{"id":7257,"date":"2017-04-06T10:10:12","date_gmt":"2017-04-06T18:10:12","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/04\/06\/news-1048\/"},"modified":"2017-04-06T10:10:12","modified_gmt":"2017-04-06T18:10:12","slug":"news-1048","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/04\/06\/news-1048\/","title":{"rendered":"Malvertising on iOS pushes eyebrow-raising VPN app"},"content":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Thu, 06 Apr 2017 17:10:49 +0000<\/strong><\/p>\n<p>There is a preconceived idea that malvertising mostly affects the Windows platform. Certainly, when it comes to malicious adverts, Internet Explorer is a prime target for malware infections. However, malvertising can produce different outcomes adapted to the device the user is running.<\/p>\n<p>Case in point, we discovered this scareware campaign that pushes a &#8216;free&#8217; VPN app called <em>My Mobile Secure<\/em> to iOS users\u00a0via rogue ads on popular Torrent sites. The page plays an ear-piercing beeping sound and claims your device is infected with viruses.<\/p>\n<p><em>&#8220;We have detected that your Mobile Safari is (45.4%) DAMAGED by BROWSER TROJAN VIRUSES picked up while surfing recent corrupted sites.&#8221;<\/em><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/scareware_.png\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17315 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/scareware_.png\" alt=\"\" width=\"616\" height=\"707\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/scareware_.png 616w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/scareware_-261x300.png 261w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/scareware_-523x600.png 523w\" sizes=\"auto, (max-width: 616px) 100vw, 616px\" \/><\/a><\/p>\n<p>Such alerts on mobile devices are not new and sadly\u00a0common place via many\u00a0ad networks these days. Usually, aggressive affiliates remunerated per lead\u00a0will use these kinds\u00a0of tactics to drive traffic to game apps or even\u00a0<a href=\"https:\/\/twitter.com\/jeromesegura\/status\/812776441234395137\" target=\"_blank\">tech support scams<\/a>.<\/p>\n<p>Thankfully for the latter, Apple has released an update to their mobile operating system (<a href=\"https:\/\/support.apple.com\/HT207688\" target=\"_blank\">iOS 10.3.1<\/a>) to avoid so-called &#8220;browser lockers&#8221; via incessant JavaScript popups that prevented users from closing the offending page. Having said that, social engineering attacks such as the one above are still active and prey on the surprise effect or culpability someone may experience after browsing sites with pirated material.<\/p>\n<h3>Network traffic<\/h3>\n<p>This malvertising chain starts off with an ad call from Propeller Ads Media, goes through Real Time Bidding (RTB) via AdMetix, is redirected to RevenueHits, and finishes off with scammy advertisers.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/Traffic_flow.png\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17321\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/Traffic_flow.png\" alt=\"\" width=\"963\" height=\"385\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/Traffic_flow.png 963w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/Traffic_flow-300x120.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/Traffic_flow-600x240.png 600w\" sizes=\"auto, (max-width: 963px) 100vw, 963px\" \/><\/a><\/p>\n<h3>&#8216;Free&#8217; VPN\u00a0app<\/h3>\n<p>This fake website advertises the <a href=\"https:\/\/itunes.apple.com\/app\/mymobilesecure-unlimited-vpn-proxy\/id1139266439?mt=8\" target=\"_blank\"><em>MyMobileSecure <\/em>VPN<\/a>\u00a0to remove &#8220;infected applications and files&#8221;. Tapping on &#8216;Remove Virus&#8217; opens up the App Store to download this app.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-17327 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/scare2.png\" alt=\"\" width=\"575\" height=\"676\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/scare2.png 676w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/scare2-255x300.png 255w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/scare2-510x600.png 510w\" sizes=\"auto, (max-width: 575px) 100vw, 575px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-17329 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/ad_VPN.png\" alt=\"\" width=\"575\" height=\"767\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/ad_VPN.png 632w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/ad_VPN-225x300.png 225w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/ad_VPN-450x600.png 450w\" sizes=\"auto, (max-width: 575px) 100vw, 575px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-17325 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/app.png\" alt=\"\" width=\"580\" height=\"774\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/app.png 627w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/app-225x300.png 225w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/app-449x600.png 449w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/><\/p>\n<p>The MyMobileSecure\u00a0developer, VoiceFive is a\u00a0comScore, Inc. company, <em>&#8220;a leading global market research company that studies and reports on Internet trends and behavior.