During the so-called Celebgate, or “Fappening”, after that the privacy of dozen international celebrities and Apple Apple clients was violated, and hundreds of intimate pictures were made public, media analysts were quick to point out supposed vulnerabilities of Apple products. From Cupertino came a different version: according to the company, accidents were the result of specific attacks, targeting their customers and aimed at stealing their personal and account details.
A new research by security company Tiger Security, – whose work I already covered when they were protecting Brazil’s World Cup online infrastructures – seems to give some legs to Apple’s position.
The company discovered a new (“actually it is not completely new, but it was used before only in small circles – Tiger’s Ceo Emanuele Gentili says”) phishing kit called “Besmellah” which seems to target specifically bank accounts and credit card details of Apple customers.
Researcher were also able to discover the identity of one of the attackers, a Tunisian kid – “aged 12 or 13 – Gentili says” – who committed only one, very silly mistake: he used to receive the accounts and victims’ personal info, the same email address he used to register his Facebook profile.
Here’s how researchers tracked him down. The Besmellah attack, like similar phishing operations, starts with a fraudulent email, sent to the recipient from an apparently legitimate support account address (in this case, support@apple.com). In the body of the email the attacker refers to a non-specified technical issue, and recommends the recipient to follow a link in order to validate the account and avoid its closure.
Following the link, the victim is re-addressed to a counterfeit support page, which closely resembles the original one, where he is asked to insert his account credentials. In this specific case, the website used to host the pages, was that of an Indian professional, previously hacked through the exploitation of CMS known vulnerabilities of WorldPress, and used to install the kit.
Once credentials are submitted an email is forwarded to the attacker with the customer’s IP address, along with date and time of the submission; as second step, the victim is asked to fill a second form and provide other key information linked to his or her account (name, address,phone number, driving license and credit card details).
Finally, the victim is redirected to the legitimate domain, in this case Apple’s “itunesconnect.apple.com”. A simple, but effective scam, provided the victim clicks on the spoofed link. And provided also the attackers is clever enough to wipe all traces that could lead back to him.
Which this young guy apparently wasn’t. Or he simply took for granted that no one would try and find him; otherwise, he would not have forgotten in the directory of the Indian hacked website, a zipped copy of the phishing kit. Analysing the source code, researchers were able to discover the email address used to receive the info.
Just copying and pasting it into Facebook, using the “search by email” function, they were able to get to a profile a teenager who, according his interests, friends and other characteristics, was almost certainly the guy they were looking for.
Except for the happy ending, this is a classical phishing case. What’s scary, is that even such a young guy was able to perform it, and for a few bucks. “The average cost of a similar kit – Gentili tells me – is around twenty dollars. You can easily buy it in the black markets of the Deep Web, but there are also Facebook groups and forums where it is sold or traded in exchange for other exploits”. It’s easy to predict then, that the Celebgate won’t be the last one of its kind. One can only hope that all attackers are careless like this guy was.
