‘XcodeGhost’ Malware Attack in 2015 Impacted 128 Million iOS Users, According to Trial Documents

Back in 2015, a malware-infected version of Xcode began circulating in China, and malware-ridden “XcodeGhost” apps made their method into Apples App Store and past the App Store review team.
There were more than 50 recognized contaminated iOS apps at the time, including major apps like WeChat, NetEase, and Didi Taxi, with as much as 500 million iOS users potentially impacted. Its been a long period of time since the XcodeGhost attack, but Apples trial with Epic is emerging new details.
Trial files highlighted by Motherboard indicate that a total of 128 million users downloaded apps with the XcodeGhost malware, consisting of 18 million users in the United States.
XcodeGhost was among the biggest attacks against iPhone users to date due to the number of iPhone users that were impacted. The 128 million impacted users got malware from downloads of more than 2,500 affected apps.
Based upon e-mails shared in the trial, Apple worked to determine the impact of the attack and how to best alert those who downloaded contaminated apps. “Due to the big number of consumers possibly impacted, do we wish to send an e-mail to all of them?” Apples App Store vice president Matt Fischer asked.
Apple did ultimately inform users that downloaded XcodeGhost apps, and likewise published a list of the leading 25 most popular apps that were compromised. Apple removed all of the infected apps from the App Store, and provided info to developers to assist them confirm Xcode going forward.
XcodeGhost was an extensive attack, however it was hazardous or not effective. At the time, Apple said that it had no information to recommend that the malware was ever used for any harmful function nor that sensitive personal information was taken, however it did collect app package identifiers, network information, and gadget names and types.