Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

The only thing cheaper than hardware is talk.


computers / misc.phone.mobile.iphone / Here's how to protect against the iPhone GoldPickaxe iOS trojan

SubjectAuthor
* Here's how to protect against the iPhone GoldPickaxe iOS trojanOscar Mayer
+* Re: Here's how to protect against the iPhone GoldPickaxe iOS trojanAlan Browne
|`* Re: Here's how to protect against the iPhone GoldPickaxe iOS trojanOscar Mayer
| +- Re: Here's how to protect against the iPhone GoldPickaxe iOS trojanAlan Browne
| `- Re: Here's how to protect against the iPhone GoldPickaxe iOS trojanJolly Roger
`* Re: Here's how to protect against the iPhone GoldPickaxe iOS trojanJolly Roger
 `- Re: Here's how to protect against the iPhone GoldPickaxe iOS trojanJörg Lorenz

1
Here's how to protect against the iPhone GoldPickaxe iOS trojan

<uqqris$h7jd$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=12335&group=misc.phone.mobile.iphone#12335

  copy link   Newsgroups: misc.phone.mobile.iphone
Path: i2pn2.org!i2pn.org!news.chmurka.net!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nobody@oscarmayer.com (Oscar Mayer)
Newsgroups: misc.phone.mobile.iphone
Subject: Here's how to protect against the iPhone GoldPickaxe iOS trojan
Date: Sat, 17 Feb 2024 12:49:15 -0500
Organization: A noiseless patient Spider
Lines: 12
Message-ID: <uqqris$h7jd$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 17 Feb 2024 17:49:17 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="e50eb52ee3b3ea2fa800c0786e35dd7c";
logging-data="564845"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18yALaXBK3YKXl0wm4sy/EC"
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:102.0) Gecko/20100101 Thunderbird/102.10.0
Cancel-Lock: sha1:LxQSF6eiqvhron4SNP2WiqC0E5U=
Content-Language: en-US
 by: Oscar Mayer - Sat, 17 Feb 2024 17:49 UTC

Here's how to protect against the iPhone GoldPickaxe trojan.
https://9to5mac.com/2024/02/16/protect-against-iphone-trojan-goldpickaxe/

Goldpickaxe malware can collect an iOS user's biometric information from
iPhone photos, SMS text messages, intercept web activity, and more.

While the iPhone trojan was first found distributed through the iOS
TestFlight beta testing system, Apple was able to shut that down (at least
for now).

However, the latest evolution has seen GoldPickaxe being distributed
through malicious iOS mobile device management (MDM) profiles.

Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan

<Yd7AN.292221$Ama9.97314@fx12.iad>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=12337&group=misc.phone.mobile.iphone#12337

  copy link   Newsgroups: misc.phone.mobile.iphone
Path: i2pn2.org!i2pn.org!newsfeed.endofthelinebbs.com!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx12.iad.POSTED!not-for-mail
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Subject: Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan
Newsgroups: misc.phone.mobile.iphone
References: <uqqris$h7jd$1@dont-email.me>
Content-Language: en-US
From: bitbucket@blackhole.com (Alan Browne)
In-Reply-To: <uqqris$h7jd$1@dont-email.me>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Lines: 38
Message-ID: <Yd7AN.292221$Ama9.97314@fx12.iad>
X-Complaints-To: abuse@usenetserver.com
NNTP-Posting-Date: Sat, 17 Feb 2024 18:50:32 UTC
Organization: UsenetServer - www.usenetserver.com
Date: Sat, 17 Feb 2024 13:50:32 -0500
X-Received-Bytes: 2302
 by: Alan Browne - Sat, 17 Feb 2024 18:50 UTC

On 2024-02-17 12:49, Oscar Mayer wrote:
> Here's how to protect against the iPhone GoldPickaxe trojan.
> https://9to5mac.com/2024/02/16/protect-against-iphone-trojan-goldpickaxe/
>
> Goldpickaxe malware can collect an iOS user's biometric information from
> iPhone photos, SMS text messages, intercept web activity, and more.
> While the iPhone trojan was first found distributed through the iOS
> TestFlight beta testing system, Apple was able to shut that down (at least
> for now).
>
> However, the latest evolution has seen GoldPickaxe being distributed
> through malicious iOS mobile device management (MDM) profiles.

