Recently, iOS SDK found spying and involved with Ad fraud and data leak on billions of iOS users. The iOS SDK is quite famous, and it is used by nearly 1200 apps, along with billions of mobile users, not only this, but SDK also has over 300 million combined downloads per month.
This data breach carried some malicious code, and its motive was to perpetrating mobile ad-click fraud and obtaining sensitive information of the users.
This data breach was detected by the cybersecurity firm Snyk, and later the researchers of the cybersecurity firm named this data breach as “SourMint.”
According to the experts from Synk, when a user taps on an ad that is not assisted by the Mintegral network, the SDK inserts itself into the referral method. Therefore it starts deceiving iOS into as the user had clicked on different ads.
The main motive of this ill-disposed data breach was that the threat actors make the users click on ads inside the app. These ads are mostly present in mobile applications; that’s why the advertisements are often impersonated by ad networks that the developer blends into their code.
The advertisers pay the ad networks to promote their ads, and these are credited to the appearance and performance of the ad. Through this network chain, all the app developers get some profits by the advertisement and the ad network gains from the advertisers.
These advertisements are quite profit-making, and that’s why the threat actors always prefer ad fraud. And these ad frauds are quite easy to perform as well.
In this data breach, the SDK has managed to obtain a hefty amount of data that includes:-
This data breach consisted of some very unusual technical exploit data, they are:-
The data that are involved in this data breach are mentioned below:-
This data breach contains much delicate information, and the attackers have stolen the personal information of the users. However, the experts are investigating the whole matter thoroughly, and they would soon update the information regarding this breach.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Attackers are exploiting the recently discovered critical security vulnerability tracked as (CVE-2023-46604) affecting Apache ActiveMQ…
Media reports highlight the sale of LLMs like WormGPT and FraudGPT on underground forums. Fears…
An open-source security scanner, developed by Git Hub user Adam Swanda, was released to explore…
One of Slovenia's major power providers, HSE, has recently fallen victim to a significant cyberattack.…
In the labyrinthine landscape of cyber threats, the Trend Micro Managed XDR team has uncovered…
BOSTON, MASS. and TEL AVIV, ISRAEL, November 28, 2023 - A severe design flaw in…