In short: On 6 August 2026 Kaspersky reported that trojanised copies of popular iPhone apps — a marketplace client, a photo editor and a video service — are being handed out through a Russian-language Telegram channel. They install outside the App Store: you download an IPA file, buy a developer certificate from the seller and sign the app. Once open, a hidden module collects device data, location and screenshots. The fix is simple: install iOS apps only from the App Store.
What happened
Kaspersky researchers discovered modified versions of well-known iPhone apps circulating in a Telegram channel. Outwardly these are the same familiar programs — an online marketplace, a photo editor, a video-watching service — but attackers have embedded a malicious module inside the real app. The bait is convenience: users are promised a "working" build without the usual App Store restrictions. Our blog's security breakdowns keep returning to the same lesson — the download source matters more than the app's name.
This is not a jailbreak and not a hole in iOS itself. It is social engineering wrapped around Apple's own sideloading mechanics, and that is exactly why it slips past people who trust the brand of the app rather than where it came from.
How the scheme works
The chain has several manual steps, and each one is a red flag. The channel publishes an installer file (an IPA). To make iOS run it, the victim has to obtain a developer certificate — sold by the same attackers — and import it into a third-party signing tool such as eSign or Scarlet. The signed app then installs, bypassing the App Store entirely. In other words, the user is talked into manually stripping away Apple's main safety check and trusting a certificate controlled by a stranger.
What the malware collects
While the app is open, the hidden module gathers device name, battery level, regional settings, memory details and whether the phone is jailbroken, and it can also read geolocation, the mobile operator code and take screenshots, sending it all to the attackers. There is one important limitation: the malware cannot work in the background — it only harvests data while its host app is on screen. That reduces the damage but does not remove it: a photo editor or a shopping app is open often enough, and a single screenshot can expose a message, a code or a payment detail.
What it means for you
The takeaway is not "iPhones are unsafe." The App Store review process specifically exists to catch this, and the attack only works once a user is persuaded to route around it. The real risk is the habit of chasing a "free" or "unlocked" build off-platform. On mobile, the install source is the security boundary — see our overview of what actually protects your data. A device name, your location and screenshots are exactly the fingerprints used to build a profile of you and target follow-up scams.
How to protect yourself
First, install iOS apps only from the App Store. If a program you need is not there, look for it on the developer's official site — never from a chat that also sells you the certificate to run it. Second, if you have already installed such a build, delete it, and in Settings → General → VPN & Device Management remove any unfamiliar developer certificate or configuration profile. Third, keep iOS and your apps updated, and review app permissions (location, screen recording).
Finally, add a network privacy layer. A VPN does not scan apps for malware — that is not its job — but on public and untrusted networks the LiMP VPN app encrypts your traffic so the network owner and provider cannot see which services you use, and thanks to its no-logs policy the service itself keeps no record of your activity. Keep the layers distinct: the App Store guards what runs on the device, a VPN guards your data on the network.