Quote from Group-IB: "Social engineering is the primary method used to
deliver malware to victims’ devices across the whole family of
GoldFactory Trojans.

GoldPickaxe.iOS is distributed through Apple’s TestFlight or by
social-engineering the victims to install an MDM profile."

Note the social-engineering required to get this onboard - something
everyone needs to be vigilant about at all times.

Vector 1: TestFlight of an iOS app. Less than 1% of iPhone users?
More? Less? (more likely less). And Apple have slammed that door
shut. Nothing burger.

Vector 2: Similar - (MDM profile) something for co. IT people to look
into as well as warn their users against social engineered attacks.
Pretty close to a nothing burger.

Vector 3: social engineering. Everyone should be vigilant at all times
anyway.

--
“Markets can remain irrational longer than your can remain solvent.”
- John Maynard Keynes.

Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan

<uqr2hq$im91$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=12338&group=misc.phone.mobile.iphone#12338

  copy link   Newsgroups: misc.phone.mobile.iphone
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nobody@oscarmayer.com (Oscar Mayer)
Newsgroups: misc.phone.mobile.iphone
Subject: Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan
Date: Sat, 17 Feb 2024 14:48:09 -0500
Organization: A noiseless patient Spider
Lines: 20
Message-ID: <uqr2hq$im91$1@dont-email.me>
References: <uqqris$h7jd$1@dont-email.me> <Yd7AN.292221$Ama9.97314@fx12.iad>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 17 Feb 2024 19:48:11 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="e50eb52ee3b3ea2fa800c0786e35dd7c";
logging-data="612641"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18YjVcmbOW/0EmmXi0kLxOP"
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:102.0) Gecko/20100101 Thunderbird/102.10.0
Cancel-Lock: sha1:romJc5y2widd3ifnUPcO7uvsY74=
Content-Language: en-US
 by: Oscar Mayer - Sat, 17 Feb 2024 19:48 UTC

On Sat, 17 Feb 2024 13:50:32 -0500, Alan Browne wrote:

> Markets can remain irrational longer than your can remain solvent.

There is a minor typo in your sig. But it's a nothing burger.

> And Apple have slammed that door shut. Nothing burger.

Another typo but more important, the fact it was there is not a nothing
burger because Occams Razor tells us there are plenty more also there.

> Vector 2: Similar - (MDM profile) something for co. IT people to look
> into as well as warn their users against social engineered attacks.
> Pretty close to a nothing burger.

It shows Apple didn't test properly. That's not a nothing burger.

> Everyone should be vigilant at all times anyway.

True but that's besides the point.

Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan

<cKcAN.312987$q3F7.89474@fx45.iad>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=12342&group=misc.phone.mobile.iphone#12342

  copy link   Newsgroups: misc.phone.mobile.iphone
Path: i2pn2.org!rocksolid2!news.neodome.net!news.mixmin.net!newsreader4.netcologne.de!news.netcologne.de!peer01.ams1!peer.ams1.xlned.com!news.xlned.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx45.iad.POSTED!not-for-mail
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Subject: Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan
Content-Language: en-US
Newsgroups: misc.phone.mobile.iphone
References: <uqqris$h7jd$1@dont-email.me> <Yd7AN.292221$Ama9.97314@fx12.iad>
<uqr2hq$im91$1@dont-email.me>
From: bitbucket@blackhole.com (Alan Browne)
In-Reply-To: <uqr2hq$im91$1@dont-email.me>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Lines: 46
Message-ID: <cKcAN.312987$q3F7.89474@fx45.iad>
X-Complaints-To: abuse@usenetserver.com
NNTP-Posting-Date: Sun, 18 Feb 2024 01:06:16 UTC
Organization: UsenetServer - www.usenetserver.com
Date: Sat, 17 Feb 2024 20:06:16 -0500
X-Received-Bytes: 2590
 by: Alan Browne - Sun, 18 Feb 2024 01:06 UTC

On 2024-02-17 14:48, Oscar Mayer wrote:
> On Sat, 17 Feb 2024 13:50:32 -0500, Alan Browne wrote:
>
>> Markets can remain irrational longer than your can remain solvent.
>
> There is a minor typo in your sig. But it's a nothing burger.

I noticed that a few days ago, but haven't fixed it. But is it typical
of you to post garbage and when challenged to point at squirrels to
deflect from your worthless posts? Seems so.

