Security Affairs
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|
Advertisement

Ad Placeholder

Full Width × 90

Cyber Crime

Symantec alerts on surge in Phishing for Apple ID

Symantec has released a security advisory on the increment of phishing activities for Apple ID login credentials. The Symantec security firm has published an interesting blog post to warn Apple Mobile users on the increment of phishing campaigns to steal Apple ID credentials. Cybercriminals are adopting new techniques to trick users into disclose their personal information […]

Symantec alerts on surge in Phishing for Apple ID

Symantec has released a security advisory on the increment of phishing activities for Apple ID login credentials.

The Symantec security firm has published an interesting blog post to warn Apple Mobile users on the increment of phishing campaigns to steal Apple ID credentials. Cybercriminals are adopting new techniques to trick users into disclose their personal information including Apple ID.

Why steal Apple ID credentials?

“Once the attacker harvests the Apple ID login and password, they direct users to a second phishing page that asks for financial and personal information, such as credit card number, date of birth, and a security question,” Symantec explains. “Once this information has been submitted, the user is directed back to the real Apple.com. However, their Apple ID along with their personal and financial details have now been compromised.” explains Satnam Narang, Security Response Manager at Symantec.

Last week I wrote about a singular case which affected Australian Apple users,  cyber criminals have targeted a large number of Apple’s iCloud users with a sophisticated extortion scheme based on a ransom request. Apple has clarified that its iCloud infrastructure hasn’t suffered a data breach and that users involved in the scam were probably victims of some for of phishing for their Apple ID.

“While there have been no confirmed reports as to how these Apple IDs were compromised, one possible explanation is phishing scams. Due to all the media attention this event has received, Symantec is cautioning users to be skeptical of emails claiming to be from Apple. This event presents scammers with more credibility when attempting to phish for Apple IDs, especially now that many users are concerned about the safety and security of their Apple IDs and devices.” states Symantec.

As explained in the post published by Symantec, phishers are adopting techniques even more sophisticated users to circumvent which are more aware of cyber threats. 

Apple ID phishing 1

The spike of phishing activities is interesting many countries, including the United Kingdom, the United States, Canada, Italy, Germany and also other Asian.

The phishing activities for Apple ID credentials are typically based on emails with password-change requests, so be “Symantec is cautioning users to be skeptical of emails claiming to be from Apple”.

The emails used in some of the phishing campaign for Apple ID look like legitimate appearing with actual Apple layout, in many cases bad spelling and wrong text formatting have to alert users, security experts have discovered recently many malicious emails with following subject lines:

• Please update your Apple account now
• Apple – Your Account Is Not Confirmed
• Please Verify Account Information For Your Apple ID
• Please verify the email address associated with your Apple ID

“These subjects are used to trick users into opening emails, improving the odds that they may click on the links within them.” adds Symantec.

 

Apple ID phishing 2

 

Below useful suggestions to prevent Apple ID phishing:

  • Watch out for suspicious emails. If you receive an email claiming that your Apple ID has been disabled or that you need to update your information, do not click on the link within the message. Open up a browser tab and browse to apple.com instead.
  • Pay attention to the address bar. If you happen to click on a link in an email, look closely at the URL in your address bar. If the URL looks suspicious, like the examples shown in this blog, do not type in your Apple ID and password. In modern browsers, look for the green lock symbol and “Apple Inc.” to confirm you are on the real Apple website.
  • Enable two step verification for your Apple ID. With two step verification enabled, if your Apple ID is phished, an attacker cannot log in to your account without obtaining physical access to your cellphone or other trusted devices.

Pierluigi Paganini

(Security Affairs –  Apple ID, phishing)