Monday, August 31, 2026

'KakaoTalk Impersonation' Login Screen Was Enough to Get Everything Stolen... iPhone Hack Code Raises Alarm

Input
2026-08-31 07:29:37
Updated
2026-08-31 07:29:37
/Photo=Yonhap News Agency, Nurilab

[Financial News] A new phishing attack has emerged that can steal personal information stored on an iPhone simply by visiting what looks like a KakaoTalk login screen. The attack specifically targets certain versions of the iPhone operating system (iOS), prompting users to remain on alert.
Malware Disguised as KakaoTalk Screen Steals Internal iPhone Data

According to Nurilab, an AI security company, on the 29th, malware has recently been distributed that disguises itself as a KakaoTalk login screen and steals internal iPhone data.
The phishing site was made to look so similar to the real KakaoTalk login page that it is difficult to tell them apart. It appears to be a normal login screen on the surface, but once a user visits it, the site communicates with the hacker's attack server in the background.
The attack can begin simply when a user clicks a link sent through a text message or messenger app and accesses the site.
The attack server first checks the operating system version of the smartphone that connected. The target range is iOS 18.4.0 through 18.7.2. If one of those versions is detected, the malware is activated. The attack is designed to stop on iOS 18.7.3 or later.
The hacker used a 'full-chain exploit' technique that breaks through multiple security vulnerabilities step by step.
First, the attacker uses a vulnerability in the browser engine to access iPhone memory. Next, the attack disables Apple's core security technology, Pointer Authentication Codes (PAC), which protects against memory manipulation. Finally, it breaks through the sandbox, which prevents each application from freely accessing other areas.
Once device control is secured through this process, the damage is not limited to account information. It has been confirmed that the attacker can also steal files and network information stored on the iPhone, as well as keychain data, the encrypted system that stores smartphone wallet and password information.
Nurilab: 'Comparable to the latest commercial spyware'

Nurilab said the attack method is comparable to the latest commercial spyware developed by specialized firms. However, it added that the information confirmed so far is not enough to conclude that a specific country or hacking group was behind it.
Ko Bo-seung, head of the Minos Ignite Center at Nurilab, said, "Phishing attacks have evolved beyond simple account theft into a form that can seize full device privileges just by making a connection." He added, "We will quickly block new security threats by combining automated analysis technology with in-depth analysis."
Above all, keeping the iPhone operating system up to date is essential to prevent damage. In particular, since this attack was designed to target iOS 18.4.0 to 18.7.2 and stop working on 18.7.3 or later, users need to check whether their operating system has been updated.
Users should also avoid directly clicking login links sent through text messages or messengers such as KakaoTalk. Even if the screen looks identical to the real service, the link itself may lead to a malicious site.
Companies also need to check the security update status of smartphones used by employees and take steps such as blocking access to malicious sites.
[email protected] Ahn Ga-eul Reporter