-
Apple TestFlight Used for Phishing Attacks via Gemini/ChatGPT Ads Manager Beta Invitation
I wanted to give a heads up about these unsolicited Apple TestFlight invites.
I have recieved several and finally decided to open one. It is shocking r/apple allows TestFlight to be used to distribute Phishing attack vectors.
The email reads:
Gemini Ads Manager.
By Google Gemini Technologies ,LLC for iOS.
The link in the email comes from apple: https://testflight.apple.com/v1/invite/bf3d709416a041fda2409b9c60206b4b7728374630e7439d9b32226deaf7147c192e06659?ct=LD4B7L3UBD&advp=10000&platform=ios
My suspicion was raised when i was asked to use facebook account to login into a Gemini App, Clearly a phishing attack looking to capture facebook credentials.
I tried to use sign in with another method expecting an OTP to be sent to my email to verify it is really from facebook.com but clearly a phishing attack.
it is shocking that r/apple allows a developer called [email protected] to distribute an app in beta via testflight with title Gemini Ads Manager
Log in to reply.