• NEWS
  • INDUSTRY SPOTLIGHT
  • SECURITY BLOGGERS NETWORK
    • ANALYTICS
    • APPSEC
    • CISO
    • CLOUD
    • DEVOPS
    • GRC
    • IDENTITY
    • IDENTITY RESPONSE
    • IOT / ICS
    • THREAT / BREACHES
    • MORE
      • BLOCKCHAIN / DIGITAL CURRENCIES
      • CAREERS
      • CYBERLAW
      • HUMOR
      • MOBILE SECURITY
      • SOCIAL ENGINEERING
  • CHATS
  • LIBRARY
  • WEBINARS
© 2020 · MediaOps Inc. All rights reserved.View Non-AMP Version
  • Homepage
  • Security Bloggers Network

Phishing Site Encrypted With AES Designed to Steal Users’ Apple IDs

Scammers designed a phishing website and encrypted it with the Advanced Encrypted Standard (AES) in their attempts to steal unsuspecting users’ Apple IDs.

Researchers at Trend Micro came across the phishing campaign on 30 April. It all began when they received an email designed to look like it came from Apple. The email warned recipients that Apple had restricted their account access due to “unusual activity,” and it required them to update their payment information to fix the issue.

The phishing email received from what appears to be Apple. (Source: Trend Micro)

Of course, the email was a fake. Its “Update Your Payment Details” button led users to a site that looked like Apple’s sign-in page. Before going offline, the website was located at the following sanitized link: hxxp://avtive1s[.]beget[.]tech/limited/apple-couzin/apple%20couzin/Uu4gX/login.php?sslmode=true&access_token=1SGMm8LG43m4qPGE7D8Q00qCRZ2hwIVyBBkYK6FP91UzQBeYemPenfQeeTwLCrjd3EcNKRDUTxuJ8IIm.

After they attempted to sign in, the phishing website informed users that Apple had suspended their accounts due to suspicious activity. It then directed them to a sophisticated webpage designed to collect unsuspecting users’ personal and payment card information. After acquiring all of this data, the site “logged out” its victims and redirected them to Apple’s actual homepage.

This campaign wasn’t the first scheme aimed at stealing users’ Apple IDs. But what made it unique was its incorporation of code in “login.php,” “process.php” and “verified.php” to invoke JavaScript-based AES obfuscation with custom variables.

AES encryption implementation designed to conceal the malicious payload. (Source: Trend Micro)

Trend Micro researcher Jindrich Karasek elaborates on what this implementation of AES encryption meant for the phishing campaign:

Network packet inspection would not identify this as malicious because the payload is hidden thanks to the encryption. The only way to spot this threat is via reputation services that identify the sender as malicious. The unique way that this phishing (Read more...)

*** This is a Security Bloggers Network syndicated blog from The State of Security authored by David Bisson. Read the original post at: https://www.tripwire.com/state-of-security/latest-security-news/phishing-site-encrypted-with-aes-designed-to-steal-users-apple-ids/

Tags: AppleencryptionLatest Security NewsPhishing
3 years ago
David Bisson

Related Post

  • Second Swiss Firm Said to Be CIA Encryption Puppet

    First Crypto AG, and now Omnisec AG: Sources say second Swiss company was also in the…

  • Why It’s Time to Quantum-Proof Your Communications Infrastructure

    It’s a matter of time until the day arrives when quantum computers will crack traditional…

  • Targeted Spear-Phishing on the Rise

    The pandemic has presented many challenges for cybersecurity, especially COVID-19-related phishing attempts targeting employees working…

Recent Posts

  • Press Releases

NewDay Scores with TigerGraph Cloud to Fight Financial Fraud

Leading UK Credit Card Consumer Finance Company Uses Advanced Graph Analytics to Intercept Fraudulent Credit Card Applications, Boost Anti-Fraud Efforts…

35 mins ago
  • Press Releases
  • Press Releases

VMRay Closes $25 Million Series B

Digital+ Partners Leads Continuation Funding Round in Growing Automated Threat Analysis & Detection Provider, Closing its Series B Round at…

3 hours ago
  • Security Bloggers Network

The Hacker Mind Podcast: Hacking OpenWRT

For three years OpenWRT had a severe validation problem with its download package manager, until a fuzz tester found and…

3 hours ago
  • Data Security
  • Security Bloggers Network

Goodbye to Flash – if you’re still running it, uninstall Flash Player now

It’s time to say a final “Goodbye” to Flash. (Or should that be “Good riddance”?) With earlier this week seeing…

3 hours ago
  • Network Security
  • Security Bloggers Network

Being a Defender

1. Be a student of (information security, network security, cyber security). Always strive to know what the latest tactics, trends,…

4 hours ago
  • Security Bloggers Network

Smart DNS: Delivering the Best Subscriber Experience

This is the second in a series of blog posts that discuss how smart DNS resolvers can enhance ongoing network…

4 hours ago
  • About
  • Media Kit
  • Sponsors Info
  • Copyright
  • TOS
  • Privacy Policy
  • DMCA Compliance Statement
© 2020 · MediaOps Inc. All rights reserved.View Non-AMP Version
  • t