Please Stop Trying to Pay Me to Advertise Fake iOS Jailbreak Websites

Credit to Author: Joseph Cox| Date: Fri, 08 Nov 2019 13:44:07 +0000

Jailbreaking your phone can lead to all sorts of issues, such as not getting important security patches or further opening up your device to attack. If you did want to take that risk, you first have to find somewhere to download a jailbreaking tool that actually works. With that in mind, a marketing firm is, presumably on behalf of some clients, trying to pay journalists to write articles that link to fake jailbreaking websites.

The sites are fake in that they are not the sites of the original jailbreak creators. There isn't an immediate indication that the files they are linking to are malicious, but it still shows a deceptive and opportunistic side of someone trying to ride the wave of the jailbreaking community.

"Hi Admin / Advertising Team, Looking for a place to publish a paid guest post about iOS Jailbreaking," Madusanka Premaratne, the co-founder of a marketing company, wrote in an email addressed to me and VICE's sales team.

Premaratne's company Insfra Technologies offers services such as search engine and app store optimization, helping its customers get better rankings on each respectively, according to the company's website. The site also contains nonsensical industry buzz terms, such as "We use AI-based analytics & internal monitoring systems to analyze the digital performance."

Know anything about fake jailbreaks? You can contact Joseph Cox securely on Signal on +44 20 8133 5190, Wickr on josephcox, OTR chat on jfcox@jabber.ccc.de, or email joseph.cox@vice.com.

Premaratne's idea was that he would pay me to occasionally link back to a series of jailbreaking related websites, he said in a follow-up email. These include a knock-off version of the site for the "Yalu" jailbreak.

"It's a domain name squatter," iOS hacker Luca Todesco told Motherboard in an online chat when asked about the fake website, referring to someone who registers a domain name similar to another often to mislead web users. The fake domain uses the Yalu name and is a top result on Google.

Another of the websites Premaratne wanted to pay me to promote was one for an iOS 9 hack from the Taig jailbreak group. The problem, though, is that "Taig never released an iOS 9 jailbreak," Todesco added.

The purpose of these promotions is unclear, be that generating more ad revenue or something else. Premaratne stopped responding to my emails when I asked for more information.

Subscribe to our new cybersecurity podcast, CYBER.

This article originally appeared on VICE US.

http://www.vice.com/en_ca/rss