Multiple brand-impersonation phishing campaigns are targeting consumers by abusing trust in Avast and Apple to drive victims into disclosing payment or account details. One campaign uses a near-identical fake Avast portal aimed at French-speaking users, presenting a fabricated €499.99 “subscription charge” and a short cancellation window to induce urgency; the site validates entered card numbers using the Luhn algorithm and uses a Tawk.to live-chat widget (ID 689773de2f0f7c192611b3bf) to pressure victims in real time into submitting full card details (including CVV) under the pretense of processing a refund.
Separate Apple-themed scams use phishing-to-phone and SMS lures to route victims to scam call centers and harvest credentials and financial information. One email purporting to be from an “Apple Fraud Prevention” team attempts to panic recipients into calling a fake support number, while an “Apple Security Alert” Apple Pay text claims a suspicious $143.95 Apple Store transaction and urges an immediate call to a +1 850-85* number to “cancel” the charge. Another tactic abuses iOS Calendar subscriptions (“iPhone Calendar Scam”) to flood devices with fake security/prize alerts that push users to click malicious links; guidance emphasizes unsubscribing from the rogue calendar and avoiding interacting with the spam invites.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A scam email impersonating McAfee claimed a 'McAfee Firewall Security' subscription would auto-renew for $104.79 and urged recipients to call fake customer service numbers. The campaign was described as a subscription-renewal fraud designed to trick victims into granting computer access and disclosing credentials, personal data, and financial information.
A scam campaign impersonating Webroot was described using fake renewal texts, invoices, billing notices, and phishing emails that falsely claimed a payment or subscription renewal had been processed. Victims were pressured to call fraudulent support numbers, where scammers attempted to steal personal or financial information or gain remote access to devices.
A tech support scam was reported in which a fake Norton renewal email falsely claimed the recipient had been charged hundreds of dollars and urged them to call a listed number to cancel or modify the transaction. The number allegedly connected victims to a fraudulent call center impersonating Norton and other technology companies to steal credentials, banking details, or remote access.
Researchers identified a phishing campaign impersonating Avast with a near-identical website that falsely claimed victims were charged €499.99 and pushed them to submit payment card details for a supposed refund. Malwarebytes reported the site used client-side date generation, Luhn validation for card numbers, and a Tawk.to live chat widget to increase pressure and improve theft of usable card data.
A phishing tactic abusing iPhone calendar subscriptions was described, in which victims are tricked into subscribing to malicious calendars that generate persistent fake alerts and prize messages. The scam was noted to rely on social engineering rather than malware, with guidance provided for unsubscribing and removing suspicious calendar accounts.
An SMS phishing campaign posing as an "Apple Security Alert" claimed an Apple ID was used for a $143.95 Apple Pay pre-authorization and urged recipients to call a scammer-controlled number. The operation aimed to steal account credentials and personal or financial information through a fraudulent call center.
A phishing email campaign impersonating an "Apple Fraud Prevention Team" was reported, using alarmist language to pressure recipients into calling a fraudulent support number not associated with Apple. The scam was described as a phone-based social engineering attempt targeting Apple users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
onlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourcehackread.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.