Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le septembre 18, 2017, 13:01:40

Titre: [Trend]iXintpwn/YJSNPI Abuses iOS’s Config Profile, can Crash Devices
Posté par: igor51 le septembre 18, 2017, 13:01:40
iXintpwn/YJSNPI Abuses iOS’s Config Profile, can Crash Devices

While iOS devices generally see relatively fewer threats because of the platform's walled garden approach in terms of how apps are installed, it’s not entirely unbreachable. We saw a number of threats that successfully scaled the walls in 2016, from those that abused enterprise certificates to ones that exploited vulnerabilities to curtail Apple’s stringent control over its platforms.


This is further exemplified by iXintpwn/YJSNPI (detected by Trend Micro as TROJ_YJSNPI.A), a malicious profile that can render the iOS device unresponsive. It was part of the remnants of the work of a Japanese script kiddie who was arrested in early June this year.


While iXintpwn/YJSNPI seems currently concentrated in Japan, it won't surprise anyone if it spreads beyond the country given how it proliferated in social media.


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


iXintpwn/YJSNPI Abuses iOS’s Config Profile, can Crash Devices


Source: iXintpwn/YJSNPI Abuses iOS’s Config Profile, can Crash Devices (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/Bzs3_unx690/)