Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceidentity-impersonation-fraudvoice-social-engineeringbusiness-email-compromise

Consumer Brand Impersonation Phishing and Tech-Support Scams Targeting Apple and Avast Users

Updated 3mo agoFirst seen Feb 26, 20267 sources

Multiple brand-impersonation phishing campaigns are targeting consumers by abusing trust in Avast and Apple to drive victims into disclosing payment or account details. One campaign uses a near-identical fake Avast portal aimed at French-speaking users, presenting a fabricated €499.99 “subscription charge” and a short cancellation window to induce urgency; the site validates entered card numbers using the Luhn algorithm and uses a Tawk.to live-chat widget (ID 689773de2f0f7c192611b3bf) to pressure victims in real time into submitting full card details (including CVV) under the pretense of processing a refund.

Separate Apple-themed scams use phishing-to-phone and SMS lures to route victims to scam call centers and harvest credentials and financial information. One email purporting to be from an “Apple Fraud Prevention” team attempts to panic recipients into calling a fake support number, while an “Apple Security Alert” Apple Pay text claims a suspicious $143.95 Apple Store transaction and urges an immediate call to a +1 850-85* number to “cancel” the charge. Another tactic abuses iOS Calendar subscriptions (“iPhone Calendar Scam”) to flood devices with fake security/prize alerts that push users to click malicious links; guidance emphasizes unsubscribing from the rogue calendar and avoiding interacting with the spam invites.

Share:
Consumer Brand Impersonation Phishing and Tech-Support Scams Targeting Apple and Avast Users
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 31, 20263mo ago

Fake Webroot renewal scam uses payment alerts and callback lures

A scam campaign impersonating Webroot was described using fake renewal texts, invoices, billing notices, and phishing emails that falsely claimed a payment or subscription renewal had been processed. Victims were pressured to call fraudulent support numbers, where scammers attempted to steal personal or financial information or gain remote access to devices.

Webroot Scam Antivirus Payment Cancellation Text
Mar 26, 20263mo ago

Fake Norton renewal email scam uses callback number 1-810-219-4913

A tech support scam was reported in which a fake Norton renewal email falsely claimed the recipient had been charged hundreds of dollars and urged them to call a listed number to cancel or modify the transaction. The number allegedly connected victims to a fraudulent call center impersonating Norton and other technology companies to steal credentials, banking details, or remote access.

1-810-219-4913 Scam Telephone Number
Feb 26, 20264mo ago

Researchers observe fake Avast refund phishing site targeting French speakers

Researchers identified a phishing campaign impersonating Avast with a near-identical website that falsely claimed victims were charged €499.99 and pushed them to submit payment card details for a supposed refund. Malwarebytes reported the site used client-side date generation, Luhn validation for card numbers, and a Tawk.to live chat widget to increase pressure and improve theft of usable card data.

Feb 25, 20264mo ago

Rogue iPhone calendar subscription scam highlighted

A phishing tactic abusing iPhone calendar subscriptions was described, in which victims are tricked into subscribing to malicious calendars that generate persistent fake alerts and prize messages. The scam was noted to rely on social engineering rather than malware, with guidance provided for unsubscribing and removing suspicious calendar accounts.

Feb 24, 20264mo ago

Apple Pay smishing campaign uses fake purchase alert and callback number

An SMS phishing campaign posing as an "Apple Security Alert" claimed an Apple ID was used for a $143.95 Apple Pay pre-authorization and urged recipients to call a scammer-controlled number. The operation aimed to steal account credentials and personal or financial information through a fraudulent call center.

Apple-themed fraud prevention phishing email scam documented

A phishing email campaign impersonating an "Apple Fraud Prevention Team" was reported, using alarmist language to pressure recipients into calling a fraudulent support number not associated with Apple. The scam was described as a phone-based social engineering attempt targeting Apple users.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Affected products
1 linked
Apple Support
Organizations
6 linked
Microsoft CorporationWebrootAvastAppleMalwarebytesTawk.to
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.