Kaspersky Lab discovered infected versions of popular iPhone applications that were distributed through a Russian-language Telegram channel. A malicious module was embedded in the modified programs, capable of collecting device information, determining location, and taking screenshots.

Under the guise of improved versions, users were offered applications without ads, with unlocked paid features, or those unavailable in the official store. To install, one had to download an IPA file and sign it with a developer certificate using third-party tools like eSign or Scarlet. The program could also be launched from a computer or on a jailbroken device.

While the infected application is open, the malware obtains the device name, battery level, region settings, memory data, carrier information, and jailbreak status. The collected information and screenshots are then sent to attackers.

However, the module cannot continuously monitor the iPhone owner: after the program is closed, it stops working in the background. But even a short launch can be enough to intercept sensitive information displayed on the screen.

Experts advise installing applications only from official or developer-recommended sources. Some programs from the discovered Telegram channel did not contain malicious code but led users to where infected versions were distributed.

Read more on the topic: