On 16 September 2015 an iOS developer in China flagged the malware on Weibo, the first public mention. The next day Alibaba's security researchers published their analysis and gave it a name, XcodeGhost, and Claud Xiao of Palo Alto Networks published his own the same day. The mechanism was ordinary. Xcode, Apple's development suite, is a multi-gigabyte download, and from Apple's servers it crawled in China: Phil Schiller would say a week later that an install taking about twenty-five minutes in the United States could take three times as long there. So developers followed links on forums to copies held on Baidu's cloud storage, versions 6.1 to 6.4 — and one of those copies had been altered to build a passenger into every app it compiled.
The passenger reported home: the time, the app's name and bundle identifier, the device's name and type, its language, country, UUID and network type, to a server at init.icloud-analysis.com, dressed to look like Apple's. Xiao's first post found two infected apps in the App Store, NetEase's Cloud Music among them. By 18 September Palo Alto listed thirty-nine, and the names were the ones that mattered in China: WeChat 6.2.5, Didi Chuxing, Railway 12306, CamCard, China Unicom's mobile office suite, the Tonghuashun stock-trading app. Tencent said it had shipped WeChat 6.2.6 with the code removed. Then the counts diverged. Qihoo 360 listed 344 apps; the Pangu jailbreak team claimed 3,418; FireEye said within days it had found more than 4,000. Each was a finding, not a total.
Apple began pulling apps on 18 September. That Friday night an account claiming to be the author posted what it called the source code, with an apology, on GitHub; Xiao, who found it, wrote that there was no telling whether the author or the code were real, and no explaining why anyone would own up so quickly. Apple said it had removed the apps it knew had been built with the counterfeit software and was helping developers rebuild them. Palo Alto had shown that same 18 September what else the code could do: raise a fake alert to phish a password, or open any URL it chose. By 23 September Schiller had told Sina that Apple would host Xcode inside China, and would publish a list of the twenty-five most popular infected apps.
The ending took six years. In May 2021, in Epic Games v Apple, the company's internal emails from September 2015 entered the record. Dale Bagwell, the iTunes customer experience manager, had the counts: 128 million customers had downloaded more than 2,500 infected apps, 203 million downloads in all, some 18 million of those customers American and 55 per cent Chinese. Matt Fischer, the App Store's vice-president, asked whether, given the number, they wanted to email all of them, and noted the mass-notification tools were still being tested. Apple published its list of twenty-five and told users to update the affected apps. The total stayed private until a court made it public — and the method, poison the tool rather than the developer, outlived the month by a decade (July 2026).
Words, then actions
On 25 September 2015, at the White House, Barack Obama and Xi Jinping announced a common understanding: neither government would conduct or knowingly support cyber-enabled theft of intellectual property, including trade secrets or other confidential business information, for commercial advantage. It was the first time a Chinese leader had accepted the American distinction between spying for the state and stealing for a company. They added a senior experts group and a complaints channel, and similar wording went into the G20 communiqué that November. Two days earlier, OPM had revised the fingerprint records lost in the breach of June from 1.1 million to 5.6 million. FireEye iSIGHT reported the following June that successful compromises by the China-based groups it tracked had fallen steeply — Fortune put the figure at about ninety per cent over two years — but the fall had begun in mid-2014, and Kevin Mandia credited Mandiant's 2013 report naming a PLA unit, the indictment of five of its officers in 2014 and the threat of sanctions. Quieter tradecraft would have looked the same from outside. By December 2018 Washington was saying the understanding had been broken.
Where nobody was looking
On 9 September Excellus BlueCross BlueShield of Rochester, New York, said intruders had been inside since 23 December 2013 — twenty months before the review it had commissioned from Mandiant, after Anthem, Premera and CareFirst were breached, found them on 5 August — with reach into the records of more than ten million people; it said it knew too little about those earlier investigations to say whether they were connected. The same day Kaspersky's Stefan Tanase showed how the Turla group hid its command servers: listening to the unencrypted downstream of satellite beams over the Middle East and Africa, borrowing paying subscribers' addresses and answering over ordinary lines, so the server could be neither located nor seized. On 15 September FireEye's Mandiant reported SYNful Knock — at least fourteen Cisco routers in Ukraine, the Philippines, Mexico and India running a modified IOS image that survived reboots, took a backdoor password and loaded modules from TCP packets with deliberately wrong sequence numbers. No vulnerability was involved: valid credentials or physical access, Cisco confirmed that day. By 18 September a scan of the internet had found seventy-nine hosts answering the knock, twenty-five on one east-coast provider.
The policy that lasted a day
On 21 September 2015 the Department of Electronics and Information Technology posted a draft National Encryption Policy. Users and businesses were to keep plain-text copies of whatever they sent encrypted for ninety days and produce them on demand; foreign providers were to register before serving Indians, and the government would set the algorithms and key lengths. The objection that carried was practical: plain text held for ninety days so the state could read it is plain text held where anyone else can steal it. DeitY issued an addendum exempting mass-use products — WhatsApp, Facebook, Twitter, online banking and purchases — and on 22 September the IT minister, Ravi Shankar Prasad, withdrew the draft, saying some of its expressions had given rise to uncalled-for misgivings and that it would be reworked. No replacement has been issued in the decade since.
