Press Releases

Report Finds Rate of iOS Malware Increasing Faster than Android Malware at iPhone Ten Year Anniversary

Number of Disclosed iOS Vulnerabilities in Q1 2017 Surpassed All of 2016

Palo Alto, Calif. — July 18, 2017 – Skycure, the leader in mobile threat defense, today released the company’s latest mobile threat intelligence report, “10 Years of (Hacking) iOS“. The report examines the security impact of iOS on the enterprise over the past ten years, and includes Skycure analysis of iOS mobile threat data from the first quarter of 2017. The study found that as iOS has become more popular as a platform, especially for enterprise executives and government agency officials, the rate of attack and incidents of malware have increased. According to the report, the percentage of enterprise iOS devices that have malicious apps installed today has more than tripled since Q3 2016. In comparison, the rate of Android malware infections has stayed relatively flat. In addition, the number of disclosed vulnerabilities in the first quarter of 2017 was greater than all of 2016.

Yair Amit, co-founder and CTO of Skycure said, “iOS has had a profound effect on the security of enterprises. The iPhone ushered in the trend of BYOD, and the concept of apps and the app store, changing how IT manages corporate networks and equipment. The impact of iPhones and iPads on work productivity means more employees are choosing iOS devices for BYOD, and that makes iOS a valuable target for hackers. The number of vulnerabilities and malware does not indicate how secure a platform is, but it does indicate how often hackers are attempting to break into it. Increasing malware and vulnerabilities demonstrate that hackers want to break into iOS devices. Enterprises need to make sure that they don’t find a way in.”

There’s a (Malicious) App for That

The Skycure study reports that malware on iOS devices is becoming more prevalent as the sophistication of exploits continues to increase. The rate of iOS malware has continued to increase and tripled from Q3 2016 to Q1 2017.

Apple does a tremendous job of keeping malware out of the App Store. Common misconception is that iOS devices can’t get malware because apps must come from the Apple App Store. In truth, there are many ways to infect an iOS device, according to the Skycure report. The Skycure report lists the following methods and examples of threats that exploited them to infiltrate devices:

  • Via App Store (example known campaign includes XcodeGhost)
  • Via malicious app using Apple-approved certificate (example known campaign includes AceDeceiver)
  • Via sideloaded app (example known campaign includes Yispecter)
  • Via jailbroken device (example known campaign includes Xsser mRAT)
  • Via cable (example known campaigns include Wirelurker, Malicious Chargers)
  • Via malicious settings (example known campaign includes Malicious Profiles)
  • By leveraging an OS vulnerability (example known campaign includes Pegasus)

Today’s attacks are becoming very good at hiding their presence to extend the period of control or spying access. XcodeGhost exploited the iOS development environment itself to get malware into the App Store. The report includes a “Mobile Kill Chain” to demonstrate the step-by-step process used by the most dangerous mobile threats today, beginning with targeted social engineering to get the victim to click or install something, then jailbreaking the device, and ending with the bad guys having access to GPS, camera, microphone, SMS, email, and other apps.

Publicly Disclosed Vulnerabilities are on the rise but iOS Devices are Patched Quickly

One of the most important things that can be done to secure a mobile device is to be sure it is on the latest security patch. Despite the increase in malware, iOS devices have a much shorter window of vulnerability to any exploit because they are more likely to have the most updated security patches. In the Skycure study, 91 percent of active devices were on the latest major version (iOS 10) at the end of Q1, and 22 percent were on the latest minor release (iOS 10.3). By comparison, only 21 percent of Android devices were on the most recent Android version (7.0 – Nougat). A previous Skycure reportfound that 71 percent of Android devices still run on security patches more than two months old.

iOS and Risky Network Exposure

The Skycure report also examined the risk of network exposure on iOS devices, finding the following in Q1 of this year:

  • iOS devices in Europe connect to more risky networks and experience a higher rate of network incidents than iOS devices in the US
  • iPads are much less likely to connect to risky networks than iPhones. About 39 percent of iPhones experienced risky network incidents, averaging over seven incidents per affected device, while only 25 percent of iPads were exposed, averaging only five incidents each.

In any typical organization, about 21 percent of all mobile devices will be exposed to a network threat in the first month of security monitoring. This number goes to 41 percent over the next three months.

Top Five Recommendations to Keep Your iOS Device Safe

The Skycure researchers offered the following tips to keep iOS devices safe:

  1. Don’t click, install or connect to anything that you are not confident is safe.
  2. Only install apps from reputable app stores.
  3. Don’t perform sensitive work on your device while connected to a network you don’t trust.
  4. Always update to the latest security patch as soon as it is available for your device.
  5. Protect your device with a free mobile security app like Skycure –

For details and to learn more about how Skycure Mobile Threat Defense protects organizations and prevents cyber attacks without compromising the mobile user experience or privacy, visit

About the Mobile Threat Intelligence Report

The Skycure Mobile Threat Intelligence Report reviews worldwide threat intelligence data. Today’s report is based on millions of monthly security tests from January through March 2017 and includes both unmanaged devices and those under security management in enterprise organizations. Data includes Skycure’s proprietary Mobile Threat Risk Score, which acts as a credit score to measure the risk of threat exposure for mobile devices. For organizations, Skycure condenses millions of data points to calculate a risk score so that IT can quickly discern the state of the overall system and the risk to each device. Skycure analyzes 1 million apps and more than 1.5 million unique networks worldwide every year.

About Skycure

Skycure is the leader in mobile threat defense. Skycure’s platform offers unparalleled depth of threat intelligence to predict, detect and protect against the broadest range of existing and unknown threats. Skycure’s predictive technology uses a layered approach that leverages massive crowd-sourced threat intelligence, in addition to both device- and server-based analysis, to proactively protect mobile devices from malware, network threats, and app/OS vulnerability exploits. Skycure Research Labs have identified some of the most-discussed mobile device vulnerabilities of the past few years, including App-in-the-Middle, Accessibility Clickjacking, No iOS Zone, Malicious Profiles, Invisible Malicious Profiles, WifiGate and LinkedOut. The company was founded by security industry veterans Adi Sharabani and Yair Amit and is backed by Foundation Capital, Shasta Ventures, Pitango Venture Capital, New York Life, Mike Weider, Peter McKay, Lane Bess, and other strategic investors.


Chris Fucanan
AquaLab PR for Skycure