>
>> And Apple have slammed that door shut.  Nothing burger.
>
> Another typo but more important, the fact it was there is not a nothing
> burger because Occams Razor tells us there are plenty more also there.

A-holes assailing s/w for illegal monetary gain is new, is it?

>> Vector 2: Similar - (MDM profile) something for co. IT people to look
>> into as well as warn their users against social engineered attacks.
>> Pretty close to a nothing burger.
>
> It shows Apple didn't test properly. That's not a nothing burger.

Nobody can test for all eventualities. And as new things creep in, the
tests get more robust. Wow - so ordinary. Snooze time.
>
>> Everyone should be vigilant at all times anyway.
>
> True but that's besides the point.

Not at all. You posted what amounts to an extreme narrow case on top of
a narrow case. When all that is pointed out, you react poorly. Sheesh.
Get a grip on reality.

--
“Markets can remain irrational longer than you can remain solvent.”
- John Maynard Keynes.

"Typos can linger for ages before they're noticed."
- Editor of 'The Absolute Perfection Guide to Publishing.'

"Pointing out people's grammar and typos errors on usenet is childish
deflection."
- Everyone above age 12.

Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan

<l3dahpFa9lvU1@mid.individual.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=12343&group=misc.phone.mobile.iphone#12343

  copy link   Newsgroups: misc.phone.mobile.iphone
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: jollyroger@pobox.com (Jolly Roger)
Newsgroups: misc.phone.mobile.iphone
Subject: Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan
Date: 18 Feb 2024 03:06:33 GMT
Organization: People for the Ethical Treatment of Pirates
Lines: 42
Message-ID: <l3dahpFa9lvU1@mid.individual.net>
References: <uqqris$h7jd$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net jBmudEhkt4Zhxzv32/bEfwrktHQDNk/HuamilNHL5B7RTmtLdy
Cancel-Lock: sha1:gzIL4I+ave1ZuQte8U6KwYRBGwI= sha256:M/DUCzqvwcSmh9+6O2KTBQtF+swhUH4V/+iJKvmbcqQ=
Mail-Copies-To: nobody
X-Face: _.g>n!a$f3/H3jA]>9pN55*5<`}Tud57>1<n@LQ!aZ7vLO_nWbK~@T'XIS0,oAJcU.qLM
dk/j8Udo?O"o9B9Jyx+ez2:B<nx(k3EdHnTvB]'eoVaR495,Rv~/vPa[e^JI+^h5Zk*i`Q;ezqDW<
ZFs6kmAJWZjOH\8[$$7jm,Ogw3C_%QM'|H6nygNGhhl+@}n30Nz(^vWo@h>Y%b|b-Y~()~\t,LZ3e
up1/bO{=-)
User-Agent: slrn/1.0.3 (Darwin)
 by: Jolly Roger - Sun, 18 Feb 2024 03:06 UTC

On 2024-02-17, Oscar Mayer <nobody@oscarmayer.com> wrote:
>
> Here's how to protect against the iPhone GoldPickaxe trojan.
> https://9to5mac.com/2024/02/16/protect-against-iphone-trojan-goldpickaxe/
>
> Goldpickaxe malware can collect an iOS user's biometric information
> from iPhone photos, SMS text messages, intercept web activity, and
> more.
>
> While the iPhone trojan was first found distributed through the iOS
> TestFlight beta testing system, Apple was able to shut that down (at
> least for now).
>
> However, the latest evolution has seen GoldPickaxe being distributed
> through malicious iOS mobile device management (MDM) profiles.

Misleading clickbait.

The “facial recognition data” in question here is absolutely NOT Apple’s
Face ID data. Instead, it’s a particular Vietnamese banking app which
requires its own separate facial scans from its users that was
compromised.

Also, the app was NEVER available in Apple’s App Store. Instead, users
had to install the app through Test Flight from an untrusted developer
account. And after Apple revoked the associated developer account, users
had to manually install an untrusted Mobile Device Management (MDM)
profile in order to install the app.

