KeyRaider

KeyRaider is malware that steals Apple account credentials and other data from jailbroken iOS devices. It also has ransomware functionality. [1]

ID: S0288
Type: MALWARE
Version: 1.0
Created: 25 October 2017
Last Modified: 24 October 2022

Techniques Used

Domain ID Name Use
Mobile T1638 Adversary-in-the-Middle

Most KeyRaider samples hook SSLRead and SSLWrite functions in the itunesstored process to intercept device communication with the Apple App Store.[2]

Mobile T1426 System Information Discovery

Most KeyRaider samples search to find the Apple account's username, password and device's GUID in data being transferred.[1]

References