Fake AWS & Apple ID Pages Push iOS Spyware

The Hacker News · High sophistication
Last updated August 3, 2026

Researchers found an active campaign using fake AWS sign-in pages and an Apple ID decoy page to pull victims onto attacker-controlled websites. Visiting these pages can trigger an iOS exploit chain that installs GHOSTBLADE and steals sensitive data like iCloud, Keychain, and Wi‑Fi credentials.

How the attack worked

Researchers at Censys identified an unknown operator running more than 100 web properties, most of which are fake AWS sign-in pages. Victims are funneled to one of two entry points: an AWS-console impersonation subdomain or an Apple ID sign-in decoy page. When a victim reaches either page, a malicious iframe loads JavaScript that fires an exploit chain. Successful exploitation deploys GHOSTBLADE modules that dump keychain, iCloud, and Wi-Fi credentials and exfiltrate files from the device.

The operator's infrastructure included multiple admin and panel logins, referenced internally with names like DarkSword Admin, Decode Dashboard, and C2 Control Panel, along with exposed tooling found in an open directory. A Telegram contact link was also found on the C2 Control Panel, suggesting a direct channel for the operator.

Why it succeeded

This campaign works because it targets two of the most routine actions people take online: signing into a cloud console and signing into an Apple ID. Both AWS and Apple ID logins are trusted, frequently used prompts, so a lookalike page in the right context does not necessarily stand out. The attack chain also does not always require credential entry, since simply reaching the page can be enough to trigger the exploit against iOS. That combination of familiar pretext and a low bar for compromise makes the approach effective against a broad range of users, including IT, DevOps, engineering, and executives.

What to watch for

  • Login prompts for AWS or Apple ID that appear on unusual domains or subdomains rather than the official ones
  • A sign-in page reached through a random link, search result, or unfamiliar site rather than a bookmarked URL or official app flow
  • Unexpected page behavior, such as hidden iframe or script activity, that seems inconsistent with a normal sign-in page
  • Sign-in pages hosted alongside unrelated admin or panel infrastructure

How to build resistance

Treat cloud login pages as high-risk touchpoints. Employees should only sign in through bookmarked or known-good URLs rather than links received in messages or found through search. Any unexpected AWS or Apple ID sign-in prompt should be treated as suspicious until verified through an official channel.

Because a website visit alone can be enough to start an iOS compromise in this campaign, keeping iOS devices fully updated and avoiding unknown or unofficial sites on work devices is important. Given that stolen data can include password stores and cloud account credentials, organizations should encourage use of managed devices where possible and promote quick reporting of any unusual or unexpected sign-in prompts so security teams can investigate before credentials or device data are exposed.

Key findings

  • Censys observed an unknown China-linked operator running 100+ web properties, largely fake AWS sign-in pages.
  • Victims are funneled to an AWS-console impersonation subdomain or an Apple ID sign-in decoy; a malicious iframe loads JavaScript to trigger the exploit chain.
  • Successful exploitation deploys GHOSTBLADE modules that dump credentials (Keychain/iCloud/Wi‑Fi) and exfiltrate files.
  • Operator infrastructure included multiple admin/panel logins (e.g., “DarkSword Admin,” “Decode Dashboard,” and “C2 Control Panel”) and exposed tooling in an open directory.
  • A Telegram contact link was found on the C2 Control Panel, suggesting a direct operator contact channel.

Who’s being targeted

  • Commonly targeted roles: Executives, All iOS users, IT, DevOps/Cloud administrators, Engineering.
  • Affected industries: Technology (cloud users), Any organization with employees using iOS devices, Any organization using AWS.
  • Attack channels: website.
  • Impersonated: Amazon Web Services (AWS) login, Apple ID sign-in.

Red flags to watch for

  • Login page is hosted on an unusual domain/subdomain not used by AWS
  • Unexpected sign-in prompt reached from a random link or unfamiliar site
  • Page behavior may include hidden content (e.g., embedded iframe/script activity) inconsistent with normal sign-in pages
  • Apple ID sign-in prompt appears on a non-Apple domain or unexpected IP-hosted page
  • Sign-in page is reached via an unfamiliar link rather than the official Apple settings/app flow
  • The page is hosted alongside unrelated “panel” or admin infrastructure
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does this attack start?

It begins when a victim reaches an operator-controlled domain, either an AWS-console impersonation subdomain or an Apple ID sign-in decoy, which loads a malicious iframe that fires JavaScript to trigger the exploit chain.

What data can attackers steal with this campaign?

Once the exploit succeeds, the implant delivers modules that dump keychain, iCloud, and Wi-Fi credentials and can exfiltrate files from the device.

Do I need to enter credentials for the attack to work?

Not necessarily. Researchers note that simply reaching one of the lookalike pages can be enough to trigger an iOS exploit chain, in addition to credential entry on the fake sign-in forms.

How can I tell a fake AWS or Apple ID sign-in page from a real one?

Watch for sign-in prompts hosted on unusual domains or subdomains not used by AWS or Apple, prompts that appear after clicking an unfamiliar link rather than through official settings or console flows, and pages that behave oddly or are hosted alongside unrelated admin panels.

Read the video transcript

Imagine this: you tap an AWS login link, and just visiting that page starts hacking your iPhone. Researchers found more than 100 fake AWS sign-in sites and an Apple ID decoy page. You land there, a hidden iframe runs JavaScript, and an iOS exploit chain drops spyware called GHOSTBLADE that can dump your iCloud, Keychain, and Wi‑Fi passwords. Here’s the trick: the page looks normal, AWS or Apple branding, but the address bar gives it away. If you see an AWS or Apple ID login on some random domain or IP, especially from a link in a site or chat, assume it’s a trap. Your move: never log in to AWS or Apple ID from a link. Only use your own bookmark or type the address yourself, if a prompt pops up from anywhere else, close it and report it.

Categories

Similar attacks

Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Fake Recruiters Steal Corporate Logins on Mobile

Fake Recruiters Steal Corporate Logins on Mobile

Scammers posing as HR staff at major brands are luring targets into an interview “scheduling” flow that ultimately steals corporate passwords on mobile devices. The campaign uses a browser-in-the-browser style approach (or a full-screen fake login on phones) and even blocks personal email logins to…

August 26, 2026
Fake Recruiters Steal Enterprise Logins on Mobile

Fake Recruiters Steal Enterprise Logins on Mobile

A real “fake recruiter” phishing campaign (tracked as RecruitTrap) is targeting employees’ corporate credentials, especially on mobile devices. The scam uses lookalike recruitment domains and full-screen fake login pages that hide browser cues, and it rejects personal email addresses to focus on…

August 25, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
Fake GitHub Page Tricks Mac Users Into Malware

Fake GitHub Page Tricks Mac Users Into Malware

Researchers found a real macOS malware campaign that uses a fake GitHub download page to convince users to paste a command into Terminal and enter their Mac password. The malware then steals credentials, cookies, and files, and can even turn the victim’s Chromium browser into a remotely controlled…

August 17, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026