AntiMalwareSeptember 2, 2026🇷🇺Translated from Russian

Unsolicited iPhone 15 Pro Max Delivery to Reddit User Sparks Fears of Targeted Cyber Attack

A Reddit user recently received an unsolicited iPhone 15 Pro Max delivered in a sealed retail box that the recipient had never ordered. The smartphone appeared brand new on the outside, yet verification of its serial number through Apple’s systems immediately raised red flags.

According to Apple’s records, the device had been purchased or activated as early as December 2023, and its warranty coverage had already expired in 2024. This timeline directly contradicts the pristine condition of the packaging, suggesting the phone inside may have been used or handled previously.

The shipment arrived with a FedEx shipping label, but the tracking number printed on the label could not be found in the carrier’s official tracking system. The recipient wisely chose not to power on the device, insert a SIM card, or link it to any personal network or Apple ID.

Community discussion on Reddit quickly turned to the possibility of a targeted cyber attack. Commenters speculated that an adversary might have sent a pre-modified handset as part of a whaling or spear-phishing operation aimed at extracting sensitive data or gaining access to high-value accounts once the phone was activated.

While the scenario resembles techniques sometimes associated with advanced targeted attacks, no definitive proof has emerged that the package was sent by malicious actors. It remains equally plausible that the delivery resulted from a logistics error, return fraud, or another non-security-related mix-up.

Security-conscious recipients of similar unsolicited devices are advised to leave the hardware powered off, avoid any network connections, and either submit it to Apple for forensic examination or recycle it through certified electronic-waste channels.

Related articles

AntiMalwareFraud & Social Engineering

F6 and MAX Neutralize Over 2,550 External Phishing and Scam Resources in Two-Month Operation

F6 and the MAX messenger have jointly blocked more than 2,550 malicious external websites used for phishing, scams, and other forms of online fraud. The effort relied on the F6 Digital Risk Protection platform, which continuously scans for fake authentication pages and fraudulent resources targeting users. Monitoring took place during July and August 2026, after which experts from both organizations arranged for the sites to be taken down. The action focused exclusively on external resources and did not involve any malicious content hosted inside the MAX messenger itself. F6 Digital Risk Protection head Stanislav Goncharov noted that regular takedowns can reduce attacker activity over time, yet users must still verify website addresses manually before entering credentials or payment data.

HispasecFraud & Social Engineering

Trezor Warns of Email Provider Breach Used in Targeted Phishing Campaign Against Hardware Wallet Users

Trezor has disclosed that attackers compromised an external email provider and leveraged it to send phishing messages that appeared to originate from the company. The emails carried the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and falsely claimed a hardware flaw in STM32 microcontrollers that would reduce entropy and allow seed phrase reconstruction. No such CVE exists, and the campaign followed classic social-engineering patterns of urgency and brand impersonation aimed at stealing recovery phrases. Trezor has since disabled the malicious domain and continues investigating how the provider was accessed. Similar messages may have reached users of BitBox, suggesting possible compromise of shared service providers across the hardware wallet ecosystem. The incident underscores the difficulty of detecting phishing when it originates from legitimate third-party infrastructure.

AntiMalwareFraud & Social Engineering

Free Robux Lures Used in Phishing Campaign Targeting Children's Messenger Accounts

Scammers have launched a new wave of attacks aimed at children and teenagers by promising free in-game currency for Roblox, Brawl Stars, and Standoff 2. The scheme, uncovered by specialists from F6, uses short YouTube videos that direct victims to phishing sites disguised as reward platforms. One prominent site branded as NovaDrop tricks users into selecting a messenger and game before presenting a rigged roulette that awards a fake prize of 25,000 coins. To claim the reward, victims must enter a phone number and six-digit verification code, which actually authorizes the attackers in the chosen messenger. Once inside, the criminals can read conversations, view documents and media, access contacts, and send messages to the victim's friends while sometimes remaining undetected. The attackers are increasingly focused on hijacking existing accounts due to difficulties in purchasing new Russian profiles for their operations.

HabrFraud & Social Engineering

Dynamic QR Codes Enable Personalized Redirects and Conceal Final Destinations

Dynamic QR codes printed on menus, receipts, and advertisements do not contain the final destination URL. Instead they point to an intermediary service that logs each scan and issues a redirect chosen at scan time. The redirect decision can depend on device model, language, IP address, country, and previous scans, allowing different users to receive entirely different pages. Owners can change the target after printing without replacing the physical code, creating risks when domains or accounts change hands. Each scan records time, device details, and approximate location, leaving a trail users did not consent to. Attackers exploit these properties with overlay stickers, QR codes inside documents that bypass email filters, and fake payment pages that request card details instead of processing a true QR payment.