

Back in 2015, a malware-infected version of Xcode began circulating in China, and malware-ridden "XcodeGhost" apps made their way into Apple's App Store and past the ‌App Store‌ review team.

XcodeGhost Featured1
There were more than 50 known infected iOS apps at the time, including major apps like WeChat, NetEase, and Didi Taxi, with up to 500 million iOS users potentially impacted. It's been a long time since the XcodeGhost attack, but Apple's trial with Epic is surfacing new details.

Trial documents highlighted by Motherboard indicate that a total of 128 million users downloaded apps with the XcodeGhost malware, including 18 million users in the United States.

XcodeGhost was one of the biggest attacks against iPhone users to date due to the number of ‌iPhone‌ users that were impacted. The 128 million impacted users got malware from downloads of more than 2,500 affected apps.

Based on emails shared in the trial, Apple worked to determine the impact of the attack and how to best notify those who downloaded infected apps. "Due to the large number of customers potentially affected, do we want to send an email to all of them?" Apple's ‌App Store‌ vice president Matt Fischer asked.

Apple did ultimately inform users that downloaded XcodeGhost apps, and also published a list of the top 25 most popular apps that were compromised. Apple removed all of the infected apps from the ‌App Store‌, and provided information to developers to help them validate Xcode going forward.

XcodeGhost was a widespread attack, but it was not effective or dangerous. At the time, Apple said that it had no information to suggest that the malware was ever used for any malicious purpose nor that sensitive personal data was stolen, but it did collect app bundle identifiers, network details, and device names and types.

Top Rated Comments

Stromos Avatar
21 months ago
Yes its so convenient to figure out which app store I need to download and install to get an app. Then provide credit card details to any and every developer that I want to purchase something. Then figure out which store I need to open to update an app. Better regularly launch the alternative stores to get updates. Oh a store was compromised which apps on my device came from that store?

No purpose to the end user at all.
Score: 20 Votes (Like | Disagree)
deevey Avatar
21 months ago

how are these companies obtaining these private emails?
The ongoing Epic / Apple.

I'd guess these emails were entered into evidence by Apple as an insight into what they actually do in term of securing the App Store, further justifying the 30% commission.
Score: 8 Votes (Like | Disagree)
ArPe Avatar
21 months ago
If phones turned into multiple App Store flea markets then half the apps installed would be these malware and spyware. Every one of you could have your money stolen or become the next Khashoggi.
Score: 6 Votes (Like | Disagree)
hot-gril Avatar
21 months ago
It's silly that Apple has to even justify the 30% commission they charge on their own platform that devs and users are free to use or not use, esp when nobody else justifies the same, but these emails are interesting to read.
Score: 6 Votes (Like | Disagree)
rjohnstone Avatar
21 months ago

It's silly that Apple has to even justify the 30% commission they charge on their own platform that devs and users are free to use or not use, esp when nobody else justifies the same, but these emails are interesting to read.
Devs are not free to use the platform. They have to pay annually to have the opportunity to be listed. Not all apps get listed. ;)
Score: 6 Votes (Like | Disagree)
Cosmosent Avatar
21 months ago
Another Nugget thanks to the trial !
Score: 6 Votes (Like | Disagree)

Related Stories

Apple Music One Free Month Offwhite

Apple Music Reduces Free Trial Period to One Month

Friday February 4, 2022 8:34 am PST by
Since launching in 2015, Apple Music has offered a three-month free trial to first-time subscribers, but the trial period has now been reduced. Starting this week, Apple Music offers a shorter one-month free trial to first-time subscribers in the United States, Canada, Australia, United Kingdom, Japan, and other countries. The change was first spotted by Japanese blog Mac Otakara. Apple...
app store blue banner

Apple Says iOS is Safer Than Android Because Sideloading Apps Isn't Allowed

Wednesday October 13, 2021 5:00 am PDT by
In response to the European Commission's proposed Digital Markets Act, which could force sideloading of apps on the iPhone in Europe, Apple has shared an in-depth document highlighting the security and privacy risks of sideloading. Sideloading refers to installing apps outside of the App Store, such as from a website or a third-party app store. Apple's document, titled Building a Trusted...
apple security banner

