YiSpecter is an iOS malware family that targets Apple mobile devices and is notable for abusing Apple enterprise app signing to install malicious applications on non-jailbroken iPhones outside the official App Store. It has been observed using enterprise certificates to sideload malicious apps, giving operators an initial-access path that bypasses normal consumer app distribution channels.
Once installed, YiSpecter performs device and process discovery on compromised iOS systems. Reported behaviors include collecting information about running processes as well as harvesting device identifiers such as the device UUID and MAC address. It also communicates with command-and-control infrastructure over HTTP, enabling remote tasking and data transmission.
The available evidence supports classifying YiSpecter as iOS surveillance-oriented malware with backdoor-like command-and-control functionality rather than a purely destructive or financially focused payload. Its known behavior centers on host profiling, process enumeration, and exfiltration of collected device information from compromised iOS devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
iOS malware that abuses enterprise certificates to install on non-jailbroken devices.
iOS malware that collects the device UUID.
iOS malware that collects the device UUID.
Mobile malware that connects to command-and-control infrastructure over HTTP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.