Security Affairs
PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Is your iOS device hostage? Old scam scheme used to lock mobile

A number of iOS devices are being held ransom by the Russian “Oleg Pliss” who is demanding a payment of $100 to unlock the device. Basically the hijack is being done using stolen iCloud passwords and the “locate device” feature to lock the device and display a message to the affected user. Now how the passwords […]

sourmint ios SDK

A number of iOS devices are being held ransom by the Russian “Oleg Pliss” who is demanding a payment of $100 to unlock the device.

Basically the hijack is being done using stolen iCloud passwords and the “locate device” feature to lock the device and display a message to the affected user.

Now how the passwords got out is something Apple is pointing fingers to the latest LinkedIn data leak or blaming it on users affected by phishing attacks. Getting past all the finger pointing and “he started it!” accusations, estimates are suggesting 40 million devices in the United States,Europe and Australia have been affected. But sources also suggest that these numbers may be blown out of proportions, but to have put such an attack on the radar a good hundred thousand victims would have been affected.

This not a new type of scam and since last February similar scams have been affecting the Apple’s line of devices.

In May 2014, cyber criminals targeted a large number of Australian Apple’s iCloud users with a similar attack, the attackers allegedly hijacked Apple’s Find My iPhone feature, in this way criminals remotely lock iOS and Mac devices and send messages demanding ransom money.

iOS devices ransom scheme

The attack normally happens when the actor uses your iCloud password to locate and trigger the “locate device” feature and hence can display a message and cause your device to make sounds to grab your attention. The message normally tells the victim to order the password by mailing to the given e-mail address.

Most of the passwords come from numerous data breaches that occurred over the time, including iMesh , VK.comMySpace, , Badoo.com, HotScripts.com, Mac-Forums.com and phishing attacks.

The Mac-Forums leaked database is available for approximately $755 while HotScripts has a database selling for  $1900.

Apple has issued support for users and there are suggestions to use a unique password only for the Apple ID as well as two-factor authentication and two-step verification process.

Joshua BahirvaniAbout the Author: Joshua Bahirvani
Cyber Security Enthusiast and believer of Privacy in this Digital Age.
LinkedIn : https://in.linkedin.com/in/jbahirvani15
Peerlyst: https://www.peerlyst.com/users/joshua-bahirvani
Twitter : @B15joshua

 

 

 

[adrotate banner=”9″]

Edited by Pierluigi Paganini

(Security Affairs – ios-devices, scam)