Suspicious

Phishings targeting Apple

Suspicious and active websites


Phishings targeting Apple

Suspicious and active websites


Active
13
New (7d)
5
Trend (7d)
↑150%
Website
apple.com
About
AIApple ID phishing targets iCloud / Find My data and is commonly tied to iPhone resale fraud after device theft.
Countries
United StatesUnited States (7) · MoldovaMoldova (3) · United KingdomUnited Kingdom (1)
TLS certs
YR1 (3) · YE2 (1) · Microsoft TLS G2 RSA CA OCSP 02 (1)
Possible campaigns 4 of these are in a suspected cluster 0c90e25d777d

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) ▾ URL Screenshot Flags Details
2026-10-02 21:30 2026-10-02 13:04
http://cloud-ld-soporte.com/icloud2022-esp.php
Screenshot of cloud-ld-soporte.com GSB OpenPhish Details
2026-10-02 21:30 2026-10-02 05:25
https://drive-icloud.com
Screenshot of drive-icloud.com GSB Details
2026-10-02 21:30 2026-10-01 13:04
https://suportcloud-us.info/icloud2022-esp.php/s3.php/
Screenshot of suportcloud-us.info GSB OpenPhish Details
2026-10-02 21:30 2026-10-01 13:03
http://suport-appcloud.us/icloud-archivos/code2022esp.php
Screenshot of suport-appcloud.us GSB OpenPhish Details
2026-10-02 21:30 2026-09-30 23:24
https://icloudmex-lost.com
Screenshot of icloudmex-lost.com GSB Details
2026-10-02 21:30 2026-09-25 23:26
https://icloudweb-ext860.click
Screenshot of icloudweb-ext860.click GSB Details
2026-10-02 21:30 2026-09-24 23:26
https://user-id-apple-icloud-account.oneworldnetwork.com
Screenshot of user-id-apple-icloud-account.oneworldnetwork.com GSB Details
2026-10-02 21:30 2026-09-16 17:25
https://icloudnotify.help
Screenshot of icloudnotify.help GSB Details
2026-10-02 21:30 2026-09-14 13:09
http://apple-icloud.azurewebsites.net
Screenshot of apple-icloud.azurewebsites.net GSB OpenPhish TweetFeed Details
2026-10-02 21:30 2026-09-12 23:25
https://icloud-asisten-official.com
Screenshot of icloud-asisten-official.com GSB Details
2026-10-02 21:30 2026-09-07 05:24
https://buscarmi-icloud.app
Screenshot of buscarmi-icloud.app GSB Details
2026-10-02 21:30 2026-07-28 18:06
http://assign-icloud.com
Screenshot of assign-icloud.com TweetFeed Details
2026-10-02 21:30 2026-07-28 03:05
http://noreply-icloud.app
Screenshot of noreply-icloud.app TweetFeed Details

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

URL Screenshot Details
http://cloud-ld-soporte.com/i…
GSB OpenPhish
Screenshot of cloud-ld-soporte.com Details
https://drive-icloud.com
GSB
Screenshot of drive-icloud.com Details
https://suportcloud-us.info/i…
GSB OpenPhish
Screenshot of suportcloud-us.info Details
http://suport-appcloud.us/icl…
GSB OpenPhish
Screenshot of suport-appcloud.us Details
https://icloudmex-lost.com
GSB
Screenshot of icloudmex-lost.com Details
https://icloudweb-ext860.click
GSB
Screenshot of icloudweb-ext860.click Details
https://user-id-apple-icloud-…
GSB
Screenshot of user-id-apple-icloud-account.oneworldnetwork.com Details
https://icloudnotify.help
GSB
Screenshot of icloudnotify.help Details
http://apple-icloud.azurewebs…
GSB OpenPhish TweetFeed
Screenshot of apple-icloud.azurewebsites.net Details
https://icloud-asisten-offici…
GSB
Screenshot of icloud-asisten-official.com Details
https://buscarmi-icloud.app
GSB
Screenshot of buscarmi-icloud.app Details
http://assign-icloud.com
TweetFeed
Screenshot of assign-icloud.com Details
http://noreply-icloud.app
TweetFeed
Screenshot of noreply-icloud.app Details

AIHow to verify a real Apple URL

  • Legitimate Apple URLs always end in apple.com (e.g. www.apple.com, account.apple.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Apple.
  • The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
  • If you got the link from email, SMS, or social media, do not click it. Open apple.com from your browser bookmark or type the domain manually.
  • Real Apple pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.