
ChatGPT Billing Phish and Fake Snap Support Scams
This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted…
Researchers found an active campaign using fake AWS sign-in pages and an Apple ID decoy page to pull victims onto attacker-controlled websites. Visiting these pages can trigger an iOS exploit chain that installs GHOSTBLADE and steals sensitive data like iCloud, Keychain, and Wi‑Fi credentials.
Researchers at Censys identified an unknown operator running more than 100 web properties, most of which are fake AWS sign-in pages. Victims are funneled to one of two entry points: an AWS-console impersonation subdomain or an Apple ID sign-in decoy page. When a victim reaches either page, a malicious iframe loads JavaScript that fires an exploit chain. Successful exploitation deploys GHOSTBLADE modules that dump keychain, iCloud, and Wi-Fi credentials and exfiltrate files from the device.
The operator's infrastructure included multiple admin and panel logins, referenced internally with names like DarkSword Admin, Decode Dashboard, and C2 Control Panel, along with exposed tooling found in an open directory. A Telegram contact link was also found on the C2 Control Panel, suggesting a direct channel for the operator.
This campaign works because it targets two of the most routine actions people take online: signing into a cloud console and signing into an Apple ID. Both AWS and Apple ID logins are trusted, frequently used prompts, so a lookalike page in the right context does not necessarily stand out. The attack chain also does not always require credential entry, since simply reaching the page can be enough to trigger the exploit against iOS. That combination of familiar pretext and a low bar for compromise makes the approach effective against a broad range of users, including IT, DevOps, engineering, and executives.
Treat cloud login pages as high-risk touchpoints. Employees should only sign in through bookmarked or known-good URLs rather than links received in messages or found through search. Any unexpected AWS or Apple ID sign-in prompt should be treated as suspicious until verified through an official channel.
Because a website visit alone can be enough to start an iOS compromise in this campaign, keeping iOS devices fully updated and avoiding unknown or unofficial sites on work devices is important. Given that stolen data can include password stores and cloud account credentials, organizations should encourage use of managed devices where possible and promote quick reporting of any unusual or unexpected sign-in prompts so security teams can investigate before credentials or device data are exposed.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It begins when a victim reaches an operator-controlled domain, either an AWS-console impersonation subdomain or an Apple ID sign-in decoy, which loads a malicious iframe that fires JavaScript to trigger the exploit chain.
Once the exploit succeeds, the implant delivers modules that dump keychain, iCloud, and Wi-Fi credentials and can exfiltrate files from the device.
Not necessarily. Researchers note that simply reaching one of the lookalike pages can be enough to trigger an iOS exploit chain, in addition to credential entry on the fake sign-in forms.
Watch for sign-in prompts hosted on unusual domains or subdomains not used by AWS or Apple, prompts that appear after clicking an unfamiliar link rather than through official settings or console flows, and pages that behave oddly or are hosted alongside unrelated admin panels.
Imagine this: you tap an AWS login link, and just visiting that page starts hacking your iPhone. Researchers found more than 100 fake AWS sign-in sites and an Apple ID decoy page. You land there, a hidden iframe runs JavaScript, and an iOS exploit chain drops spyware called GHOSTBLADE that can dump your iCloud, Keychain, and Wi‑Fi passwords. Here’s the trick: the page looks normal, AWS or Apple branding, but the address bar gives it away. If you see an AWS or Apple ID login on some random domain or IP, especially from a link in a site or chat, assume it’s a trap. Your move: never log in to AWS or Apple ID from a link. Only use your own bookmark or type the address yourself, if a prompt pops up from anywhere else, close it and report it.

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command.…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…