CSIDB logo
Incident

BigBoss

Incident posture

Attack window
Jul 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-02-01 16:10

Linked entities

Victim
BigBoss
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major Cydia repository for jailbreak tweaks was compromised by hackers identifying as "Kim Jong-Cracks," resulting in the theft of all paid and free software packages. The attackers created a rival site named ripBigBoss hosting the stolen content for free, while promoting hashtags linked to a purported ideological motivation tied to Cydia's creator. Although the hackers claimed to inject malware into the packages, cryptographic verification mechanisms indicated no unauthorized modifications to the original repository's content. The incident prompted advisories against using the pirated repository due to potential security risks.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In July 2014, the BigBoss repository—a default source for jailbreak tweaks on Cydia serving jailbroken iOS devices like iPhones, iPads, and iPod Touches—was compromised by hackers identifying as "Kim Jong-Cracks." The attackers exfiltrated all 13,954 packages from the repository, encompassing both paid and free software tweaks. They established a competing site named "ripBigBoss," hosting the stolen packages without charge and providing downloadable evidence of the breach, including the repository’s deb index and database containing package names and MD5 checksums. The group cited Saurik’s (Cydia creator Jay Freeman) "Competition vs Community" commentary as motivation for their actions, while promoting hashtags #WhichSideAreYouOn and #SupportTheCompettition. Kim Jong-Cracks asserted they had injected malware into the redistributed packages, though no technical evidence corroborated this claim at the time of reporting.

Saurik publicly disputed the malware assertion, clarifying that Cydia repositories cryptographically verify packages against repository indices, with no unauthorized changes detected in BigBoss’s historical package data. Despite this assurance, security advisories urged users to avoid installing or updating tweaks from the official BigBoss repository pending further investigation. ripBigBoss was explicitly flagged as a risk due to potential malware in pirated packages. The incident disrupted trust in a primary distribution channel for jailbreak utilities, exposing paid developers to revenue loss from pirated redistributions while creating uncertainty around repository integrity verification mechanisms. No containment measures by BigBoss or Cydia administrators were detailed in available reports.

Sources

Sources available to members: 1 source.

CSIDB