IOS 15.7 and previous versions are affected, and attackers use Apple iMessage to spread malware
CTOnews.com June 2, according to the latest report released by Kaspersky, there are attackers using iMessage to spread malware, iOS 15.7 and previous versions are affected.
After analyzing the problem device through mvt-ios (iOS Mobile Verification Kit), Kaspersky found that the attacker could send information through iMessage. After receiving the message, the victim could trigger a vulnerability in the system and execute arbitrary malicious code without any user interaction.
The vulnerability downloads other malicious scripts from the command and control (ClearC) server to elevate its privileges, clean up signs of intrusion, steal user data, and so on.
Kaspersky says the malicious script is not persistent and will be reset after the user restarts the device. As of June 2023, the vulnerability was only valid for iOS 15.7 and earlier, CTOnews.com reported, citing Kaspersky.
The original report of Kaspersky is attached to CTOnews.com, which can be read by interested users.