Cybercriminals are tricking iPhoneinto disabling Apple iMessage's built-in phishing protection and re-enabling disabled malicious links.
As more of our daily activities are now done on our phones, threat actors are increasingly conducting smishing (SMS phishing) attacks. To protect users from such attacks, Apple iMessage automatically disables links in messages received from unknown senders, whether they are an email address or a phone number.
However, according to Apple, if a user replies to this malicious message or adds the sender to their contact list, the phishing links will be activated.
See also: Phishing campaign steals PayPal accounts

Misleading users
Over the past two months, there has been an increase in attacks that attempt to trick users into replying to an iMessage message so that the links can be reactivated.
For example, iMessage users abroad have received a fake message from the USPS about a package being shipped and a message about paying tolls. These decoys are often used in phishing attacks and in this case ask users to respond with “Y” to activate the links.
“Please reply Y, then exit the text message, reopen the activation link in the message, or copy the link into your Safari browser to open it,” the phishing messages state.

As users have become accustomed to typing STOP, Yes, or NO to confirm or opt out of text messages, threat actors hope that this familiar practice will cause the recipient to respond and activate the phishing links.
See also: Phishing email impersonates CrowdStrike and targets developers
This will re-enable links and disable Apple iMessage's built-in phishing protection for that message.
Even if a user does not click on the now activated link, the response shows the attacker that this target responds to phishing messages and is therefore more likely to fall for another similar trap.
iMessage users should be very careful with the messages they receive. If the links in a message are disabled or come from an unknown sender asking you to respond, it's best not to respond. Instead, contact the company or organization directly to verify the message.
See also: FlowerStorm: New phishing platform steals Microsoft credentials

Phishing protection
The above attack shows that there is a great need to take some protection measures against phishing messages/emails. Let's look at some of them:
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Use of email spam filters
- Leveraging built-in phishing protection (like Apple iMessage)
- Protecting devices with antivirus
- Regular software updates
- Using a unique password for each of your online accounts
- Multi-factor authentication application
- Backup
Source: www.bleepingcomputer.com