Details here, for anyone interested:
https://www.group-ib.com/blog/goldfactory-ios-trojan/

While (thankfully) customers outside the EU have to jump through such
hoops to be compromised, EU customers who use alternative apps stores
should buckle up for a rough ride, because the risk of them falling
victim to this sort of thing is about to get a lot higher. 😉

--
E-mail sent to this address may be devoured by my ravenous SPAM filter.
I often ignore posts from Google. Use a real news client instead.

JR

Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan

<l3dak7Fa9lvU2@mid.individual.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=12344&group=misc.phone.mobile.iphone#12344

  copy link   Newsgroups: misc.phone.mobile.iphone
Path: i2pn2.org!i2pn.org!nntp.comgw.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: jollyroger@pobox.com (Jolly Roger)
Newsgroups: misc.phone.mobile.iphone
Subject: Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan
Date: 18 Feb 2024 03:07:51 GMT
Organization: People for the Ethical Treatment of Pirates
Lines: 16
Message-ID: <l3dak7Fa9lvU2@mid.individual.net>
References: <uqqris$h7jd$1@dont-email.me> <Yd7AN.292221$Ama9.97314@fx12.iad>
<uqr2hq$im91$1@dont-email.me>
X-Trace: individual.net g0vXvXBBU18BbHPxxO/GVQBBTr6oIcmn80vVVxN4dCSP9QsVpt
Cancel-Lock: sha1:kMEkuI01jZkmkSIgnR17GI/tQ5U= sha256:CBakI5c5Rg0HzTJY2MRrBWeyldYVeorrJHU88s0sruU=
Mail-Copies-To: nobody
X-Face: _.g>n!a$f3/H3jA]>9pN55*5<`}Tud57>1<n@LQ!aZ7vLO_nWbK~@T'XIS0,oAJcU.qLM
dk/j8Udo?O"o9B9Jyx+ez2:B<nx(k3EdHnTvB]'eoVaR495,Rv~/vPa[e^JI+^h5Zk*i`Q;ezqDW<
ZFs6kmAJWZjOH\8[$$7jm,Ogw3C_%QM'|H6nygNGhhl+@}n30Nz(^vWo@h>Y%b|b-Y~()~\t,LZ3e
up1/bO{=-)
User-Agent: slrn/1.0.3 (Darwin)
 by: Jolly Roger - Sun, 18 Feb 2024 03:07 UTC

On 2024-02-17, Oscar Mayer <nobody@oscarmayer.com> wrote:
> On Sat, 17 Feb 2024 13:50:32 -0500, Alan Browne wrote:
>
>> Vector 2: Similar - (MDM profile) something for co. IT people to look
>> into as well as warn their users against social engineered attacks.
>> Pretty close to a nothing burger.
>
> It shows Apple didn't test properly.

Nah.

--
E-mail sent to this address may be devoured by my ravenous SPAM filter.
I often ignore posts from Google. Use a real news client instead.

JR

Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan

<uqsaaq$u8p8$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=12345&group=misc.phone.mobile.iphone#12345

  copy link   Newsgroups: misc.phone.mobile.iphone
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: hugybear@gmx.net (Jörg Lorenz)
Newsgroups: misc.phone.mobile.iphone
Subject: Re: Here's how to protect against the iPhone GoldPickaxe iOS trojan
Date: Sun, 18 Feb 2024 08:07:06 +0100
Organization: Camembert Normand au Lait Cru
Lines: 10
Message-ID: <uqsaaq$u8p8$1@dont-email.me>
References: <uqqris$h7jd$1@dont-email.me> <l3dahpFa9lvU1@mid.individual.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Sun, 18 Feb 2024 07:07:06 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="83cfc3f8080c1381f072915b86ca0cda";
logging-data="992040"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+icKUaOKOQb6eQbnYLnAhDFrsBe6/i4hg="
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:115.0)
Gecko/20100101 Thunderbird/115.7.0
Cancel-Lock: sha1:MwevU/TNL82b3LYWxwSq0+OS0MA=
Content-Language: de-CH
In-Reply-To: <l3dahpFa9lvU1@mid.individual.net>
 by: Jörg Lorenz - Sun, 18 Feb 2024 07:07 UTC

Am 18.02.24 um 04:06 schrieb Jolly Roger:
> EU customers who use alternative apps stores
> should buckle up for a rough ride, because the risk of them falling
> victim to this sort of thing is about to get a lot higher. 😉

Has no practical relevance.

--
"Gutta cavat lapidem." (Ovid)

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor