EXTREME ATTENTION: A scam is underway that combines the theft of iPhones with Phishing websites to extract data from victims' mobile phones!
A scam targeting iPhone users has been going on for a few days. According to reliable information, the scam targets owners of Apple phones, after their phones were physically stolen! The scam has been detected by SecNews analysts, after multiple complaints we received, but until now we expect measures to be taken by the competent law enforcement authorities!

How the fraud is carried out
Initially, regarding the fraud analyzed, it all started with the theft of an iPhone 6s Plus mobile phone in the Syntagma area. The user who fell victim to the theft IMMEDIATELY locked his device through the Apple service that can be found at https://www.icloud.com, while at the same time reporting the theft to the nearby police station (Syntagma). With the relevant document he received, he also blocked the SIM card from the telecommunications provider so that it could not be used.
Therefore, the device can now only be opened by the user himself with his own apple id and password. Especially since the user had taken security measures to secure his data, having activated the two-factor authentication (2 factor authentication), even if the fraudsters found his apple id and password, they would have to enter the unique six-digit code that the victim user received on another device (Macbook), in order to open the device. Therefore, their device was now useless!

But the strange things started the very same evening that the theft took place.
The fraudsters, likely gang members, tried to open the device and saw on the screen the contact number that the victim user had provided and the message that read "I want it back, however much you want.
Then a "war" of messages & communication attempts began in order to steal the user's passwords in various ways, in order to initialize it (reset to factory settings) and sell it as new.
- Initially, a message came from an address like Apple to the registered mobile phone, asking him to enter his codes to see where the mobile phone had updated its location a few minutes ago.

- When the perpetrators saw that the victim “didn’t bite,” they then sent a message that the stolen phone had been found and invited the user to “verify ownership” in order to send it back. In this particular message, they falsely stated that it had been located by the Greek Police.
- Because the victim did not respond to any of these messages and did not enter his passwords anywhere, they tried to contact them from a Vodafone prepaid phone which was later identified as belonging to a certain Saleem Muhammad Ahmad Bashir.
In this case, the victim acted extremely effectively and was not convinced by the scammers' efforts. However, the same did not happen in a large number of similar cases, as we were informed!!!
4 Important questions

- It is obvious that this is an organized fraud, an organized circuit with strong structures, since in less than 24 hours the victim received relevant messages that led to Phishing websites that had been created at an earlier time. Therefore, this is not a simple theft of mobile phones but something much more organized. Why was it not treated by the providers & the authorities as a serious case but as a simple theft of a mobile phone?
- Why in cases of organized fraud or organized theft of mobile phones, can't the provider carry out IMMEDIATE lifting of confidentiality? The fraudsters communicated normally with their victim, in fact there was an exchange of messages from both sides, therefore detection is more than easy!
- Why is the signal from this particular prepaid phone not located through mobile antennas and the data provided IMMEDIATELY to the competent authorities and not with a delay of months so that they can proceed with the relevant investigations? Mainly not to find the phones but to find the members of the gang who have set up this entire organized crime.
- Why is there no filtering by decision of internet providers on Phishing websites that intercept the passwords of hundreds of subscribers who do not have the knowledge to identify the false websites?
Analysis / Immediate measures against law enforcement authorities/telecommunications providers!
An analysis was conducted of the Phishing websites used by fraudsters to obtain their victims' passwords. The detailed findings are as follows:
- As it was found, the server is located in Russia, specifically in a datacenter in the city of Irkutsk with IP address 80.87.203.19 and hostname mhost18.ispserver.com
- The server hosts multiple phishing domains that are associated with numerous Phishing attacks worldwide. Authorities should IMMEDIATELY contact abuse@abusehost.ru regarding this attack. This is therefore an organized internet gang with the aim of stealing user information and data worldwide.
- The phishing website as you can see is identical to the Apple website and is not currently detected by Antivirus or Anti-phishing applications. Antivirus companies should also be notified immediately.

- SecNews has identified the full list of phishing domains used by the scammers. You can see the full list as we publish it here: https://pastebin.com/JhACfh5z , while a portion of it is presented below. As you will see, in addition to fake Apple websites, the online scammers are impersonating e-shops for medicines, perfumes and financial research companies.

- Our assessment is that the gang behind this particular cyberattack uses the websites we present for a number of other attacks such as money laundering through mules, phishing at banks, fraud against companies with fake invoices or recruitment of innocent victims
- Ordinary users and corporate network administrators should immediately filter the IP address 80.87.203.19 mentioned above and the related phishing domains, either in corporate Firewalls or in personal computer security suites!
- The use of Phishing websites, mainly from Russia, largely indicates the origin of the users who steal mobile phones in Greece and carry out this fraud.
Greek mobile and internet telecommunications providers should IMMEDIATELY, in order to protect society as a whole and Greek subscribers, filter the malicious Phishing websites we have identified (more information here: https://pastebin.com/JhACfh5z). The attack continues and only with a decision to centrally filter at the ISP level the websites that are proven to lead to phishing pages will its development be limited.
We expect the implementation of immediate measures by the authorities after the disclosure of the fraud details.



