A security researcher showed that the anti-reverse-engineering controls in an anonymized 64-bit iOS banking app dubbed VIBA could be bypassed despite extensive runtime self-protection. The app used obfuscation, encrypted strings, anti-jailbreak checks, anti-Frida logic, debugger detection, file-integrity validation, and large volumes of raw syscalls to resist analysis on modified devices. The researcher found several protections relied on weak patterns, including simple XOR string decryption, recognizable success and failure constants, and ptrace and exit syscalls that could be patched out, allowing checks for Frida files, port 27042, injected dylibs, jailbreak artifacts, and Info.plist integrity to be defeated through static patching and runtime hooking.
Separate malware analysis detailed a stealth-focused macOS backdoor known as Tiny FUD that masquerades as Apple-like processes, hides itself from Finder, and communicates with a command-and-control server at 69.197.175.10:9999. The trojan collects host identifiers including UUID, username, hostname, and kernel version, executes remote commands, and captures screenshots every five minutes for exfiltration. Researchers said the sample also used self-signing with permissive entitlements, DYLD-related injection support, and cleanup routines to erase traces and terminate itself and child processes, and they published indicators including SHA-256 d64e2688344c685c4156819156bdb15630d1168314b21c919eee5540b1beb54a, related domains, and a YARA rule to aid detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A researcher published an analysis of the iOS banking app anonymized as VIBA, detailing its anti-reverse-engineering and runtime self-protection mechanisms and showing how jailbreak, Frida, dylib injection, debugger, and integrity checks could be bypassed.
A researcher published an analysis of the Tiny FUD macOS backdoor, describing its stealth features, C2 communications, screenshot capture behavior, and indicators of compromise including a SHA-256 hash and YARA rule.
A researcher documented reversing an unnamed iOS banking app's obfuscated syscall-based jailbreak detection, including identifying stat64 checks against /private/var/lib/apt and patching multiple similar checks. The post also introduced a Frida-based iOS syscall tracer to reveal syscall names and arguments during dynamic analysis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
developer.apple.com
Open sourcejuliangrtz.me
Open sourcedenwp.com
Open sourcejuliangrtz.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.