Mac users, don’t fall for this repurposed Windows phishing attack appeared first on MacDailyNews. Mac users, don’t fall for this repurposed Windows phishing attack appeared first on MacDailyNews. Mac users, don’t fall for this repurposed Windows phishing attack appeared first on MacDailyNews. Mac users, don’t fall for this repurposed Windows phishing attack appeared first on MacDailyNews.
LayerX Labs, a security firm, has uncovered an advanced phishing campaign that has shifted its focus to Mac users following the implementation of enhanced browser protections that diminished the success

Mac users, don't fall for this repurposed Windows phishing attack

LayerX Labs, a security firm, has uncovered an advanced phishing campaign that has shifted its focus to Mac users following the implementation of enhanced browser protections that diminished the success of its Windows-based attacks. Initially, the attackers employed fake Microsoft security alerts to target Windows users, but they have since modified their approach due to new anti-scareware measures introduced in Chrome, Edge, and Firefox browsers earlier this year.

Tim Hardwick for MacRumors:

According to LayerX, the original campaign relied on compromised websites that would display fake security warnings claiming the user’s computer had been “compromised” and “locked.” The malicious code would then freeze the webpage, creating the illusion that the computer was locked and prompting victims to enter their Windows credentials.

What made the campaign particularly effective was its apparent credibility, since the phishing pages were hosted on Microsoft’s Windows.net platform. The use of legitimate infrastructure also helped it bypass security tools that assess risk based on domain reputation.

After browser developers implemented new anti-scareware protections in early 2025, LayerX said it observed a 90% drop in Windows-targeted attacks. Within just two weeks, the attackers had shifted their focus to Mac users, who weren’t covered by the new protection measures.

The Mac-targeted phishing pages use a similar visual design but have been tailored specifically for macOS and Safari users. However, the campaign is still using the Windows.net infrastructure.


MacDailyNews Note: More in LayerX’s article here.



Please help support MacDailyNews — and enjoy subscriber-only articles, comments, chat, and more — by subscribing to our Substack: macdailynews.substack.com. Thank you!

Support MacDailyNews at no extra cost to you by using this link to shop at Amazon.

The post Mac users, don’t fall for this repurposed Windows phishing attack appeared first on MacDailyNews.

original link


You may also be interested in this

Judge blasts Apple for wi…

Apple willfully violated a court order limiting its anti-competitive App Store practices and taking commission on external transactions. (via Cult of Mac - Apple news, rumors, reviews and how-tos)

Hands on: GAMEBABY Case t…

I was someone who grew up with a Gameboy Color in my hands. I would play games like Pokemon, Ray-Man, and Super Mario until my fingers cramped. So, last year,

Apple Seeds Second Beta o…

Apple today seeded the second beta of the recently announced macOS 14 Sonoma update to developers for testing purposes. The beta comes two weeks after the launch of the first

If you haven’t updated yo…

Macworld All attention might be on iOS 17 and macOS Sonoma, but Apple hasn’t stopped working on its current crop of operating systems. And if you’re not running the betas,

ChatGPT Search is now ava…

Back in October, OpenAI launched its own search engine integrated into ChatGPT. At first, the feature was made available only to ChatGPT Plus subscribers, but now OpenAI is rolling out

New iOS 18.2 feature will…

iOS 18.2 is now available for iPhone users, and one of its new features is gaining high praise from musical artist Michael Bublé, also known as the king of Christmas.

Inside Apple’s secret aud…

AirPods Pro (2nd generation) “We don’t let cameras in this place normally. And so it’s a little bit of an out-of-body experience for everybody,” John Ternus, senior vice president of

DOJ says TikTok collected…

The ongoing battle between the US government and TikTok owner Bytedance continues, with the Department of Justice (DOJ) saying that TikTok collected sensitive user data on a variety of controversial
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.