Chinese Authorities Shut Down WireLurker Distribution Site, Arrest Suspects Involved - MacRumors
Skip to Content

Chinese Authorities Shut Down WireLurker Distribution Site, Arrest Suspects Involved

lightning_usb_cable_0_5_mLast Friday, Chinese authorities arrested three individuals that are suspected of developing the "WireLurker" malware, which infected thousands of mobile devices in China after Mac users installed malicious software from a third-party App Store.

According to a police post on Chinese social network Sina Weibo, the three men were arrested in Beijing on suspicion of "manufacturing and distributing" WireLurker after police received a tip from Chinese security company Qihoo 360 technology. In addition to arresting the suspects involved in the creation of the malicious software, Chinese authorities also shut down the site that was spreading it.

First publicized by researchers in early November, WireLurker is a trojan that infected thousands of Chinese iOS and Mac users after they installed software from the Maiyadi App Store, a third-party app platform that delivered more than 400 infected OS X applications.

WireLurker was able to attack iOS devices through Macs using USB, and was described as heralding "a new era in malware attacking Apple's desktop and mobile platforms." After being installed on a Mac, WireLurker would infect an iOS device using enterprise provisioning, making it the first malware capable of installing third-party applications on non-jailbroken iOS devices.

At the time information was published on WireLurker, infected apps had already been downloaded more than 356,104 times. Apple quickly took steps to block the infected apps, preventing them from launching, and in a statement, it reminded users not to install software from untrusted sources.

Just a week after WireLurker surfaced, another vulnerability in iOS was publicized by researchers. Called Masque Attack, it also infects iOS devices using enterprise provision profiles and is somewhat more dangerous, as it can replace existing apps with nearly undetectable fake versions.

Though it hasn't been found in the wild, Masque Attack prompted a warning from the U.S. government and a statement from Apple, with the company once again encouraging customers to download apps only from trusted sources.

Neither Masque Attack nor WireLurker are likely to affect the average iOS user as long as Apple's security features are not bypassed, as both vulnerabilities circumvent the App Store and Mac App Store to install apps.

Popular Stories

Four iPhone 18 Pro Colors Mock Feature

iPhone 18 Pro: Pre-Orders and Release Date

Thursday August 20, 2026 8:00 am PDT by
Apple has yet to reveal when the iPhone 18 Pro and iPhone Ultra will be announced and released, but the dates usually follow a familiar pattern. As usual, the iPhone event is expected to take place in the first half of September. Labor Day falls on September 7 this year. The last time the holiday was on that day was in 2020, but the iPhone event that year was delayed until October due to...
macOS 27 next to MacBook Pro Running macOS 27

macOS Golden Gate Marks the End of an Era

Thursday August 20, 2026 2:19 pm PDT by
macOS 27 Golden Gate is not compatible with any Macs with Intel processors, marking the end of an era. The update, which is currently in beta ahead of a release later this year, is limited to Apple silicon Macs with an M1 chip or newer. Last year, Apple said that macOS 26 Tahoe would be the final macOS release compatible with Intel-based Macs, so this was an expected development. Intel...
Aston Martin CarPlay Ultra Screen

Apple Says CarPlay Ultra is Coming to These Vehicle Brands

Wednesday August 19, 2026 12:53 pm PDT by
Last year, Apple launched CarPlay Ultra, the long-awaited next-generation version of its CarPlay software system for vehicles. More than a year later, CarPlay Ultra is still limited to Aston Martin's latest luxury vehicles, but that should change in the foreseeable future. In May 2025, Apple said many other vehicle brands planned to offer CarPlay Ultra, including Hyundai, Kia, and Genesis. ...

Top Rated Comments

mgipe Avatar
154 months ago
Probably gave them an offer they couldn't refuse: go on the government payroll or go to jail.
Score: 13 Votes (Like | Disagree)
154 months ago
I will need to see more evidence before i'm convinced that this so called arrest isn't just propaganda.
Score: 11 Votes (Like | Disagree)
154 months ago
My favorite part of these attacks are the part when I realize that because I download stuff only from the App Store and my company's website, I'm good. Love that security.
Score: 8 Votes (Like | Disagree)
macs4nw Avatar
154 months ago
"Neither Masque Attack nor WireLurker are likely to affect the average iOS user as long as Apple's security features are not bypassed, as both apps circumvent the App Store and Mac App Store to install apps."

And that's the key portion of the article, my friends. Live 'dangerously' at your own peril.
Score: 8 Votes (Like | Disagree)
Tzerlag Avatar
154 months ago
PLA unit 61398 didn't like the competition.
Score: 7 Votes (Like | Disagree)
nepalisherpa Avatar
154 months ago
There will be lurkers waiting for them in the prison. Good job!
Score: 6 Votes (Like | Disagree)