Cyber Security News

Cybercriminals Leveraging CapCut Popularity to Harvest Apple ID Credentials & Credit Card Data

Cybercriminals have begun exploiting the widespread popularity of CapCut, the dominant short-form video editing application, to orchestrate sophisticated phishing campaigns targeting Apple ID credentials and credit card information.

This emerging threat demonstrates how attackers strategically leverage trending applications to enhance the credibility of their malicious schemes, creating convincing lures that deceive unsuspecting users into surrendering sensitive personal and financial data.

The attack campaign employs meticulously crafted fake CapCut subscription invoices distributed via email, presenting recipients with fraudulent billing notifications for CapCut Pro subscriptions priced at $49.99 per month.

Email Body (Source – Cofense)

These deceptive communications incorporate official CapCut branding and Apple Store references, creating an authentic appearance that instills trust in potential victims.

The emails feature compelling calls-to-action, specifically “Cancel Your Subscription” buttons that serve as the initial infection vector for the multi-stage attack.

First Landing Page (Source – Cofense)

Cofense analysts identified this campaign as a sophisticated two-pronged phishing operation designed to maximize credential harvesting efficiency.

The researchers noted that threat actors have implemented advanced social engineering tactics, combining urgency-driven messaging with financial incentives to manipulate victims into compliance.

The campaign’s effectiveness stems from its exploitation of users’ familiarity with legitimate subscription services and their natural desire to avoid unwanted charges.

Infection Mechanism and Technical Analysis

The attack initiates when victims interact with the malicious “Cancel Your Subscription” button, redirecting them to a fraudulent Apple ID login page hosted at flashersofts[.]store/Applys/project/index[.]php.

This domain, completely unrelated to legitimate Apple services, presents an authentic-looking interface that mimics official Apple branding and design elements.

Upon credential submission, the malicious site executes an HTTP POST request to the command-and-control server at IP address 104[.]21[.]33[.]45, transmitting stolen Apple ID credentials in plaintext format.

The attack then transitions to its second phase, presenting victims with a fake “Apple Pay Refund” interface requesting credit card details under the pretext of processing the subscription refund.

Fake Authentication code prompt (Source – Cofense)

The campaign concludes with a deceptive authentication code verification step that never actually sends codes, regardless of user attempts.

This final component serves to delay victim suspicion and prevent immediate incident reporting, allowing attackers additional time to exploit harvested credentials before detection.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

7 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

11 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

17 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

23 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

33 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago