Bogus iCloud log-in page fools Chinese Apple users

Chinese hackers have launched a man-in-the-middle attack designed to intercept the usernames and passwords of Apple's iCloud users.

According to reports from anti-censorship organisation Greatfire, the hack coincides with the launch of the Apple iPhone 6 and 6 Plus in the country.

The organisation said Chinese users that try to log into iCloud using the IP address 23.59.94.46 will see a fake login site identical to the real Apple iCloud login page. However, alarm bells should ring as the fake site throws up a few security warnings.

Users with browsers such as Chrome or Firefox should detect fake security certificates, however many in the country prefer to use home-grown browsers that do not flag these certificates as bogus. Greatfire said Qihoo's popular Chinese 360 secure browser is "anything but and will load the MITMed page directly."

If users ignore the warnings, their details will get passed onto eavesdroppers, it is claimed.

"This is clearly a malicious attack on Apple in an effort to gain access to user names and passwords and consequently all data stored on iCloud such as iMessages, photos, contacts, etc," said Greatfire in the blog post.

"Unlike the recent attack on Google, this attack is nationwide and coincides with the launch today in China of the newest iPhone."

The censorship watchdog said authorities had also mounted attacks on Google, Yahoo, Github and others. It said the latest attack may also somehow be related again to images and videos of the Hong Kong protests being shared on the mainland.

Greatfire also said the attack could be related to the increased security of the new iPhone. Better encryption on the iPhone designed to keep out the NSA would also prevent Chinese authorities snooping on Apple's users.

The censorship watchdog said this latest episode should "provide a clear warning signal to foreign companies that work with the Chinese authorities on their censorship agenda".

"Working with the authorities to help them prevent free access to news and information is not a guaranteed path to riches in China. If anything, cooperation with the Chinese authorities can now increasingly be labelled as the worst decision a foreign company can make."

Greatfire urged users to access the internet using a VPN and enable two-factor authentication on their iCloud accounts.

Rene Millman

Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.