Cybercriminals Shift Focus to Mac Users in New Phishing Campaign

Mar 25 / Nayanika
Cybercriminals have shifted their focus from Windows users to Mac and Safari users in a new phishing campaign aimed at stealing Apple ID credentials. According to cybersecurity firm LayerX Labs, this pivot follows anti-scareware updates from Microsoft Edge, Google Chrome, and Mozilla Firefox, which successfully reduced phishing attacks targeting Windows users by 90%.

The attackers, who previously used fake websites hosted on Windows.net domains to lure Windows users, are now employing revised methods to target Mac users. These websites are designed to look professional and display fake security warnings to deceive users into entering their Apple ID credentials. Once obtained, these credentials could grant access to victims' iCloud accounts, including files, pictures, and backups.


Experts warn that the consequences of such attacks are far-reaching. Cybercriminals often use techniques like credential stuffing to access multiple systems once they have one password.

Darren Guccione, CEO of Keeper Security, highlighted the importance of user vigilance, stating, "The best defense is knowing how to spot and respond to phishing attempts."


To protect against these evolving threats, cybersecurity professionals recommend using password managers, enabling multi-factor authentication (MFA), and undergoing security awareness training. Staying alert for urgent language, suspicious links, and pop-ups while visiting trusted websites directly is essential.


This campaign underscores how cybercriminals adapt quickly to changes in security infrastructure, exploiting vulnerabilities in trusted platforms. As phishing threats evolve, organizations and individuals must remain vigilant to ensure their digital safety.


Read more: Link
Created with