HomeSecurityThe iServer phishing platform was taken down by the authorities

The iServer phishing platform was taken down by the authorities

Law enforcement agencies in Europe and Latin America announced on Thursday the takedown of iServer , a phishing-as-a-service platform that allows the unlocking of stolen and lost phones.

See also: SambaSpy Malware: Targets Italian users with phishing emails

iServer phishing platform

iServer, which was dismantled as part of an international law enforcement effort called Operation Kaerb, is estimated to have targeted over 1.2 million mobile phones and caused more than 480,000 victims.

The authorities' operation, which took place between September 10 and 17, resulted in the arrest of 17 people in Argentina, Chile, Colombia, Ecuador, Peru and Spain, including an Argentine national believed to be the platform's administrator.

According to researchers, the iServer administrator had been creating and running phishing services since 2018 and had been using the mobile phone unlocking platform for the past five years.

iServer had over 2,000 registered paying users, who were “ charged additional costs for phishing, SMS, emails or making calls ,” Europol says .

According to the company Group-IB, which helped with the investigation, iServer was an automated phishing platform specifically focused on collecting credentials that allowed criminals to unlock phones.

See also: DOJ charges Chinese engineer with spear phishing against NASA

The platform allowed users to steal credentials from cloud-based mobile services and other personal information from their victims, which could be used to bypass the devices' Lost Mode feature.

The iServer phishing platform was taken down by the authorities

The owner of the iServer phishing platform sold access to "unlockers," i.e. people who provided phone unlocking services to criminals in possession of illegally obtained phones, Group-IB explains.

Phishing attacks were designed to collect data such as IMEI, language, owner details and other information that provided access to physical mobile devices via Lost Mode or via cloud-based mobile platforms.

Victims were sent SMS messages containing phishing links that redirected them to phishing pages where they were asked to enter their credentials and additional information, including OTP codes.

After receiving the credentials and validating them, the criminals unlocked the phones, disabled Lost Mode, and disconnected them from their previous owners.

See also: DuckDuckGo: Ranks Etherscan phishing sites in top results

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Phishing is a fraudulent technique used to trick people into revealing personal information such as passwords, credit card numbers and other sensitive details. Attackers often use emails that appear to come from trusted sources to trap their victims. It is important for users to be cautious and check the authenticity of messages before providing any confidential information.

Source: securityweek

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS