Here’s something you may not know: Hackers can sign up for phishing-as-a-service platforms. In other words, there are businesses that put together a PhAAS software package that hackers can buy and run phishing schemes. A new PhAAS called Lucid is now available and is used to target iPhones, according to a report by security researcher Catalyst.
What’s alarming about Lucid is that it involved phishing messages sent via Apple’s iMessage, which uses end-to-end encryption that allows the messages to bypass spam filters. Lucid also sends messages via encrypted RCS, which allows for attacks on Android devices. Apple has announced support for encrypted RCS that will arrive in a future iOS update.
Read more at Macworld.com
