Cyber Security News

New iPhone Hack Convinces Users With Fake Lockdown Mode

A post-exploitation tampering technique has been discovered that allows the malware to visually trick the user into thinking their iPhone is in Lockdown Mode.

While iOS devices with Lockdown Mode have a smaller attack surface, it’s crucial to keep in mind that Lockdown Mode does not prevent malware from executing after a device has been compromised.

Lockdown Mode does not identify malware that has already been installed, it does not act as antivirus software, and it has no effect on the ability to spy on a device that has already been infiltrated.

Truly, its effectiveness lies in limiting the number of entry points that an attacker can exploit before an attack occurs.

False Sense of Security with Lockdown Mode

In September 2022, Apple implemented Lockdown Mode in reaction to an increase in worldwide cyberattack campaigns.

To prevent possible attackers from accessing all functionality, Lockdown Mode reduces it. Despite being simple, this strategy is strong because the less code you expose, the fewer opportunities attackers have to exploit weaknesses in your device.

iOS 16 or later, iPadOS 16 or later, watchOS 10 or later, and macOS Ventura or later all support lockdown mode. WatchOS 10, macOS Sonoma, iPadOS 17, and iOS 17 all offer additional protection.

What Lockdown mode disables?

Certain file formats will no longer be supported when Lockdown Mode is activated, mostly because of their history of exploitation. Additionally, it will turn off convenient features like the ability to preview URLs received through Messages, turn off shared albums, stop configuration profile installations, and block enrollment in mobile device management (MDM) software.

“While Lockdown Mode has proven its effectiveness in certain scenarios, our evaluation of Lockdown Mode emphasizes that it won’t stop an attack that has already been initiated on the device”, Jamf Threat Labs said in a report shared with Cyber Security News.

Fake Lockdown Mode in Safari

“When Lockdown Mode is enabled, your device won’t function like it typically does. To reduce the attack surface that potentially could be exploited by highly targeted mercenary spyware, certain apps, websites, and features are strictly limited for security and some experiences might not be available at all”, according to Apple.

There is a warning for iPhone users: locking down won’t stop malware that has already gained access to the system if your device has already been compromised.

Rather than adding more security mechanisms to stop malicious payloads from being executed, Lockdown Mode’s main goal is to decrease potential attack vectors.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago