XLoader for iOS is an iOS malware family associated with mobile device profiling and data theft. Documented behavior includes collecting device-identifying information such as UDID, version and product information, and subscriber or hardware identifiers including IMEM, ICCID, and MEID. The malware has also been observed exfiltrating stolen data over HTTP, indicating use of standard application-layer network traffic for outbound theft and likely command-and-control blending. The available reporting supports XLoader for iOS as a mobile surveillance or information-stealing threat focused on harvesting host metadata from compromised iOS devices. High-confidence public details in the available material are limited, and no specific initial infection vector, industry targeting, or threat-actor attribution is established here.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
iOS malware family that exfiltrates data using HTTP requests.
iOS variant of XLoader that obtains device UDID, version number, and product number.
iOS malware that obtains device UDID, version number, and product number.
iOS malware that exfiltrates data using HTTP requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.