{"id":25190,"date":"2024-09-12T09:12:40","date_gmt":"2024-09-12T17:12:40","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/09\/12\/news-18920\/"},"modified":"2024-09-12T09:12:40","modified_gmt":"2024-09-12T17:12:40","slug":"news-18920","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/09\/12\/news-18920\/","title":{"rendered":"Scammers advertise fake AppleCare+ service via GitHub repos"},"content":{"rendered":"\n<p>We&#8217;ve uncovered a malicious campaign going after Mac users looking for support or extended warranty from Apple via the AppleCare+ support plans. The perpetrators are buying Google ads to lure in their victims and redirect them to bogus pages hosted on <a href=\"https:\/\/github.com\/about\">GitHub<\/a>, the developer and code repository platform owned by Microsoft.<\/p>\n<p>The goal of this scam is to get unsuspecting people on the phone with someone pretending to be working for Apple. From there, fraudulent call center agents will social engineer their victims in order to extract money from them.<\/p>\n<p>In this blog post, we expose the techniques behind this scam and provide mitigation steps to stay away from them. We&#8217;d like to thank GitHub for their quick response in taking down the malicious accounts we reported to them.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-hey-siri-google-apple-phone-support\">Hey Siri, google &#8220;Apple phone support&#8221;<\/h2>\n<p>While Apple products are designed with simplicity in mind, we&#8217;ve all come across an issue at some point that we need assistance with. Google, who reportedly <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2024-05-01\/google-s-payments-to-apple-reached-20-billion-in-2022-cue-says\">paid Apple $20 billion<\/a> to be the default search engine, will display results in Safari, along with ads, hence the lucrative partnership.<\/p>\n<p>Those &#8220;Sponsored&#8221; results can appear at the top or further down the search results page. In the image seen below, a malicious ad appears at the very top, right before Apple&#8217;s official phone number. In other cases we encountered, multiple malicious ads were displayed before any legitimate results.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"863\" height=\"932\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/09\/image_a53442.png\" alt=\"\" class=\"wp-image-117418\" \/><\/figure>\n<p>Clicking on one of those will redirect to a fake AppleCare+ customer service page, inviting users to call a 1-800 phone number supposedly belonging to Apple. In reality, in just 2 simple clicks victims are connected with scammers located in call centers overseas.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-github-repos\">GitHub repos<\/h2>\n<p>The fake Apple customer service pages are hosted on Microsoft&#8217;s GitHub source code repository as standalone HTML templates using Apple&#8217;s branding. Scammers are creating several accounts on GitHub with one or multiple repositories with the same fraudulent <em>index.html<\/em> template:<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"755\" height=\"653\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/09\/image_2d5056.png\" alt=\"\" class=\"wp-image-117432\" \/><\/figure>\n<p>During an active campaign, they can easily swap phone numbers in case one got reported and blocked. In fact, we saw scammers do just that thanks to GitHub&#8217;s commit history:<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"742\" height=\"574\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/09\/image_b914f1.png\" alt=\"\" class=\"wp-image-117426\" \/><\/figure>\n<p>There is also an interesting piece of code within the page (autoDial) that automatically pops up the phone dialog menu. This ensures that victims have one less thing to click on to get connected with a scammer impersonating Apple:<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"671\" height=\"396\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/09\/image_daec4e.png\" alt=\"\" class=\"wp-image-117430\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-risks-and-mitigations\">Risks and mitigations<\/h2>\n<p>This particular scheme is exceptionally easy to fall for due to the combination of malicious Google ads and lookalike pages. Scammers are preying on unsuspecting users to trust that they are real Apple service agents and that it&#8217;s okay to give them personal information.<\/p>\n<p>The biggest risk to consumers is being defrauded for hundreds, and often thousands of dollars. Scammers typically instruct victims to withdraw money from their bank account and send it to them, in various ways.<\/p>\n<p>In some cases we investigated this year, fraudsters will ask for the victim&#8217;s name, address, social security number and banking details. With that information, they can easily blackmail them directly or share their profile with other scammers who will pretend to help from the original incident.<\/p>\n<p>We advise users to be extremely cautious when looking for phone or online support related to any of the most popular brands. Microsoft is usually highly <a href=\"https:\/\/www.malwarebytes.com\/blog\/scams\/2024\/08\/psa-these-microsoft-support-ploys-may-just-fool-you\">targeted by scammers<\/a> due to its dominance in the computer market share. Keep in mind that whenever you click on a sponsored result or ad, you are taking a chance of being redirected to a malicious site.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-check-your-digital-footprint\">Check your digital footprint<\/h2>\n<p>If you want to find out what personal data of yours has been exposed online, you can use our&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">free Digital Footprint scan<\/a>. Fill in the email address you\u2019re curious about (it\u2019s best to submit the one you most frequently use) and we\u2019ll send you a free report.<\/p>\n<div class=\"wp-block-malware-bytes-button mb-button\" id=\"mb-button-7ba16f0b-04e8-4679-9512-2f21a0971dcf\">\n<div class=\"mb-button__row u-justify-content-center\">\n<div class=\"mb-button__item mb-button-item-0\">\n<p class=\"btn-main\"><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=b2c_pro_acq_fy25dfplaunch_171269600960&amp;utm_content=V1\"><\/a><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">SCAN NOW<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identit<\/strong>y<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">identity protection<\/a>.<\/p>\n<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/scams\/2024\/09\/scammers-advertise-fake-applecare-service-via-github-repos\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Beware before calling Apple for assistance as scammers are creating malicious ads and fake pages to lure you in. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10574],"class_list":["post-25190","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-scams"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25190","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25190"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25190\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25190"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25190"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}