Researchers Find Over a Dozen iOS Games Tied to Golduck Malware

Security firm Wandera discovers 14 retro-style iPhone apps communicating with a command server linked to the Android-focused Golduck malware. These apps currently push ads and collect user data, but pose a potential future risk.

Security researchers at Wandera uncover 14 retro-style iPhone apps that secretly communicate with a server associated with Golduck, a malware strain originally known for infecting Android devices. Golduck historically embeds backdoor code in classic games to silently push malicious payloads, previously affecting over 10 million Android users by running high-privilege commands like sending premium SMS messages.

The affected iOS apps, which include titles like Commando Metal and Classic Bomber, currently exhibit relatively benign behavior compared to their Android counterparts. Instead of pushing malicious payloads, the command and control server tells the apps which icons and links to display in a designated ad space in the upper-right corner of the screen.

Despite the lack of immediate malicious payloads, these apps still pose a privacy risk by sending sensitive information back to the Golduck server. TechCrunch verifies that the apps transmit the app name, version, device type, IP address, and sometimes location data, leaving the door open for more dangerous commands in the future.

Read More at the original source →