{"id":19183,"date":"2020-11-02T09:58:01","date_gmt":"2020-11-02T14:58:01","guid":{"rendered":"https:\/\/nuxx.net\/blog\/?p=19183"},"modified":"2020-11-02T10:01:21","modified_gmt":"2020-11-02T15:01:21","slug":"mail-hijacking-malicious-profile-on-ios","status":"publish","type":"post","link":"https:\/\/nuxx.net\/blog\/2020\/11\/02\/mail-hijacking-malicious-profile-on-ios\/","title":{"rendered":"Mail-Hijacking Malicious Profile on iOS"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"919\" src=\"https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221934934-1024x919.jpg\" alt=\"\" class=\"wp-image-19190\" srcset=\"https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221934934-1024x919.jpg 1024w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221934934-300x269.jpg 300w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221934934-768x689.jpg 768w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221934934-1536x1378.jpg 1536w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221934934-2048x1838.jpg 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>I was recently asked to look at a family member&#8217;s iPad because it was no longer sending email. Turns out that it had been set up to use an additional email account that steals copies of all their outgoing mail. Unfortunately, they didn&#8217;t notice until the attacker&#8217;s system stopped working and the iPad started showing an error message. Besides the irritating (or worse) spam they saw, their stolen emails could have been used for anything from <a href=\"https:\/\/en.wikipedia.org\/wiki\/Phishing#Spear_phishing\">spear phishing<\/a> to accessing one&#8217;s online accounts, impersonating them, phishing others, delivering targeted spam, fake news \/ propaganda, etc.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222400474-903x1024.jpg\" alt=\"\" class=\"wp-image-19186\" width=\"226\" height=\"256\" srcset=\"https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222400474-903x1024.jpg 903w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222400474-265x300.jpg 265w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222400474-768x871.jpg 768w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222400474-1354x1536.jpg 1354w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222400474-1806x2048.jpg 1806w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222400474.jpg 1811w\" sizes=\"auto, (max-width: 226px) 100vw, 226px\" \/><\/figure><\/div>\n\n\n\n<p>So how did this get set up?<\/p>\n\n\n\n<p>Apparently at some point this person installed the <a href=\"https:\/\/myaccurateforecast.com\/\">My Accurate Forecast<\/a> app [1]. Included in this app was a <a href=\"https:\/\/support.apple.com\/en-us\/HT209435\">Profile<\/a> &#8212; or a set of settings for Apple devices &#8212; that added a second email account with address <em>lazaroburst@my.minbox.email<\/em>. This account was also set as the outgoing server for their <a href=\"https:\/\/en.wikipedia.org\/wiki\/Outlook.com\">Hotmail (Outlook.com)<\/a> account.<\/p>\n\n\n\n<p class=\"has-text-align-left\">This person would then have seen all messages in this account, with notifications just like their normal Hotmail email. Worse, everything they sent, from any email account, went to the attacker first. As it&#8217;s a separate email account, all the normal spam and malware protections from a normal email provider don&#8217;t apply&#8230; It&#8217;s a firehose of junk straight to their mailbox, with outgoing mail theft frosting on top.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221956681-851x1024.jpg\" alt=\"\" class=\"wp-image-19189\" width=\"213\" height=\"256\" srcset=\"https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221956681-851x1024.jpg 851w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221956681-249x300.jpg 249w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221956681-768x924.jpg 768w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221956681-1276x1536.jpg 1276w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_221956681-1701x2048.jpg 1701w\" sizes=\"auto, (max-width: 213px) 100vw, 213px\" \/><\/figure><\/div>\n\n\n\n<p>This is bad because not only does it end up with them getting more spam, it allows the attacker to know exactly what they sent and to whom, and to modify those messages before delivering them to the intended recipients.