OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters

OS-Aware Phishing Kit Fans Fake iCloud Alert into (TL-2026-2704), also tracked as OS-Aware iCloud Phishing Kit, is a high-severity phishing campaign, first published 2026-09-27. It is attributed to G-MLOGS Operator Group with low confidence, affects Apple iCloud / Apple ID sign-in, maps to 13 MITRE ATT&CK techniques (T1027, T1036, T1102.002), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-2704

Threat ID
TL-2026-2704
Also known as
OS-Aware iCloud Phishing Kit, G-MLOGS
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-27
Last reviewed
2026-09-27
Attribution
G-MLOGS Operator Group
Attribution confidence
LOW
Motivation
FINANCIAL
Target regions
united states of america
Detection rules
9
Indicators of compromise
18

Malware and tooling in OS-Aware Phishing Kit Fans Fake iCloud Alert into

Malware and tooling: @dswagofficebot (Telegram Bot ID 5958383710), @smokeiT_bot (Telegram Bot ID 6075686319), ScreenConnect

A reusable, operator-maintained phishing kit spoofs an iCloud sign-in alert and reads the visitor's User-Agent server-side to silently fork traffic by OS: Windows users are socially engineered into installing a code-signed ScreenConnect RMM client for full interactive access, Apple users are routed to a spoofed iCloud/Apple ID credential page, and Android/Linux users hit a fake Microsoft sign-in page with a live human-operated Telegram AiTM relay that captures and replays MFA codes.

How OS-Aware Phishing Kit Fans Fake iCloud Alert into works

KnowBe4 Threat Labs identified and dismantled an active, architecturally isolated phishing operation that profiles each visitor's operating system at click-time and routes them down one of three independent attack branches from a single email lure. The lure impersonates an Apple iCloud 'new sign-in' security alert, complete with a fabricated device/IP/timestamp, a fake support reference number, and a corporate legal disclaimer, and displays https://account.apple.com while the underlying link actually resolves elsewhere. Clicking the link first passes through a three-hop SEG-bypass redirect chain: an abused open redirect on the legitimate credit-union domain track[.]rbfcu[.]org (exploiting trusted-domain allow-listing), through the intermediate domain globalema[.]com carrying a base64-encoded destination parameter, and finally to the attacker-controlled server cherylbirch[.]com. Before serving content, cherylbirch[.]com runs every request through antibot.php, which fingerprints User-Agent strings associated with Microsoft Defender/ZAP scanners, checks the HTTP Referer header for Outlook SafeLinks rewriting, queries ip-api.com to filter out cloud-sandbox IP ranges, and requires a mouse-move or keypress within 5 seconds to weed out headless browsers (failures are silently bounced to zoom[.]com). Traffic that survives the gate is forked purely on User-Agent: Windows visitors are shown a spoofed DocSend 'secure document' portal that delivers a legitimately code-signed ScreenConnect.ClientSetup.exe installer, granting the operators full interactive remote access to the victim machine without triggering antivirus (SHA-256 f9a67b861d56beffa0c880ecc90ec8c1fe6b540aec6438783bb60ea094c0aef9). Apple visitors (iPhone/iPad/Mac User-Agents) are silently redirected off-domain to andersonsin[.]com, which hosts a spoofed iCloud login page to harvest Apple ID credentials, with the same reusable server infrastructure also hosting Microsoft 365 credential-harvesting templates. Android, Linux, and other visitors are routed to a fake Microsoft sign-in page backed by a live adversary-in-the-middle relay: the moment a victim submits credentials, they are pushed to the operator's Telegram bot (@smokeiT_bot) in real time, and the victim's browser polls the backend every 3 seconds waiting for the human operator's reply, letting the operator steer the victim through additional prompts and capture and replay time-sensitive MFA codes before they expire. Across all branches, a fabricated 'incorrect password' error forces every victim to re-enter their credentials a second time, a low-cost filter that discards typo'd submissions and passes only validated credential pairs downstream. KnowBe4 found the attacker's server had directory listing enabled, exposing the full kit: a small, coordinated five-person Telegram supergroup ('G-MLOGS', channel ID -1003626986152) with a production exfiltration bot (@smokeiT_bot, bot ID 6075686319) and a separate debug/test bot (@dswagofficebot, bot ID 5958383710), operated principally by @jhlee111 (user ID 6156764114, group creator) with @dswag10 ('Babasuwe') handling the live AiTM relay. Telegram bot tokens dating to September 2025 indicate the kit has been operational for 8+ months. The same server hosted unrelated, modular phishing templates for other targets entirely, including a fake Awardco HR-platform login page (iex.html) and additional Microsoft Authenticator, Google, and enterprise SSO harvesting pages, confirming this is plug-and-play, reusable phishing-kit infrastructure rather than a one-off campaign. During the observed 48-hour window (May 5-6, 2026), the kit drove 250+ confirmed human clicks, with Apple devices accounting for 65% of traffic, Windows 28%, and Android/other 7%; of 157 geolocated victims, 150 (over 95%) were located in the United States. The architectural isolation between the three OS branches is itself a novel evasion technique: because each branch is served from functionally separate infrastructure and payload logic, defenders investigating one branch (e.g., the ScreenConnect delivery) are unlikely to independently discover or correlate the other two branches (Apple ID harvesting, Android/Linux AiTM relay), degrading full-picture detection and takedown efforts.

