Tag: phishing
-
OpenAI steigt erstmals in Top 10 der imitierten Marken auf
Check Point zeigt im Q2-2026-Bericht: Microsoft führt das Phishing-Ranking an, während ChatGPT von OpenAI erstmals unter den zehn meistimitierten Marken liegt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/openai-top-10-der-imitierten-marken
-
Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed
A newly analyzed phishing-driven intrusion set tracked as Operation BlueDash demonstrates how threat actors are operationalizing legitimate remote monitoring and management (RMM) tools to maintain persistent and redundant access to compromised environments. The infection chain begins with a Microsoft Teams-themed phishing email delivering a “secure document” lure. Victims are redirected through compromised infrastructur to a…
-
Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/call-of-duty-mobile-players-scam/
-
Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/call-of-duty-mobile-players-scam/
-
Phishing attacks on insurance companies evolve to real-time account hijacking
First seen on scworld.com Jump to article: www.scworld.com/brief/phishing-attacks-on-insurance-companies-evolve-to-real-time-account-hijacking
-
Phishing the agent: Why identity controls are essential to secure and manage AIs
First seen on scworld.com Jump to article: www.scworld.com/resource/phishing-the-agent-why-identity-controls-are-essential-to-secure-and-manage-ais
-
Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan. First seen on therecord.media Jump to article: therecord.media/telegram-belarus-activist-russia-cyberattack
-
OpenAI erstmals unter den zehn meistimitierten Marken
Der Bericht von Check Point über das Brand-Phishing-Ranking für das zweite Quartal 2026 listet erstmals eines der großen KI-Unternehmen in den Top 10. Die Experten beobachteten zudem konkrete Betrugsmaschen mit ChatGPT, Paypal, iCloud und Microsoft Microsoft bleibt weiterhin Spitzenreiter als meistimitierte Marke und vereint 23 Prozent aller Brand-Phishing-Versuche im Quartal auf sich. Das sind fast…
-
Ransomware, die erst Wochen nach dem Phishing zuschlägt
Ransomware und Phishing waren schon immer miteinander verbunden, doch das alte Modell war recht plump. Eine Phishing-E-Mail enthielt die Schadlast, der Empfänger öffnete sie, und innerhalb weniger Stunden erfolgte die Verschlüsselung. Wie die Bedrohung im Jahr 2026 aussieht, ist grundlegend anders. Die E-Mail, die die Kette in Gang setzt, enthält nichts Gefährliches. Stattdessen trifft die…
-
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management (RMM) tools.”The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened,” ZeroBEC said in First…
-
ChatGPT joins the most impersonated brands in phishing attacks
Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/check-point-brand-phishing-trends-report/
-
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra.According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote First…
-
Check Point Brand Phishing Ranking: Microsoft bleibt vorn, ChatGPT erstmals in den Top 10
ChatGPT erreicht erstmals die Top 10 der meistimitierten Marken. Microsoft bleibt laut Check Point mit 23 Prozent das wichtigste Phishing-Ziel. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/check-point-brand-phishing-ranking-microsoft-bleibt-vorn-chatgpt-erstmals-in-den-top-10/a45875/
-
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit. That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft. New research from JUMPSEC provides rare source-level visibility into the operation after attackers mistakenly exposed JavaScript…
-
KI-unterstützter Phishing-Baukasten durch offenen Server enttarnt
Ein offener Server von Angreifern enthüllte Rapid7 einen KI-gestützten Baukasten für Phishing-Kampagnen. Ziel war unter anderem Mexiko. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-unterstuetzter-phishing-baukasten
-
Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages. No phishing email required. No malicious attachment. Just bad luck about which hotel…
-
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.That model is changing.Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting First seen on thehackernews.com Jump to article:…
-
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
Tags: business, communications, credentials, crypto, cyber, data, email, infection, malware, phishing, powershellA sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite, the campaign uses two distinct phishing themes that both lead to the same infection chain. One email impersonates UPS Forwarding Hub, referencing fake…
-
Betrug mit echten Buchungsdaten: Phishing-Angriffe bei Booking.com
Wer kurz vor der Reise unerwartet eine WhatsApp-Nachricht seines gebuchten Hotels erhält, sollte misstrauisch werden. Dahinter steckt oft kein technischer Fehler, sondern raffinierter Betrug mit echten Buchungsdaten, berichtet das IT- und Technikmagazin c’t. Die Ursache sind kompromittierte Hotelkonten im Verwaltungssystem von Booking.com. Die Experten raten: niemals auf Links in solchen Nachrichten klicken im… First seen…
-
Cyberkriminelle werden kreativer: 9 Phishing-Varianten, die über E-Mails hinausgehen
First seen on t3n.de Jump to article: t3n.de/news/phishing-varianten-cyberangriffe-1679869/
-
Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and…
-
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization.The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June…
-
ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point
OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chatgpt-most-impersonated-brands/
-
UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations
UAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting WinRAR vulnerabilities and using phishing…
-
Russian APT Laundry Bear perfects zero-click phishing attack
A newly identified Russian state threat actor is using a novel zero-click phishing technique, likely developed with the help of an AI, to target Western users of Zimbra software products First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645968/Russian-APT-Laundry-Bear-perfects-zero-click-phishing-attack
-
Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing
Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have…
-
Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload
A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of the Brazilian-origin banking trojan, first documented in 2019, which has consistently focused on Portuguese-speaking victims rather than domestic Brazilian targets. In the latest campaign, attackers leverage convincing financial-themed phishing emails masquerading as routine…
-
Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access
Attackers are increasingly abusing Microsoft Teams to impersonate internal IT support and trick employees into handing over remote access and corporate credentials, even as traditional email phishing volumes tied to major platforms like Tycoon2FA decline. Microsoft’s recent email threat landscape data for Q2 2026 shows a sharp downstream impact from the March disruption of the…
-
The best-funded companies open the most phishing attachments
An employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/phishing-simulation-benchmark-report/

