ZeroHour
Ars Technica · Securitypublished ()ingested

Ever wonder how crooks get the credentials to unlock stolen phones?

mediumPhishing & fraudimportance 30

Indicators of compromiseAll →

TypeIndicatorContext
domainiserver.comt: Group-IB Besides the arrest, authorities also seized the iserver.com domain. The iServer site as it appeared before the takedown
Full article383 words · extracted from arstechnica.com · click to collapse

Group-IB wrote:

During its investigations into iServer’s criminal activities, Group-IB specialists also uncovered the structure and roles of criminal syndicates operating with the platform: the platform’s owner/developer sells access to “unlockers,” who in their turn provide phone unlocking services to other criminals with locked stolen devices. The phishing attacks are specifically designed to gather data that grants access to physical mobile devices, enabling criminals to acquire users’ credentials and local device passwords to unlock devices or unlink them from their owners. iServer automates the creation and delivery of phishing pages that imitate popular cloud-based mobile platforms, featuring several unique implementations that enhance its effectiveness as a cybercrime tool.

Unlockers obtain the necessary information for unlocking the mobile phones, such as IMEI, language, owner details, and contact information, often accessed through lost mode or via cloud-based mobile platforms. They utilize phishing domains provided by iServer or create their own to set up a phishing attack. After selecting an attack scenario, iServer creates a phishing page and sends an SMS with a malicious link to the victim.

An example phishing message sent.

An example phishing message sent.

When successful, iServer customers would receive the credentials through the web interface. The customers could then unlock a phone to disable the lost mode so the device could be used by someone new.

Ultimately, criminals received the stolen and validated credentials through the iServer web interface, enabling them to unlock a phone, turn off “Lost mode,” and untie it from the owner’s account.

To better camouflage the ruse, iServer often disguised phishing pages as belonging to cloud-based services.

Phishing message asking for passcode.

Credit: Group-IB

Phishing message asking for passcode. Credit: Group-IB

Phishing message masquerades as a cloud-based service with a map once passcode is entered.

Credit: Group-IB

Phishing message masquerades as a cloud-based service with a map once passcode is entered. Credit: Group-IB

Besides the arrest, authorities also seized the iserver.com domain.

The iServer site as it appeared before the takedown.

Credit: Group-IB

The iServer site as it appeared before the takedown. Credit: Group-IB

The iServer website after the takedown.

Credit: Group-IB

The iServer website after the takedown. Credit: Group-IB

The takedown and arrests occurred from September 10–17 in Spain, Argentina, Chile, Colombia, Ecuador, and Peru. Authorities in those countries began investigating the phishing service in 2022.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/