Apple Outlines How It Will Notify Users Who Have Been Targeted by State-Sponsored Spyware Attacks

Tuesday November 23, 2021 8:15 pm PST by
Earlier today, Apple announced that it had filed suit against NSO Group, the firm responsible for the Pegasus spyware that has been used in state-sponsored surveillance campaigns in a number of countries. NSO Group seeks to take advantage of vulnerabilities in iOS and other platforms to infiltrate the devices of targeted users such as journalists, activists, dissidents, academics, and government...
craig wwdc 2021 privacy

Report Highlights How Top Apple Executives Disagreed Over How Far iOS Anti-Tracking Measures Should Go

Monday March 14, 2022 7:19 am PDT by
A new report has highlighted how three top prominent executives initially found themselves at odds in early deliberations about Apple's App Tracking Transparency framework. According to the report from The Information, the executives who disagreed over how far Apple should go in protecting user privacy in digital advertising included Apple's Craig Federighi, who oversees software...
iOS App Store General Feature JoeBlue

Apple to Allow In-App Third-Party Payment Options for First Time in the Netherlands

Saturday January 15, 2022 12:39 am PST by
Apple has announced that it will allow third-party payment options for in-app purchases for dating apps in the Netherlands, in the first ever concession of its kind. In a message posted on its developer site late on Friday, Apple announced that it will comply with a Netherlands Authority for Consumers and Markets (ACM) ruling that compels the company to allow third-party payment services to...
google one app

Google One Disappears From App Store a Day After VPN Launch [Update: Google One is Back in the App Store]

Wednesday February 2, 2022 12:01 pm PST by
The Google One app for iPhone and iPad appears to have mysteriously disappeared from the App Store this morning, and it is no longer available for download. As noted on Reddit, attempting to download the Google One app in the United States and Canada pops up an error message that says "App Not Available." It is not clear why the app has been removed from the App Store at this time, and...
iOS App Store General Feature Dock

Indie Developer Dogged By Scammy Clone Apps Again Highlights the Holes in Apple's App Store Review Process

Monday February 21, 2022 9:29 am PST by
Apps that copy concepts and features from other apps are nothing new in the ‌App Store‌, but scammy like-for-like clones of genuine apps remain a perennial problem that Apple still hasn't resolved, as indie developer Kevin Archer recently discovered. Archer is responsible for 2Stable's Authenticator App, a feature-rich app that stores and generates secure two-factor authentication tokens...
macbook pro sizes space gray

DoJ Arrests Hacker Involved With REvil Group That Stole Apple's MacBook Pro Schematics

Monday November 8, 2021 4:28 pm PST by
The United States Justice Department today announced that it has arrested Ukrainian Yaroslav Vasinskyi for his involvement with REvil, a group that executed ransomware attacks against businesses and government entities in the United States. REvil in April targeted Apple supplier Quanta Computer and stole schematics of the design of the 14 and 16-inch MacBook Pro models that were later...

Popular Stories

applefifthavenue

Man Robbed After Buying 300 iPhones From Apple Fifth Avenue

Tuesday November 29, 2022 11:54 am PST by
An unnamed 27-year-old man who purchased 300 iPhones from Apple Fifth Avenue on Monday morning was robbed shortly after leaving the store, according to 1010Wins Radio in New York. He was carrying 300 iPhone 13s in three bags and walking to his car at 1:45 a.m. when another car pulled up next to him. Two men jumped out and demanded that he hand over the bags. Not wanting to hand over 300...
iOS 16

Apple Releases iOS 16.1.2 With Carrier Improvements and Crash Detection Optimizations

Wednesday November 30, 2022 10:09 am PST by
Apple today released iOS 16.1.2, another minor bug fix update that comes one week after the release of iOS 16.1.1 and three weeks after the launch of iOS 16.1, an update that added support for iCloud Shared Photo Library, Matter, Live Activities, and more. The iOS 16.1.2 update can be downloaded on eligible iPhones over-the-air by going to Settings > General > Software Update. According...
app store awards 2021

