'Hacking Team' Data Breach Confirms Firm's Ability to Infiltrate Jailbroken iPhones

  1. MacRumors macrumors bot


    Apr 12, 2001

    Cybersecurity firm Hacking Team experienced a data breach earlier today, resulting in 400 GB of its documents being leaked onto the Internet, reports The Guardian. The documents confirm Hacking Team's ability to infiltrate and monitor jailbroken iPhones on behalf of government law enforcement agencies like the NSA, as noted by Macworld.

    Hacking Team's software would need to be installed on a jailbroken iPhone, but the firm has the ability to jailbreak and infect a phone with its software via a malware-infected trusted computer the phone is connected to. In the firm's pricing list [PDF, requires Chrome], it's revealed hacking an iOS device costs EUR50,000 ($55,242) and includes "features" like Skype, WhatsApp and Viber chats, location, contacts and lists of calls. However, this service also includes a prerequisite of a jailbroken iPhone.

    Hacking Team uses a legitimate Apple enterprise signing certificate, which is used by corporations to create software that can easily be installed on employee devices, combined with jailbroken iOS devices to bypass iOS app installation protections. Additionally, Hacking Team developed the ability to create a malicious Newsstand app that could capture keystrokes and install monitoring software.

    Last year, researchers working independently of each other at Kaspersky Lab and Citizen Lab discovered components of Hacking Team's tools and how they were used by government agencies to steal data from mobile devices, but the full extent of the software hadn't been confirmed until now.

    Data breaching software and Apple devices have been in the news before, most famously in last year's celebrity iCloud data breach, where it was discovered that hackers were using ElcomSoft Phone Password Breaker, software intended for government and law agencies, to steal usernames and passwords to access iCloud backups.

    While much of the discussion around government agencies and citizen data has revolved around mass collection, Hacking Team's software is designed to attack individual devices rather than a vast network. It's likely that the exploits detailed in Hacking Team's documents will be addressed and patched up in future iOS and Mac software updates.

  2. Shadow Runner macrumors regular

    Jun 14, 2010
    It's a good thing Apple keeps making iOS more capable. I have less and less reason to jailbreak as they keep updating it.
  3. jmh600cbr macrumors 6502a


    Feb 14, 2012
    That all sounds awful until you realize that you need an infected computer to make it happen
  4. furi0usbee macrumors 68000


    Jul 11, 2008
  5. AngerDanger, Jul 6, 2015
    Last edited: Jul 6, 2015

    AngerDanger macrumors 601


    Dec 9, 2008

    Get back into your folder and just be glad I can't delete you… without a jailbreak.
  6. hfletcher macrumors 6502


    Oct 10, 2008
    So.... you're only actually vulnerable if you happen to have a Jailbroken iPhone and a computer that is also infected with their malware.

    Pretty unlikely scenario?
  7. furi0usbee macrumors 68000


    Jul 11, 2008
    LOL @ Newstand. I want to know the one guy who uses that on a daily basis.
  8. Benjamin Frost Suspended

    Benjamin Frost

    May 9, 2015
    London, England

    MacFormat magazine.
  9. OldSchoolMacGuy Suspended


    Jul 10, 2008
    I've been saying we've been selling this to the government for years and no one seemed to care. Why is this news now? Been making tons off of this since 2008.
  10. Even Longer macrumors 6502

    Even Longer

    Dec 12, 2012
    Head of a pin
    Aren't these guys got hacked themselves yesterday?
    'Hacking team' went to 'Hacked team' and now they still claim some ability?!

  11. jdogg836 macrumors 6502


    Jul 28, 2010
    One of the arrogant members of that team was running his mouth on twitter this morning, stoking the fire even more. He was threatening the hackers who breached the data. Cool thing about all of the tools they have being released is within a few days, all the major anti-virus companies can update their software to find and remove this crap.
  12. lkrupp macrumors 6502a

    Jul 24, 2004
    It means the average user has absolutely nothing to worry about. It means you need to be targeted specifically by a professional. Your ex-boyfriend isn’t going to be able to do this. Neither will your nerdy cousin.
  13. rictus007 macrumors regular

    Oct 12, 2011
    I wonder if it is a Mac or a regular PC
  14. AngerDanger macrumors 601


    Dec 9, 2008
    A team that got hacked themselves is able to hack iOS. That seems more ominous than if the team was super competent and secure themselves.
  15. Rigby macrumors 601

    Aug 5, 2008
    San Jose, CA
    Not necessarily. There are several components:

    - Hacking Team's sniffing app can be installed on any iOS device because it is signed with a valid enterprise certificate.
    - To give the app full access to the data on the phone, the phone needs to be jailbroken.
    - Hacking Team offers malware for OS X and Windows that can jailbreak a phone that is connected to the computer, provided that the computer has pairing keys (the device has previously been connected to it). The malware could get on the computer e.g. via phishing or other means.
  16. JeffyTheQuik macrumors 68020


    Aug 27, 2014
    Charleston, SC and Everett, WA
    Which is *exactly* why I stopped jailbreaking when I put my credit cards on the phone.
  17. KALLT macrumors 601

    Sep 23, 2008
    Goes to show in what vulnerable position you are putting yourself by loading software from questionable sources with such far going access rights. Immature hackers with a unhealthy level of grandeur and flawed allegiances could ultimately be the downfall of an otherwise dedicated jailbreak community.
  18. JeffyTheQuik macrumors 68020


    Aug 27, 2014
    Charleston, SC and Everett, WA
    I'd like to meet the guy that uses it twice.

    Once is bad enough.
  19. Dargoth, Jul 6, 2015
    Last edited: Jul 6, 2015

    Dargoth macrumors regular


    Oct 27, 2014
    I'm sorry... I can't remember exactly, but I believe I used it twice. :( I'd like to meet the guy who uses it thrice.
  20. RangerXML macrumors regular

    Jul 4, 2009
    Looks like someone forgot to change the root p/w...

    Step 1. Jailbreak

    Step 2. Change the root p/w.
  21. Swift macrumors 68000


    Feb 18, 2003
    Los Angeles
    Which is why, frankly, I don't care. Time for warrants to be given to hack the digital life of anyone for whom there is probable cause to believe is committing a crime, or terrorism. You know that police did not used to routinely get a warrant to wiretap? If you commit crimes on the Internet, and you certainly can, your privacy is not a right.
  22. WannaGoMac macrumors 68020


    Feb 11, 2007
    Is that a white macbook in the Guardian article image? Wow!
  23. MacMulti macrumors regular

    Mar 20, 2013
    With great power comes greater responsibility and even greater risk.
  24. cocky jeremy macrumors 601

    cocky jeremy

    Jul 12, 2008
    Columbus, OH
    "If we physically take your phone, run 10 laps around a building, all while connecting you to our single laptop, we can infect your iPhone!"
  25. Paradoxally macrumors 68000

    Feb 4, 2011
    Apple Pay does not become less secure when jailbreaking, just like Touch ID.

