Apple Account Smishing Campaign Uses Lookalike Domains in Korea
ESTsecurity’s Alyac blog warned of a smishing campaign using Apple-themed text messages that claimed an Apple ID had been accessed from another location or showed suspicious account activity. The messages were marked as international-origin texts and directed recipients to fraudulent lookalike domains including ap****-kr.com and app****.cc, attempting to lure victims into credential theft through fake Apple login pages.
Alyac said the alerts were compiled from user-submitted reports through the AlyacM app as part of its weekly smishing roundup. In the same reporting period, the company also highlighted a separate lure impersonating Danal, threatening court appearance over alleged long-term unpaid debt and referencing a payment amount and bank account details, underscoring continued use of both financial-pressure and brand-impersonation tactics in Korean mobile phishing campaigns.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
Alyac publishes first-week February smishing alert
ESTsecurity's Alyac blog published a smishing alert for the first week of February 2026 based on AlyacM user reports, featuring Danal debt-collection and Apple account-security impersonation lures as notable examples.
Alyac identifies Danal debt-themed smishing lure in weekly roundup
In its next weekly roundup, Alyac highlighted a smishing message impersonating Danal that threatened court appearance over long-term unpaid debt and referenced a bank account for payment. The same roundup also reiterated Apple-themed account-alert lures collected from user reports.
Alyac publishes weekly alert on Apple smishing campaign
ESTsecurity's Alyac blog published a weekly smishing alert summarizing Apple-themed phishing texts reported through the AlyacM app, describing the lure variants and malicious domains involved.
Apple-themed smishing texts reported to AlyacM users
During Alyac's reporting period ending around late January 2026, users reported smishing messages impersonating Apple and claiming suspicious account activity or logins from another location. The messages used lookalike domains such as ap****-kr.com and app****.cc to lure recipients to fraudulent sites.
Alyac reports police fine-themed smishing texts
During Alyac's reporting period from 2026-01-10 to 2026-01-16, users reported smishing messages impersonating the Korean National Police Agency's civil complaint service, claiming a traffic fine notice or bill had been issued or delivered. The messages directed recipients to suspicious domains including poa.***g[.]my, moa.n***.my, and yoa.***n.mobi.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
**님 (주)다날 장기미납으로 법원출석 등기발송예정 1,227,369원 기업은행 480****0797105
blog.alyac.co.kr
Open source[국외발신] [Apple] 귀하의 계정이 다른 장소에서 로그인되고 있습니다. 확인해주세요. app****.cc
blog.alyac.co.kr
Open source[경찰청민원24] 과태료청구서가 전달되었습니다. hxxps://poa.***g[.]my
blog.alyac.co.kr
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


