A sophisticated phishing campaign has been observed targeting Apple iCloud users.
Attackers are using OAuth-based phishing techniques to gain access to user accounts without requiring passwords.
Victims are tricked into granting access to malicious applications, leading to data theft and account compromise.
Mitigation:
Educate users to verify app permissions before granting access.
Enable multi-factor authentication (MFA) for Apple iCloud accounts.
