Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceidentity-impersonation-fraudcredential-stealer-activity

Apple Account Smishing Campaign Uses Lookalike Domains in Korea

Updated 30d agoFirst seen Apr 11, 20263 sources

ESTsecurity’s Alyac blog warned of a smishing campaign using Apple-themed text messages that claimed an Apple ID had been accessed from another location or showed suspicious account activity. The messages were marked as international-origin texts and directed recipients to fraudulent lookalike domains including ap****-kr.com and app****.cc, attempting to lure victims into credential theft through fake Apple login pages.

Alyac said the alerts were compiled from user-submitted reports through the AlyacM app as part of its weekly smishing roundup. In the same reporting period, the company also highlighted a separate lure impersonating Danal, threatening court appearance over alleged long-term unpaid debt and referencing a payment amount and bank account details, underscoring continued use of both financial-pressure and brand-impersonation tactics in Korean mobile phishing campaigns.

Share:
Apple Account Smishing Campaign Uses Lookalike Domains in Korea
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 6, 20265mo ago

Alyac publishes first-week February smishing alert

ESTsecurity's Alyac blog published a smishing alert for the first week of February 2026 based on AlyacM user reports, featuring Danal debt-collection and Apple account-security impersonation lures as notable examples.

Alyac identifies Danal debt-themed smishing lure in weekly roundup

In its next weekly roundup, Alyac highlighted a smishing message impersonating Danal that threatened court appearance over long-term unpaid debt and referenced a bank account for payment. The same roundup also reiterated Apple-themed account-alert lures collected from user reports.

Jan 30, 20265mo ago

Alyac publishes weekly alert on Apple smishing campaign

ESTsecurity's Alyac blog published a weekly smishing alert summarizing Apple-themed phishing texts reported through the AlyacM app, describing the lure variants and malicious domains involved.

Apple-themed smishing texts reported to AlyacM users

During Alyac's reporting period ending around late January 2026, users reported smishing messages impersonating Apple and claiming suspicious account activity or logins from another location. The messages used lookalike domains such as ap****-kr.com and app****.cc to lure recipients to fraudulent sites.

Jan 16, 20265mo ago

Alyac reports police fine-themed smishing texts

During Alyac's reporting period from 2026-01-10 to 2026-01-16, users reported smishing messages impersonating the Korean National Police Agency's civil complaint service, claiming a traffic fine notice or bill had been issued or delivered. The messages directed recipients to suspicious domains including poa.***g[.]my, moa.n***.my, and yoa.***n.mobi.

[경찰청민원24] 과태료청구서가 전달되었습니다. hxxps://poa.***g[.]my
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Threat actors
1 linked
Affected products
2 linked
Adobe ReaderGitlab
Organizations
7 linked
AppleESTsecurityCJ LogisticsCoinoneBC CardIndustrial Bank of KoreaDanal
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.