logo

Korean researcher details scheme abusing Apple's third-party pickup policy

ID: c5e0f485-e656-50fc-83cf-83de54fe48bc

STIX ID: report--c5e0f485-e656-50fc-83cf-83de54fe48bc

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-04-18

Date Updated: 2026-04-26

Author: Laura Dobberstein

...
...

Researchers exposed a phishing-driven criminal operation called “Poisoned Apple” (active 2021–2023) that collected ~8,000 stolen credit cards and over five million personal records via fake payment pages, then used those cards to buy Apple products and resell them through second-hand marketplaces by naming buyers as designated third-party pick-up persons. The campaign targeted residents of Korea and Japan, demonstrated technical and operational sophistication (bypassing Korean multi-factor payment requirements and using Cloudflare, with configuration errors revealing origin servers), and is attributed by investigators to actors likely based in China.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.