Apple Announces 2022 App Store Award Winners, Highlighting Best Apps of the Year

Tuesday November 29, 2022 3:10 am PST by
Apple today announced its 2022 App Store Award winners, highlighting the 16 best apps and games selected by Apple's global App Store editorial team. The top apps were chosen by Apple for their quality, innovative technology, creative design, positive cultural impact, and ability to deliver "exceptional experiences." Apple CEO Tim Cook said: This year's App Store Award winners reimagined...
14 vs 16 inch mbp m2 pro and max feature 1

'M2 Max' Geekbench Scores Leak Online, Revealing Rumored Specs and Performance

Wednesday November 30, 2022 2:39 am PST by
Geekbench scores allegedly for the upcoming "M2 Max" chip have surfaced online, offering a closer look at the performance levels and specific details of the forthcoming Apple silicon processor. The Geekbench results, first spotted on Twitter, are for a Mac configuration of with the M2 Max chip, a 12-core CPU, and 96GB of memory. The Mac listed has an identifier "Mac14,6," which could be...
eufy camera

Anker's Eufy Cameras Caught Uploading Content to the Cloud Without User Consent [Updated]

Tuesday November 29, 2022 1:01 pm PST by
Anker's popular Eufy-branded security cameras appear to be sending some data to the cloud, even when cloud storage is disabled and local only storage settings are turned on. The information comes from security consultant Paul Moore, who last week published a video outlining the issue. According to Moore, he purchased a Eufy Doorbell Dual, which was meant to be a device that stored video...
Apple Park View

Elon Musk Meets With Apple CEO Tim Cook Amid Claims of Twitter App Store Dispute [Updated]

Wednesday November 30, 2022 12:43 pm PST by
Twitter CEO Elon Musk today met with Apple CEO Tim Cook at the Apple Park campus in Cupertino, California, according to a tweet shared by Musk this afternoon. Musk thanked Cook for taking him around Apple's headquarters, with no mention of what the two might have discussed. The meeting comes just after Musk on Monday claimed that Apple has "mostly stopped" offering ads on Twitter, and that...
iphone 11 tesla cybertruck close up

Elon Musk Pledges to Build iPhone Rival If Apple Ousts Twitter

Tuesday November 29, 2022 2:48 am PST by
Elon Musk has pledged to offer an "alternative phone" if Apple and Google remove Twitter from their app stores, adding to long-standing rumors about an iPhone rival from Tesla. Modified iPhone 11 Pro in the style of the Tesla Cybertruck, by Caviar. Musk's remark came after being asked about the potential scenario of Twitter being removed from app stores, which could conceivably happen if the...
Cyber Monday Deals Feature 2022

Best Cyber Monday Apple Deals Still Available for AirPods, Apple TV, iPad, and More

Monday November 28, 2022 5:24 am PST by
The Black Friday and Cyber Monday holiday shopping rush is drawing to a close, but there are still some good deals to be had out there. For Apple products, many of the deals you've seen since last week are still available, though some have expired. So for anyone who missed out on Black Friday deals, there's still an opportunity to get some of the year's best prices on many Apple devices. Note: ...
apple music replay 2022 highlight reel cropped

Apple Music Replay 2022 Revamped With 'Highlight Reel' [Updated]

Tuesday November 29, 2022 4:02 am PST by
Apple today rolled out an updated Apple Music Replay experience for 2022, showcasing a new "highlight reel" feature. Subscribe to the MacRumors YouTube channel for more videos. The overhauled experience, which started to be noticed by Apple Music subcribers on Twitter earlier today, puts the new highlight reel feature at the forefront of the Replay webpage, which users are encouraged to...
iPhone 14 Pro Rear Camera

iPhone 15 to Use 'State-of-the-Art' Image Sensor From Sony for Better Low-Light Performance

Monday November 28, 2022 11:00 am PST by
Apple's upcoming iPhone 15 models will be equipped with Sony's newest "state of the art" image sensors, according to a report from Nikkei. Compared to standard sensors, Sony's image sensor doubles the saturation signal in each pixel, allowing it to capture more light to cut down on underexposure and overexposure. Nikkei says that it is able to better photograph a person's face even with...