Photo of iPhone Keyboard
© Sina Salehian/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Attackers only need a few minutes to set up spyware keyboards and surreptitiously monitor everything iPhone users type, cybersecurity company Certo Software said in a report on Monday.

These spyware keyboards, indistinguishable from standard iOS keyboards, can be used to record passwords, 2FA codes, browsing history, private messages, notes, and just about anything users type on any iPhone.

“After receiving multiple reports of cyberstalking incidents, where stalkers appeared to know everything that their target had typed into their iPhone, Certo’s threat lab launched an investigation,” the mobile security company said, adding that security patches alone would be insufficient to fix this issue.

How Cybercriminals Hack iPhone Keyboards

According to Certo, hackers can easily install apps with custom keyboards on a target’s iPhone. These keyboards have keylogging capabilities and are available for as low as $30. It’s not uncommon to find such tools on dark web marketplaces and criminal Telegram channels.

Certo did not name the particular spyware apps used in these attacks. However, the company explained that these custom keyboards are configured to have “Full Access” to devices. Attackers replace the iPhone’s default keyboard with the custom keyboard, ensuring users’ keystrokes are sent to “an online portal” where they can access it.

The spyware Certo analyzed is distributed via the TestFlight beta testing platform. “By deploying via TestFlight, spyware developers are likely attempting to avoid detection by Apple. This is because TestFlight apps are not subjected to the same strict review process as apps from the main App Store,” the report said.

However, Certo warned that malicious custom keyboards can be hidden in any “seemingly harmless app.”

How to Disable Suspicious Keyboards on Your iPhone

To check if any malicious custom keyboards have been installed on your iPhone, go to Settings > General > Keyboard > Keyboards. You will see all the keyboards currently installed on your device. By tapping on each one, you can see whether it has “Full Access” toggled.

The default keyboards you don’t need to worry about are “English” and “Emoji.” You may also see “Grammarly,” for instance, but that belongs to a well-known grammar-checking service. If you find an unknown keyboard you do not recognize or trust with “Full Access” enabled, disable it by tapping Edit > the red minus button > Delete.

In the case of Grammarly, the company’s CEO, Brad Hoover, responded to a question about keyboard access last year, saying: “Also, the Grammarly Keyboard only reads and corrects the text you type while using it. This means that Grammarly does not see information from any of your other keyboards, including the default keyboard for iOS.”

“Apple also has a role to play in enhancing device security. Simple steps, like alerting users to keyboards with full access and scrutinizing TestFlight app submissions more closely, could make a significant difference,” Certo added.

Read our guide to what to do if your phone is hacked for additional cybersecurity tips.

For more information, follow us on X (Twitter), Threads, and Mastodon!

Leave a comment