12.1 C
London
Saturday, June 7, 2025
HomeTechnologyMac users, don't fall for this repurposed Windows phishing attack

Mac users, don’t fall for this repurposed Windows phishing attack

Date:

Related stories

Apple set for low-key WWDC news cycle after overpromising and underdelivering in 2024

Apple’s Worldwide Developers Conference (WWDC) 2025, kicking off Monday...

Molly House (Saturday Review) – Tabletop Games Blog

Georgian England saw London quickly growing...

Apple TV+ debuts trailer for new docuseries ‘The Wild Ones’

Apple TV+ on Thursday unveiled the trailer for “The...

Apple Intelligence with Alibaba rollout in China held up by CCP regulator

Apple’s rollout of Apple Intelligence services powered by state-sanctioned...

Amid real-life golf boom, Apple TV+ tees up ‘Stick,’ starring Owen Wilson

“Stick” is a new sports comedy series created by...

Mac users, don't fall for this repurposed Windows phishing attack

LayerX Labs, a security firm, has uncovered an advanced phishing campaign that has shifted its focus to Mac users following the implementation of enhanced browser protections that diminished the success of its Windows-based attacks. Initially, the attackers employed fake Microsoft security alerts to target Windows users, but they have since modified their approach due to new anti-scareware measures introduced in Chrome, Edge, and Firefox browsers earlier this year.

Tim Hardwick for MacRumors:

According to LayerX, the original campaign relied on compromised websites that would display fake security warnings claiming the user’s computer had been “compromised” and “locked.” The malicious code would then freeze the webpage, creating the illusion that the computer was locked and prompting victims to enter their Windows credentials.

What made the campaign particularly effective was its apparent credibility, since the phishing pages were hosted on Microsoft’s Windows.net platform. The use of legitimate infrastructure also helped it bypass security tools that assess risk based on domain reputation.

After browser developers implemented new anti-scareware protections in early 2025, LayerX said it observed a 90% drop in Windows-targeted attacks. Within just two weeks, the attackers had shifted their focus to Mac users, who weren’t covered by the new protection measures.

The Mac-targeted phishing pages use a similar visual design but have been tailored specifically for macOS and Safari users. However, the campaign is still using the Windows.net infrastructure.


MacDailyNews Note: More in LayerX’s article here.



Please help support MacDailyNews — and enjoy subscriber-only articles, comments, chat, and more — by subscribing to our Substack: macdailynews.substack.com. Thank you!

Support MacDailyNews at no extra cost to you by using this link to shop at Amazon.

Subscribe

- Never miss a story with notifications

Latest stories

LEAVE A REPLY

Please enter your comment!
Please enter your name here