Thursday, April 3, 2025
HomeSecurity NewsPanic Attack - Beware!! Apple Phishing Emails with Subject as Your Receipt...

Panic Attack – Beware!! Apple Phishing Emails with Subject as Your Receipt & Login Alert

Published on

SIEM as a Service

Follow Us on Google News

Security researchers from Malwarebytes spotted an Apple phishing campaign with new tricks to steal payment card details from victims. The attack ranges between February 2–6 and now the phishing sites are deactivated.

Most of the Emails sent was with the subject [ New Statement ] Your receipt from Apple [ 02 February 2018 ] and the attackers used the randomly-grabbed address.

Researchers said “the emails claim to be receipts for a payment of $9.99 made out to, er, Mr. Edward Snowden. Apparently, privacy campaigns and 2 terabyte storage plans go together nicely”.

Seems like the scammers targets some potential victims, for most of the people it displays the following message “Thanks for the order of this thing that costs you money” would be enough to have panic set in.

Apple phishing

Researchers said “the phishing link itself is also offline, but we can confirm people won’t be losing money on this one anytime soon”.

Also Read ReelPhish – A Real-Time Advanced Two-Factor Authentication Phishing Tool

Login Alert Notification – Apple phishing

Also, the scammers sent login alert notifications “someone else is logging in to your Apple account with an iPod in Monaco“.

In the Apple phishing Email, they used Cyrillic characters to bypass Bayesian filtering and the destination here is again offline. The Email read as below.

[Reminder] [Notification Update] Statement new log-in your Apple account with
another device
Fοuг уοuг ѕаfеtу, уοuг Αррlе ID hаѕ Ьееn lοсκеd Ьесаuѕе wе fοund ѕοmе ѕuѕрісіοuѕ
асtіνіtу οn уοuг ассοunt. Ѕοmеοnе ассеѕѕіng уοuг ассοunt аnd mаκе ѕοmе сhаngе
οn уοuг ассοunt іnfοгmаtіοn. This the details :
Country: Monaco
IP Address :
Date and Time: 13:09, 06 Feb 2018
OS: iPod
Browser: Safari
If you did not make these action or you believe an unauthorized person has
accessed your account, you should login to your account as soon as possible to
 verify your information.
Researchers spotted some messages that to apply pressure to victims “Payment made, quick do something!” and “So, your account is going to be terminated.”

Also some fake app purchases messages circulated with the order number attached which may prompt the individuals to click on those rogue links.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Secure Ideas Achieves CREST Accreditation and CMMC Level 1 Compliance

Secure Ideas, a premier provider of penetration testing and security consulting services, proudly announces...

New Phishing Campaign Targets Investors to Steal Login Credentials

Symantec has recently identified a sophisticated phishing campaign targeting users of Monex Securities (マネックス証券),...

UAC-0219 Hackers Leverage WRECKSTEEL PowerShell Stealer to Extract Data from Computers

In a concerning development, CERT-UA, Ukraine's Computer Emergency Response Team, has reported a series...

Hunters International Linked to Hive Ransomware in Attacks on Windows, Linux, and ESXi Systems

Hunters International, a ransomware group suspected to be a rebrand of the infamous Hive...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Advanced CoffeeLoader Malware Evades Security to Deliver Rhadamanthys Shellcode

Security researchers at Zscaler ThreatLabz have identified a new sophisticated malware family called CoffeeLoader,...

Clio: Real-Time Logging Tool with Locking, User Authentication, and Audit Trails

Clio is a cutting-edge, secure logging platform designed specifically for red team operations and...

Enhancing Satellite Security by Encrypting Video Data Directly on Payloads

The rapid expansion of low-Earth orbit (LEO) satellite constellations has underscored the need for...