<\/em>&#8221; In order to activate the free VPN app, users must join the\u00a0MobileXpression research community, and this is where things get interesting.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17334 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/screen696x696jpg.jpeg\" alt=\"\" width=\"392\" height=\"696\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/screen696x696jpg.jpeg 392w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/screen696x696jpg-169x300.jpeg 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/screen696x696jpg-338x600.jpeg 338w\" sizes=\"auto, (max-width: 392px) 100vw, 392px\" \/><\/p>\n<p>From <a href=\"http:\/\/www.mymobilesecure.com\/\" target=\"_blank\">mymobilescure.com<\/a>: <em>&#8220;The <strong>MobileXpression<\/strong> email account is a part of the software download package for iPhones and iPads. The email account is there to provide you with a better way to stay in touch with MobileXpression and also make sure our software works correctly.&#8221;<\/em><\/p>\n<h3>If the product is free, you are the product<\/h3>\n<p>According to their <a href=\"https:\/\/www.mobilexpression.com\/about.aspx\" target=\"_blank\">website<\/a>,\u00a0MobileXpression is a market research panel designed to understand the trends and behaviors of people using the mobile Internet. This seems a bit peculiar when applied to a VPN product, whose goal is to precisely anonymize your online activity by encrypting your data from your ISP, government, bad guys, etc.<\/p>\n<p>As an aside, the topic of VPNs is particularly hot at the moment, on the heels of an upcoming bill (<a href=\"https:\/\/www.congress.gov\/bill\/115th-congress\/senate-joint-resolution\/34\" target=\"_blank\">S.J. Res. 34<\/a>) that would allow Internet Service Providers (ISPs) to sell data about your online habits to advertisers. Many people are rushing into installing the first VPN they can get their hands on, which is a terrible idea considering many companies out there are very\u00a0shady and far worse than your own ISP.<\/p>\n<p>Free does not mean Open Source or risk-free for that matter. But the fact of the matter is that people tend to gravitate towards free products, especially if those are pushed aggressively via hungry advertisers. For this reason, users should pay even more attention before installing a free app.<\/p>\n<p>If the reason you want to install a VPN is because you are truly worried\u00a0about your online privacy, then you really ought to read the <a href=\"https:\/\/www.mobilexpression.com\/privacy.aspx\" target=\"_blank\">fine print<\/a>. This particular VPN app has some\u00a0concerning statements:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/privacy1.png\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17336\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/privacy1.png\" alt=\"\" width=\"795\" height=\"793\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/privacy1.png 795w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/privacy1-150x150.png 150w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/privacy1-300x300.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/privacy1-600x598.png 600w\" sizes=\"auto, (max-width: 795px) 100vw, 795px\" \/><\/a><\/p>\n<p>If you shop around\u00a0for other VPN providers, you will see the exact opposite when it comes to data collection\u00a0and logging. Here are some examples:<\/p>\n<ul>\n<li>[VPN x] never logs where you go on the Internet. If anyone asks, the best we can do is shrug our shoulders.<\/li>\n<li>[VPN y] makes it impossible to identify the type of traffic or protocol you are using, even for your ISP.<\/li>\n<li>[VPN z]\u00a0doesn&#8217;t store any connection logs whatsoever. In addition, we do not log bandwidth usage, session data or requests to our DNS servers.<\/li>\n<\/ul>\n<p>Some even provide Bitcoin as a mode of payment to completely anonymize the registration process, via a throwaway email address for example.<\/p>\n<h3>VPN providers and trust<\/h3>\n<p>Often times, affiliates are not properly policed and we observe scare tactics to force the installation of various pieces of software. It&#8217;s important to note that those affiliates are normally\u00a0distinct from the software vendors themselves, but scammy behaviors end up reflecting poorly on everyone.