Raleigh, NC

32°F
Broken Clouds Humidity: 47%
Wind: 4.63 M/S

Apple Servers Used for Phishing Attacks via iCloud Calendar

Apple Servers Used for Phishing Attacks via iCloud Calendar

Hackers are exploiting iCloud Calendar invites to send deceptive callback phishing emails, which appear to be legitimate purchase notifications. Since these emails are sent directly from Apple's servers, they are more likely to bypass spam filters and land in a target's inbox. 

In a recent example, a user received an email disguised as a PayPal payment receipt for $599. The email, which came from a "This email address is being protected from spambots. You need JavaScript enabled to view it." address, instructed the recipient to call a support number to cancel the payment. The goal of this scam is to scare the victim into calling the number, where a scammer will try to gain remote access to their computer to steal money or deploy malware. 

This particular scam is unique because it abuses the legitimate iCloud Calendar invite feature. The hackers create a calendar event and put the phishing text in the notes section. When the event is created, Apple's servers send an invitation email to the intended targets. The email passes all standard security checks like SPF, DMARC, and DKIM, giving it an air of authenticity. 

The attackers seem to be using a Microsoft 365 mailing list to automatically forward the invite to a large number of victims. Microsoft 365's Sender Rewriting Scheme allows the email to pass SPF checks, adding another layer of legitimacy. 

As a general rule, you should be cautious of any unexpected calendar invites with unusual messages, even if they appear to be from a trusted source. 

 

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Image

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.