<\/p>\n\n\n\n<p>I think this was likely generated based on geolocated advertising, but it&#8217;s possible this individual was specifically targeted. The signed Profile had a name of <em>&#8220;WEATHER ALERTS&#8221;<\/em> a description of <em>&#8220;Tap &#8216;Install&#8217; above to get your local radar forecasts and weather alerts in 48062&#8221;<\/em>, showing its intent to deceive; trying to make the normal Profile installation security alert &#8212; which is supposed to warn the user of a change to important settings &#8212; look like part of an application install.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222027478-1024x604.jpg\" alt=\"\" class=\"wp-image-19187\" width=\"256\" height=\"151\" srcset=\"https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222027478-1024x604.jpg 1024w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222027478-300x177.jpg 300w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222027478-768x453.jpg 768w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222027478-1536x905.jpg 1536w, https:\/\/nuxx.net\/blog\/wp-content\/uploads\/2020\/11\/PXL_20201101_222027478-2048x1207.jpg 2048w\" sizes=\"auto, (max-width: 256px) 100vw, 256px\" \/><\/figure><\/div>\n\n\n\n<p>I&#8217;m unsure when this first got installed, but judging by the the Profile signing certificate expiring on December 8, 2016 it was likely within a year or two prior. (Unfortunately I didn&#8217;t check the issuance date before deleting the profile.) The Profile which made these changes was signed by <a href=\"http:\/\/secure5g.com\/\">secure5g.com<\/a>, an &#8220;advertising&#8221; company which has ties to <a href=\"https:\/\/minbox.email\/\">minbox.email<\/a> (the <em>Unsubscribe<\/em> link at the bottom of the page is a generic link to a minbox.email page).<\/p>\n\n\n\n<p>A post from June 2018 on Medium, <a href=\"https:\/\/medium.com\/@sinu\/unwanted-profiles-pop-up-in-ios-devices-inviting-spam-and-malware-11f20a0ad00c\">Unwanted Profiles Pop Up in iOS Devices, Inviting Spam and Malware<\/a>, reports the same problem almost two and a half years ago. Curiously, the handful of other posts I read about this (ref: <a href=\"https:\/\/community.spiceworks.com\/topic\/1415258-ios-advertisement-installed-a-device-profile-with-imap\">1,<\/a> <a href=\"https:\/\/rubica.com\/customer-spotlight-soc-threat-hunting-discovery-malware-weather-app\/\">2<\/a>) didn&#8217;t mention (or maybe didn&#8217;t notice) the outgoing server change? Perhaps because they only noticed before things broke, or maybe this iPad somehow ended up different? (It does seem that at least one other app: <em>Daily Bible Verse<\/em>, included similar email hijacking.)<\/p>\n\n\n\n<p>Cleaning this up these settings was easy, just a matter of removing the malicious Profile, outgoing mail account, and setting the Hotmail account back to using the appropriate servers. But, who knows what damage was done with the theft of the sent mail and receipt of spammy stuff.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>[1] The <a href=\"https:\/\/myaccurateforecast.com\/\">My Accurate Forecast<\/a> website still shows screenshots of the app, but does not link to any app stores. It also no longer appears in the <a href=\"https:\/\/www.apple.com\/app-store\/\">Apple App Store<\/a>, implying that it&#8217;s been pulled out.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I was recently asked to look at a family member&#8217;s iPad because it was no longer sending email. Turns out that it had been set&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/nuxx.net\/blog\/2020\/11\/02\/mail-hijacking-malicious-profile-on-ios\/\">Continue reading<span class=\"screen-reader-text\">Mail-Hijacking Malicious Profile on iOS<\/span><\/a><\/div>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"class_list":["post-19183","post","type-post","status-publish","format-standard","hentry","category-computers","entry"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/posts\/19183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/comments?post=19183"}],"version-history":[{"count":8,"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/posts\/19183\/revisions"}],"predecessor-version":[{"id":19196,"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/posts\/19183\/revisions\/19196"}],"wp:attachment":[{"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/media?parent=19183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/categories?post=19183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuxx.net\/blog\/wp-json\/wp\/v2\/tags?post=19183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}