<\/p>\n<p>In this particular case, one cannot help but feel that this VPN application comes with some serious baggage and unfortunately the average user will not take the time to review the fine details. If the intent is to use a VPN to anonymize your online activities, this does almost the opposite.<\/p>\n<p>One statement from mobileXpression is particularly striking:<\/p>\n<p>&#8220;<em>We make commercially viable efforts to automatically filter confidential personal information such as UserID, password, credit card numbers, and account numbers. <strong>Inadvertently, we may collect personal information<\/strong> about our panelists; and when this happens, we make commercially viable efforts to purge our database of such information.<\/em>&#8221;<\/p>\n<p>This summarizes the issue quite clearly: said data should never\u00a0be collected in the first place because some very unfortunate things can happen once it is logged in a database. Haven&#8217;t there been enough data\u00a0breaches lately to be seriously concerned with what kind of data a company may collect (inadvertently or not)?<\/p>\n<p>Choosing the right VPN application these days has become very\u00a0challenging due to the renewed interest in online privacy (there are other reasons people buy VPNs as well, such as to bypass\u00a0geo-restrictions from services like Netflix, the BBC, etc). It&#8217;s important to take the time to review the companies behind those products, their policies, and real reviews, not fake or sponsored ones. At the end of the day, you are placing your data and trust in someone else&#8217;s hands.<\/p>\n<p><em>Kudos to CloudFlare for terminating\u00a0the scareware domain\u00a0in less than five minutes.<\/em><\/p>\n<h3>IOCs:<\/h3>\n<pre>onclkds.com  xml.admetix.com  clk1005.com  inclk.com  browserloading.com  giveawaywins.com  securecheckapp.com<\/pre>\n<pre>206.54.163.50  173.239.53.20  173.192.117.80  108.168.157.87  52.29.11.13  104.31.67.144  104.28.17.3<\/pre>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/04\/malvertising-on-ios-pushes-eyebrow-raising-vpn-app\/\">Malvertising on iOS pushes eyebrow-raising VPN app<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/04\/malvertising-on-ios-pushes-eyebrow-raising-vpn-app\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Thu, 06 Apr 2017 17:10:49 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/04\/malvertising-on-ios-pushes-eyebrow-raising-vpn-app\/' title='Malvertising on iOS pushes eyebrow-raising VPN app'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/04\/banner2.png' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>A malvertising campaign on iOS is pushing a scareware page tricking Apple users into installing a free VPN app that comes with serious privacy implications.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/threat-analysis\/social-engineering-threat-analysis\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/threat-analysis\/\" rel=\"category tag\">Threat analysis<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/apple\/\" rel=\"tag\">Apple<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/ios\/\" rel=\"tag\">iOS<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/iphone\/\" rel=\"tag\">iPhone<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/malvertising\/\" rel=\"tag\">malvertising<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/malware\/\" rel=\"tag\">malware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mymobilesecure\/\" rel=\"tag\">MyMobileSecure<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/scareware\/\" rel=\"tag\">scareware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/vpn\/\" rel=\"tag\">vpn<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/04\/malvertising-on-ios-pushes-eyebrow-raising-vpn-app\/' title='Malvertising on iOS pushes eyebrow-raising VPN app'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/04\/malvertising-on-ios-pushes-eyebrow-raising-vpn-app\/\">Malvertising on iOS pushes eyebrow-raising VPN app<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[2211,10480,8826,10531,3764,11900,11901,10510,10494,10863],"class_list":["post-7257","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-apple","tag-ios","tag-iphone","tag-malvertising","tag-malware","tag-mymobilesecure","tag-scareware","tag-social-engineering","tag-threat-analysis","tag-vpn"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7257","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7257"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7257\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7257"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7257"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7257"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}