WireLurker is a Mac and iOS malware family discovered in 2014 that infected trojanized OS X applications distributed through the Maiyadi third-party app store and then propagated to connected iPhones over USB. It is notable for targeting non-jailbroken iOS devices by abusing enterprise provisioning and trusted host relationships established through device pairing. On infected Mac systems, WireLurker used OS X persistence mechanisms including Launch Daemons and monitored for attached iOS devices. When a device was connected, it attempted to install malicious applications onto the iPhone and collect data from the mobile device, including contacts and text messages. The operation was associated with a China-based ecosystem and is widely cited as an early example of cross-platform malware bridging desktop and mobile Apple environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile malware cited as an example of prior malware installing malicious apps on non-jailbroken iPhones.
Named trojan referenced as discovered in 2014; no additional technical behavior described in the content.
Mac Malware of 2016 ... WireLurker ...
OS X malware distributed through trojanized apps that uses launch daemons, surveys the host, accesses contacts and texts, and can infect connected iPhones via USB.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.