iPhone Users Targeted by Fake Apple and AWS Pages in New Hack

By 813 Staff

iPhone Users Targeted by Fake Apple and AWS Pages in New Hack

A major product shift is underway — iPhone Users Targeted by Fake Apple and AWS Pages in New Hack, according to The Hacker News (@TheHackersNews) (on August 3, 2026).

Source: https://x.com/TheHackersNews/status/2084230403293073741

The first red flags didn’t surface in a security operations center, but in the quiet chaos of a phishing simulation gone sideways. Internal documents circulating among threat-intel teams this week describe a campaign that skips the usual credential-harvesting tricks and instead weaponizes the login pages themselves—fake AWS and Apple portals that trigger a native iPhone exploit the moment a victim hits “Sign In.” The attack, first flagged publicly by The Hacker News (@TheHackersNews) on August 3, appears to be the first known instance of a browser-based exploit chained to a pure login lure, and engineers close to the project say the rollout has been anything but smooth for the attackers.

According to researchers who analyzed the payload, the malicious pages are hosted on compromised domains with valid TLS certificates, making them indistinguishable from legitimate AWS IAM and Apple ID screens at a glance. The exploit itself targets a memory-corruption bug in WebKit’s JavaScript engine—a flaw Apple patched in early July, but which remains live on roughly 18% of iPhones that haven’t updated. The attack flow is deceptively simple: the page loads normally, the victim enters credentials, and the exploit fires during the form submission handler, executing code that persists long after the tab closes. One researcher described it as “a drive-by download with a login form as the tripwire.”

The sophistication is notable. The phishing pages are dynamically generated based on the victim’s user agent, so desktop users see a generic credential prompt, while mobile users receive the full exploit chain. The stolen credentials are exfiltrated in real time to a command-and-control server, which then issues a second-stage payload—currently believed to be a data stealer that targets iCloud Keychain and AWS CLI credentials. That second stage remains unconfirmed, and the identity of the threat actor is still unknown, though the infrastructure overlaps with a known financially motivated group operating out of Eastern Europe.

The timing is brutal for enterprise teams. Apple’s patch is available, but internal telemetry suggests most corporate iPhone fleets are running at least one version behind, and AWS workloads are frequently accessed from personal devices that never see the update. The vulnerability is now public, which means other actors will likely adapt it. Apple is reportedly preparing an emergency update, and AWS has begun blocking the known malicious domains, but the campaign is still active. Security teams should treat any unexpected Apple or AWS login prompt on a mobile device as suspicious until the patch is universally applied. Expect more technical details to emerge at next week’s Black Hat conference, where one of the researchers is scheduled to present a related WebKit finding.

Source: https://x.com/TheHackersNews/status/2084230403293073741

Related Stories

More Technology →