🚨 CRITICAL SECURITY ALERT: New iOS Phishing Attack
I just received this highly sophisticated phishing email a few moments ago, and I wanted to warn you immediately so you can protect your devices and crypto assets.
How the Attack Works (As seen in image.png):
The email claims my account phone number is being changed to create panic. The real danger is the attached files ending in .mobileconfig (like the caldav file pointed at by the arrow).
Why it is Dangerous:
A .mobileconfig file is an iOS Configuration Profile. If you download and install it, you give attackers deep system privileges. They can route your internet traffic through a malicious VPN, install fake certificates to spy on your data, or steal passwords and 2FA codes .
What to Do:
* Never download .mobileconfig files from emails.
* Never call the support numbers listed in these emails.
* Check your iPhone via Settings -> General -> VPN & Device Management. If you see any unauthorized profile, remove it immediately.
Stay
#SAFU ⚠️
#CyberSecurity #PhishingAlert #Web3Security