
D3Lab identified a fraudulent page using the name and visual identity of SEND, the Digital Notification Service operated by pagoPA, to persuade users to interact with a website outside the official infrastructure. SEND is the platform through which Italian public administrations can serve official notices to citizens and businesses. The prospect of receiving a legally valid communication makes this theme particularly credible and effective at creating a sense of urgency.
What makes this campaign distinctive, however, is not merely the reproduction of the portal. While the victim is viewing the phishing page, the site can load a second resource hosted on a separate server inside an iframe. This resource selects and runs an exploit chain against Safari/WebKit, with modules designed for different iOS versions. The potential objective is therefore not limited to the information voluntarily entered into the page: the code also attempts to identify the device, bypass browser protections and establish a channel for control and data collection.
In simple terms, the victim believes they have opened a public administration notice. Behind that page, however, an attempt to compromise the iPhone can be launched without any additional visible download. The exploit does not appear to target current iOS releases: the recovered loader declares support up to iOS 17.2.1. An up-to-date device should therefore fall outside the scope declared by the kit, whereas a device still running a vulnerable version represents a more attractive target.
Based on D3Lab’s observations in the Italian threat landscape, this is the first time we have documented an iOS chain of this kind embedded in a conventional phishing campaign targeting Italy.
Continua a leggere