Five days later the prime minister was in California. On 27 September Narendra Modi spent fifty minutes on stage at Facebook's headquarters in Menlo Park with Mark Zuckerberg, taking a few of the forty thousand questions and comments sent in, his voice breaking as he described a childhood in which the family cleaned dishes and carried water at neighbours' houses. Zuckerberg had changed his profile picture to the tricolour that day and offered users the same tool. The page's source named the feature for Internet.org — Facebook's zero-rated service, renamed Free Basics that month and under fire from India's net-neutrality campaigners. Facebook said there was absolutely no connection, that an engineer had mistakenly used the words as shorthand for part of the code, which was being changed. The regulator ended Free Basics in India on 8 February 2016 (February 2016).
Fifty million, and a tap on the screen
On 4 September 2015 Toyota said it would spend $50 million over five years on joint research centres at Stanford and MIT, split evenly between them, and brought in Gill Pratt — the DARPA programme manager who had run its Robotics Challenge — to direct the work. Fei-Fei Li's laboratory at Stanford took decision-making, reasoning and perception; Daniela Rus's at MIT took interfaces and the analysis of human driving, her stated aim a car never responsible for a collision. On 16 September Apple shipped iOS 9 with Proactive suggestions, which guessed at intent from time, place and habit. On 29 September Sundar Pichai introduced Android 6.0 Marshmallow with the Nexus 5X and 6P, and with it Now on Tap, which read whatever was on the screen when the home button was held. Toyota multiplied the bet on 6 November, announcing the Toyota Research Institute with a billion dollars over five years and Pratt as chief executive; the long press that summoned Now on Tap would pass to Google Assistant.
The business model, put in writing
AVG published a privacy policy in mid-September 2015, effective 15 October, that stated what the free anti-virus business had mostly left unsaid: it could collect non-personal data — browsing and search history, advertising identifiers, the device's other applications — build anonymous profiles from it and sell them. Criticism was immediate; AVG said the wording had been rewritten for transparency, that nothing identifying was sold and that collection could be switched off. On 18 September Symantec disclosed that its Thawte authority had issued test certificates for three domains nobody had requested, google.com among them, found by Google in the Certificate Transparency logs Chrome required. Symantec said the keys never left its control, were revoked at once and endangered nobody, dismissed the employees responsible, and watched its own audit raise the count to twenty-three. Four days later Project Zero's Tavis Ormandy showed Kaspersky's unpackers running unsandboxed with SYSTEM privileges — the scanner as the way in; Kaspersky patched within days. Avast bought AVG in 2016; the FTC ordered it in 2024 to pay $16.5 million and stop selling browsing data for advertising.
⏳ Time capsule — September 2015
- On 9 September Queen Elizabeth II became Britain's longest-reigning monarch, at 63 years and seven months surpassing the record set by Queen Victoria.
- On 18 September the US Environmental Protection Agency served Volkswagen notice that some 482,000 of its diesel cars carried software that recognised an emissions test and cleaned up only for it; the company admitted the deception on 20 September, put the worldwide figure at about eleven million vehicles on 22 September, and on 23 September its chief executive, Martin Winterkorn, resigned.
- On 19 September, the Rugby World Cup's opening weekend, Japan beat South Africa 34–32 at the Brighton Community Stadium, Karne Hesketh's try in the last play of the match settling it — the tournament's largest upset, and still remembered as the Brighton miracle.
- On 28 September PSLV-C30 carried Astrosat, India's first dedicated multi-wavelength space observatory — 1,513 kilograms and five payloads — into orbit from Sriharikota; the same day NASA reported hydrated salts in the dark streaks on Martian slopes, read then as flowing brine, a reading that has since lost ground to dry granular flow.
The tool, the promise and the draft
A decade on, XcodeGhost reads less as a Chinese curiosity than as the first mass-market proof of a method. Nobody attacked WeChat; they attacked the compiler its developers used, and a review process built to catch bad apps waved through good apps with a bad parent. CCleaner's build was poisoned in September 2017, SolarWinds' Orion updates in 2020 (December 2020), and by April 2023 one supply-chain attack was being delivered by another; in July 2026 this magazine was describing a compromised AI development toolchain in the same terms. The figure Apple put in an email that September, 128 million customers, was the largest known compromise of iPhone users to that point, and it stayed inside the company for six years.
The promise held for a while and then, by Washington's account, did not. The decline FireEye measured in 2016 had begun before the White House announcement, and the December 2018 indictment of two hackers working with the Ministry of State Security, for the campaign that ran through managed service providers, was Washington's public verdict. SYNful Knock put the router on the list of things that can be owned, where it has stayed. And India never did get the policy the draft promised. The San Bernardino order of February 2016, WhatsApp's switch to end-to-end encryption that April and the challenges that followed it in the Delhi High Court, and the DPDP Act of 2023, which left encryption alone, are the argument the withdrawn draft started — still unsettled.