Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Why has Trump given white South Africans refugee status? | Refugees News

May 13, 2025

KatRisk acquires Gamma to enhance property-level risk analytics and catastrophe modelling

May 13, 2025

Fastmarkets launches new carbon intelligence products to support global decarbonisation

May 13, 2025
Facebook X (Twitter) Instagram
Trending
  • Why has Trump given white South Africans refugee status? | Refugees News
  • KatRisk acquires Gamma to enhance property-level risk analytics and catastrophe modelling
  • Fastmarkets launches new carbon intelligence products to support global decarbonisation
  • HKMA competition targets sustainable investing and climate risk analytics in finance
  • Trump administration cuts another $450 million in grants to Harvard
  • Trump administration cuts another $450 million in grants to Harvard
  • Willis launches FinTech Plus to offer global insurance protection for scaling FinTech firms
  • Marks & Spencer Says Data Stolen in Ransomware Attack
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Tuesday, May 13
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Scareware Combined With Phishing in Attacks Targeting macOS Users
Cybersecurity

Scareware Combined With Phishing in Attacks Targeting macOS Users

adminBy adminMarch 19, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 31


A scareware campaign phishing for login credentials recently switched from targeting Windows to macOS, Israeli cybersecurity firm LayerX reports.

Throughout 2024 and in early 2025, the attacks targeted Windows users, relying on compromised websites to serve fake Microsoft security alerts claiming that users’ computers had been compromised and locked.

The malicious code caused the webpages to freeze, creating the illusion of an issue, and the victim was instructed to provide their Windows username and password, LayerX explains.

As part of the campaign, the threat actors hosted their phishing pages on the legitimate Azure application hosting platform Windows.net, adding a sense of legitimacy to the fake prompts.

The use of a trusted hosted service for the underlying infrastructure allowed the attackers to bypass anti-phishing defenses that check the reputation of the Top-Level Domain (TLD).

“In this case, the TLD (windows[.]net) is a well-known and highly-used platform by a reputable provider (Microsoft), with a high TLD reputation score. As a result, these pages were able to circumvent traditional protection mechanisms,” LayerX explains.

Randomized, rapidly-morphing subdomains were also used to serve malicious code, and the attackers carefully crafted their phishing pages to look as professional as possible, and included anti-bot and CAPTCHA verification on them, likely to delay automated page classification solutions.

Recently, Chrome, Firefox, and Microsoft Edge received new anti-scareware capabilities, which led to a 90% drop in Windows-targeted attacks, and forced the threat actors to switch focus to macOS users, who are not protected by these defense mechanisms.

Advertisement. Scroll to continue reading.

While no attack against macOS was observed while the Windows campaign was ongoing, within two weeks after the new anti-phishing defenses were rolled out, the first attacks against macOS users started, LayerX says.

The phishing pages were nearly identical to those used in the Windows attacks, and continued to be hosted on Windows[.]net, but the layout and messaging were tailored for macOS users, and the malicious code was modified to target Safari.

According to LayerX, victims incorrectly typing the URL for a legitimate website were taken to compromised domain ‘parking’ pages and then redirected through multiple domains to finally be served a phishing page.

“In one specific case, the victim was a macOS and Safari user working for a LayerX enterprise customer. Despite the organization employing a Secure Web Gateway (SWG), the attack bypassed it,” the cybersecurity firm explains.

LayerX believes that the attackers may further adapt their campaign after making macOS users on Safari their prime targets with minimal modifications to the existing infrastructure, and underlines that this campaign may pose a significant risk to enterprise users.

“Whereas the compromise of a personal, non-corporate account is typically limited to the exposure of that individual user, the compromise of a corporate/enterprise account can result in data exposure at the organizational level, making the threat much more severe,” LayerX head of product marketing Eyal Arazi told SecurityWeek.

“As the change of attack vectors from Windows to Mac demonstrates, this campaign is a highly professional, persistent, and adaptive attack campaign, which poses significant threats to enterprise users,” he said.

Related: Microsoft 365 Targeted in New Phishing, Account Takeover Attacks

Related: Russian State Hackers Target Organizations With Device Code Phishing

Related: Fake DeepSeek Sites Used for Credential Phishing, Crypto Theft, Scams

Related: PayPal Phishing Campaign Employs Genuine Links to Take Over Accounts



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Marks & Spencer Says Data Stolen in Ransomware Attack

May 13, 2025

Output Messenger Zero-Day Exploited by Turkish Hackers for Iraq Spying 

May 13, 2025

Suspected DoppelPaymer Ransomware Group Member Arrested

May 13, 2025

Orca Snaps Up Opus in Cloud Security Automation Push

May 13, 2025

CISA Warns of Flaw in TeleMessage App Used by Ex-National Security Advisor 

May 13, 2025

Apple Patches Major Security Flaws in iOS, macOS Platforms

May 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

Skechers’ Greenbergs Set To Pocket Up To $1.1 Billion From Sale To 3G

May 6, 2025

Skechers founders Robert Greenberg (left) and Michael Greenberg (right) started the brand more than 30…

Trump Organization Admits President Still Controls His Business

May 6, 2025

Forbes Richest Person In Every State 2025

April 30, 2025

These Billionaire Signers Of The Giving Pledge Signers On Why The Philanthropy Group Still Matters

April 29, 2025
Our Picks

Why has Trump given white South Africans refugee status? | Refugees News

May 13, 2025

KatRisk acquires Gamma to enhance property-level risk analytics and catastrophe modelling

May 13, 2025

Fastmarkets launches new carbon intelligence products to support global decarbonisation

May 13, 2025

HKMA competition targets sustainable investing and climate risk analytics in finance

May 13, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

Anthropic co-founder Jared Kaplan is coming to TechCrunch Sessions: AI

May 13, 2025

Improvements in ‘reasoning’ AI models may slow down soon, analysis finds

May 12, 2025

AllTrails debuts $80/year membership that includes AI-powered smart routes

May 12, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.