Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
appleoficial[.]support
“iCloud”
Stored detection
Cloaking alert
- Cloaking type
status_split- Cloaking score
- 1/6
Evidence Summary
The domain appleoficial.support poses a serious brand impersonation threat by masquerading as an official Apple service, specifically using the page title "iCloud" to deceive users. This tactic aims to trick individuals into believing they are interacting with Apple's legitimate support or cloud services, potentially leading to the theft of personal data, login credentials, or financial information. Users should be cautious and avoid entering any sensitive information on this site to prevent identity theft or financial loss.
PhishDestroy's analysis reveals that appleoficial.support was registered on February 8, 2026, through the registrar Gransy, s.r.o. The domain has been flagged by 20 out of 95 security vendors on VirusTotal, indicating a significant consensus about its malicious intent. It currently appears on two prominent security blocklists, OpenPhish and PhishingArmy, further confirming its elevated risk level. The domain uses a free SSL certificate from Let's Encrypt, which can give a false sense of security despite the site’s fraudulent nature. It resolves to the IP address 31.148.99.121, which should be monitored by network defenders.
If someone has visited appleoficial.support, it is critical not to provide any personal or login information. Users who suspect they may have submitted credentials should immediately change their Apple ID password and enable two-factor authentication for enhanced security. Running a comprehensive malware and antivirus scan is advisable to detect any potential infections. Additionally, reporting the site to relevant cybersecurity authorities can help protect others from falling victim to this impersonation attempt. Staying vigilant about domain authenticity and verifying URLs before engagement remains the best defense against such threats.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260329-44E4BB- Captured page title
- iCloud
- PDF artifact
- PDF evidence
Legal basis
Full evidence text
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | appleoficial.support |
phishing | Phishing Block |
| Hagezi Threat Feed | appleoficial.support |
malicious | Sinkholed |
| Cloudflare DNS | appleoficial.support |
malicious | Sinkholed |
| DNS4EU | appleoficial.support |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 10, 2026
10 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of appleoficial.support · checked Mar 29, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive