Rotten Apples: Apple-like Malicious Phishing Domains[html]
At FireEye Labs we have an automated system designed to proactively
detect newly registered malicious domains. This system observed some
phishing domains registered in the first quarter of 2016 that were
designed to appear as legitimate Apple domains. These phony Apple
domains were involved in phishing attacks against Apple iCloud users
in China and UK. In the past we have observed several phishing domains
targeting Apple, Google and Yahoo users; however,
these campaigns are unique as they are serving the same malicious
phishing content from different domains to target Apple users.
Since January 2016 we have observed several phishing campaigns
targeting the Apple IDs and passwords of Apple users. Apple provides
all of its customers with an Apple ID, a centralized personal account
that gives access to iCloud and other Apple features and services such
as the iTunes Store and App Store. Users will provide their Apple ID
to sign in to iCloud[.]com, and use the same Apple ID to set up iCloud
on their iPhone, iPad, iPod Touch, Mac, or Windows computer.
iCloud ensures that users always have the latest versions of their
important information –