🌐Wired•較早收集於 3h
地下生態系統利用被竊 iPhone 進行金融犯罪

💡涉及行動裝置漏洞利用與社交工程的重大安全威脅。
⚡ 30-Second TL;DR
有什麼變化
犯罪分子正使用專業工具解鎖被竊的 iPhone
為什麼重要
這凸顯了行動裝置安全中的關鍵漏洞,以及社交工程攻擊日益複雜的趨勢。
下一步行動
實施強大的多重身份驗證 (MFA),且不要僅依賴簡訊或基於裝置的恢復代碼。
誰應關注:Enterprise & Security Teams
關鍵要點
- •犯罪分子正使用專業工具解鎖被竊的 iPhone
- •針對受害者聯絡人的網路釣魚攻擊規模化
- •重點在於繞過生物識別與密碼安全層
🧠 深度解析
Web-grounded analysis with 19 cited sources.
🔑 增強重點摘要
- •Thieves frequently employ "shoulder surfing" to observe victims entering their passcodes in public, gaining direct access to the device and subsequently linked financial applications and saved passwords.
- •Sophisticated phishing campaigns specifically target victims of stolen iPhones by impersonating Apple Support or "Find My iPhone" services, using details from the stolen device to trick owners into revealing their Apple ID credentials.
- •Apple has responded to these threats by introducing "Stolen Device Protection" in iOS 17.3, which mandates Face ID or Touch ID for sensitive actions (like accessing saved passwords or changing Apple ID settings) when the device is away from familiar locations, and imposes a security delay for critical changes.
- •Beyond social engineering, the underground ecosystem also leverages underlying software vulnerabilities, such as flaws in WebKit, and in some cases, even secret hardware features to achieve deep system compromise and bypass security measures.
- •The stolen iPhones are often part of a larger international trafficking network, with a significant percentage of devices stolen in cities like London being moved abroad to countries such as Algeria, China, and Hong Kong for resale.
🛠️ 技術深入
- Passcode Exploitation: Criminals often obtain the device passcode through "shoulder surfing," which then serves as a fallback to bypass Face ID/Touch ID for many sensitive actions, including changing Apple ID passwords, accessing stored passwords in Keychain, and using payment methods like Apple Pay.
- Phishing Kits: Tools such as AppleKit and MagicApp, alongside a cybercriminal version of the Find My iPhone API (FMI.php), are utilized to create convincing phishing pages. These pages are designed to steal Apple ID credentials, enabling attackers to disable Activation Lock and wipe the device for resale.
- Biometric Bypass (Client-Side): Research indicates that on jailbroken iOS devices, biometric checks (Touch ID/Face ID) relying on client-side validation can be bypassed using tools like Frida scripts to intercept and manipulate functions such as
evaluatePolicyto force a "success" state. - Software Vulnerabilities: Exploits have targeted WebKit, the browser engine for Safari, allowing malicious websites to execute unauthorized code and potentially gain access to sensitive data or full control of the device.
- Hardware Exploits: Some highly sophisticated attacks have been observed leveraging "secret hardware features" to compromise iPhones, indicating deep-level exploitation beyond typical software vulnerabilities.
- Activation Lock Bypass: While Apple's Activation Lock is designed to prevent the reuse of stolen devices, criminals bypass it by acquiring the original owner's Apple ID credentials through phishing, which allows them to remove the device from the owner's account.
🔮 前景展望AI analysis grounded in cited sources
Apple will continue to enhance location-aware and biometric security features.
The introduction of Stolen Device Protection demonstrates Apple's commitment to mitigating threats that exploit physical theft and passcode knowledge, suggesting further development in this area.
The sophistication of phishing attacks targeting iPhone users will increase.
As Apple strengthens device-level security, criminals are likely to focus more on social engineering and credential theft to bypass these measures, as seen with current phishing campaigns.
International law enforcement cooperation will become more critical in combating iPhone-related financial theft.
The global nature of iPhone trafficking and the organized crime networks involved necessitate coordinated efforts across borders to disrupt these illicit operations.
⏳ 時間線
2015-09
iOS 9 increases default passcode length to six digits.
2017-09
Apple introduces Face ID with the iPhone X.
2017-11
Tools like AppleKit and MagicApp for iCloud phishing and unlocking stolen iPhones are identified.
2018-04
Grayshift's GrayKey device for iPhone unlocking (for law enforcement) is profiled.
2023-02
Reports highlight thieves 'shoulder surfing' passcodes to access stolen iPhones and financial apps.
2023-12
Apple releases iOS 17.3, introducing 'Stolen Device Protection'.
📎 來源 (19)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
📰
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: Wired ↗

