logo

Inside the OS-Aware Phishing Kit Profiling Your Device

ID: 0a459332-3ce2-5329-b9b6-7b386cde7927

STIX ID: report--0a459332-3ce2-5329-b9b6-7b386cde7927

Feed Name: KnowBe4 Blog

Threat Score
78/100

Date Published: 2026-07-30

Date Updated: 2026-07-31

Author: KnowBe4 Threat Lab

...
...

KnowBe4 analysts dissected an active iCloud sign‑in phishing campaign that dynamically routes victims by OS into three parallel attacks: ScreenConnect RMM installation for Windows, external iCloud credential harvesting for Apple devices, and a human‑operated AiTM relay for other platforms; exposed artifacts revealed domains, a URL redirect chain, a SHA256 file hash, Telegram bot and group identifiers, and 250+ confirmed human clicks (primarily US-based) over 48 hours, demonstrating advanced SEG bypass, antibot fingerprinting, and live MFA interception — recommended actions include blocking IOCs, hunting for ScreenConnect installations, forcing credential resets, monitoring/blocking Telegram API traffic, and adopting FIDO2 hardware keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.