MITRE ATT&CK techniques used in TL-2026-2704

Stealth

T1027 Obfuscated Files or Information; T1036 Masquerading; T1684.001 Impersonation

Command and Control

T1102.002 Bidirectional Communication; T1219 Remote Access Tools

Credential Access

T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle

Execution

T1204.002 Malicious File

Initial Access

T1566.002 Spearphishing Link

Exfiltration

T1567.004 Exfiltration Over Webhook

Resource Development

T1583.001 Domains; T1608.005 Link Target

Reconnaissance

T1598 Phishing for Information

Affected products and versions in OS-Aware Phishing Kit Fans Fake iCloud Alert into

  • Apple — iCloud / Apple ID sign-in
    Vulnerable versions: N/A - credential phishing targets all Apple ID account holders
  • Microsoft — Microsoft 365 / Microsoft sign-in portal (spoofed)
    Vulnerable versions: N/A - credential phishing targets all Microsoft 365 account holders
  • ConnectWise — ScreenConnect (legitimate, code-signed client abused as social-engineered payload)
    Vulnerable versions: N/A - legitimate signed installer socially engineered onto victim endpoints

Remediation for OS-Aware Phishing Kit Fans Fake iCloud Alert into

Immediate actions

  • Block/sinkhole the identified domains at DNS and web proxy: cherylbirch[.]com, andersonsin[.]com, globalema[.]com, login1.indomesinq[.]click
  • Hunt for and remove any installations of ScreenConnect.ClientSetup.exe matching SHA-256 f9a67b861d56beffa0c880ecc90ec8c1fe6b540aec6438783bb60ea094c0aef9 that were not deployed by authorized IT/RMM administrators
  • Force password resets and re-enrollment of MFA for any user who reported clicking the iCloud sign-in alert lure during May 5-6, 2026
  • Report the abused open-redirect endpoint on track[.]rbfcu[.]org to the domain owner so the redirect can be closed

Workarounds

  • Disable or tightly restrict outbound access to *.telegram.org / Telegram Bot API domains from general end-user network segments where no legitimate business use exists
  • Configure email security gateways to detonate and follow multi-hop redirect chains rather than trusting allow-listed intermediate domains at face value

Longer-term hardening

  • Deploy application allow-listing / EDR policy that blocks unauthorized installation of RMM clients (ScreenConnect, AnyDesk, TeamViewer, etc.) outside change-managed IT deployment channels
  • Implement phishing-resistant, non-relayable MFA (FIDO2/WebAuthn hardware keys) for iCloud/Apple ID, Microsoft 365, and other high-value SSO to eliminate the value of AiTM-captured OTP/push codes
  • Add behavioral detection for User-Agent-conditioned server-side redirect forking and for consumer messaging-app (Telegram) egress traffic from endpoints
  • Audit and restrict open-redirect endpoints on owned/partner web properties that could be abused for SEG-bypass redirect chains

Timeline of OS-Aware Phishing Kit Fans Fake iCloud Alert into

  • PHP error logs and Telegram bot token creation dates on the attacker's server indicate the phishing kit and its Telegram C2 bots became operational, giving KnowBe4 8+ months of prior activity evidence by the time of analysis.
  • A fabricated 'incorrect password' error forces every victim across all three branches to re-enter their credentials a second time, letting operators discard typo'd submissions and pass only validated credential pairs downstream.
  • Android/Linux/other visitors are routed to a fake Microsoft sign-in page backed by a live AiTM relay: submitted credentials are pushed to the operator's Telegram bot @smokeiT_bot in real time, the victim's browser polls every 3 seconds for the operator's next instruction, and the operator manually captures and relays MFA codes before expiry.
  • Apple/macOS visitors are silently redirected off-domain to andersonsin[.]com, which hosts a spoofed iCloud login page harvesting Apple ID credentials on infrastructure that also serves Microsoft 365 credential-harvesting templates.
  • Windows victims are shown a spoofed DocSend secure-document portal that delivers the code-signed ScreenConnect.ClientSetup.exe installer (SHA-256 f9a67b861d56beffa0c880ecc90ec8c1fe6b540aec6438783bb60ea094c0aef9), granting the operators full interactive remote access without triggering antivirus.
  • cherylbirch[.]com inspects the visitor's User-Agent server-side and silently forks the victim into one of three independent branches: Windows to ScreenConnect delivery, Apple (iPhone/iPad/Mac) to andersonsin[.]com, and Android/Linux/other to a Microsoft-themed AiTM harvester.
  • Surviving traffic passes through antibot.php, which fingerprints Defender/ZAP User-Agents, checks the HTTP Referer for Outlook SafeLinks, queries ip-api.com for cloud-sandbox IP reputation, and requires mouse/keyboard interaction within 5 seconds, bouncing failures to zoom[.]com.
  • Clicked links are funneled through a three-hop redirect chain: an abused open redirect on the legitimate credit-union domain track[.]rbfcu[.]org, an intermediate domain globalema[.]com carrying a base64-encoded destination, and finally the attacker payload server cherylbirch[.]com.
  • Mass phishing emails impersonating an Apple iCloud 'new sign-in' security alert begin reaching targets, opening a 48-hour high-volume campaign window (May 5-6, 2026) that produced 250+ confirmed clicks.
  • The 48-hour observed campaign window closes with 250+ confirmed human clicks recorded; 150 of 157 geolocated victims (over 95%) are located in the United States, with Apple devices accounting for 65% of traffic and Windows 28%.
  • KnowBe4 Threat Labs publishes 'Inside the OS-Aware Phishing Kit Profiling Your Device,' disclosing the kit's architecture, the exposed server (directory listing enabled), Telegram operator handles (@jhlee111, @dswag10) and the 'G-MLOGS' supergroup, and evidence of reusable, unrelated phishing templates (e.g., an Awardco HR-platform lure) on the same infrastructure.

Sources cited for OS-Aware Phishing Kit Fans Fake iCloud Alert into

More in phishing

Detection coverage for TL-2026-2704

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2704 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2704

3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats