Tag: phishing
-
Zendesk Infrastructure Exploited in Phishing and Pig Butchering Schemes
A new report from CloudSEK reveals threat actors are leveraging Zendesk’s free trial to create convincing phishing campaigns. First seen on securityonline.info Jump to article: securityonline.info/zendesk-infrastructure-exploited-in-phishing-and-pig-butchering-schemes/
-
Gamer geraten ins Phishing-Fadenkreuz
Tags: phishingFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/gamer-phishing-fadenkreuz
-
Datenleck bei North Pole Company Canada
Nächstes (bisher vom Unternehmen noch unbestätigtes) Datenleck. Bei der North Pole Company Canada hat es ein Datenleck gegeben, bei dem die Daten von 500.000 Benutzern öffentlich abrufbar waren. Die könnten nun der Gefahr ausgesetzt sein, Opfer von Phishing, Betrug und … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/01/21/datenleck-bei-north-pole-company-canada/
-
‘Sneaky Log’ Microsoft Spoofing Scheme Sidesteps Two-Factor Security
The phishing-as-a-service kit from Sneaky Log creates fake authentication pages to farm account information, including two-factor security codes. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/sneaky-log-microsoft-phishing-2fa/
-
AI-supported spear phishing fools more than 50% of targets
First seen on thesecurityblogger.com Jump to article: www.thesecurityblogger.com/ai-supported-spear-phishing-fools-more-than-50-of-targets/
-
Ransomware gangs pose as IT support in Microsoft Teams phishing attacks
Ransomware gangs are increasingly adopting email bombing followed by posing as tech support in Microsoft Teams calls to trick employees into allowing remote control and install malware that provides access to the company network. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransomware-gangs-pose-as-it-support-in-microsoft-teams-phishing-attacks/
-
Phishing Risks Rise as Zendesk Subdomains Facilitate Attacks
A CloudSEK report revealed Zendesk’s platform can be exploited for phishing and investment scams First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/zendesk-subdomains-facilitate/
-
Cyberkriminelle missbrauchen Microsoft-Teams als Einfallstor mit E-Mail-Bombing und Voice-Phishing
Sophos-X-Ops hat eine aktive Bedrohungskampagne näher untersucht, bei der zwei verschiedene Gruppen von Bedrohungsakteuren Unternehmen infiltrieren, indem sie die Funktionalität der Office-365-Plattform missbrauchen und anschließend versuchen, Daten abzuziehen oder Ransomware platzieren. Besonders perfide: die Angreifer verwenden eine Kombination aus E-Mail-Bombing mit bis zu 3.000 Nachrichten in weniger als einer Stunde und anschließenden Sprach- bzw. Videoanrufen…
-
Gamer im Fadenkreuz
Tags: phishingKürzlich haben Forscher von Malwarebytes in einem Blogbeitrag eine neue Phishing-Kampagne vorgestellt, die auf Gamer abzielt. Die Opfer werden dabei mit dem Angebot, Betatester eines neuen Videospiels werden zu können, geködert. Laden sie sich eine Archivdatei, die das vermeintliche Spiel enthält, auf ihr System herunter, befinden sich Infostealer unter den Daten. Deren Ziel: das Abgreifen…
-
Echtzeit-Deepfakes werden das neue Phishing
Ohne Zweifel: Die künstliche Intelligenz wird auch das Jahr 2025 bestimmen, auch und insbesondere in der Cybersecurity. Eines der Felder, in der sie schon einige Zeit eingesetzt wird, sind mittels Midjourney und ähnlichen Tools erstellte Fake-Bilder. Ein echter Meilenstein war hier wohl das Bild vom Papst in der weißen Daunenjacke, das im März 2023 veröffentlicht…
-
Beware! Fake SBI Reward APK Attacking Users to Deliver Android Malware
A recent phishing campaign has targeted customers of SBI Bank through a deceptive message circulating in WhatsApp groups. The message falsely claims that the recipient’s SBI reward points, amounting to Rs 9,980, will expire unless they download a purported >>SBI BANK REWARD App.
-
PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installers
Cybersecurity researchers are calling attention to a series of cyber attacks that have targeted Chinese-speaking regions like Hong Kong, Taiwan, and Mainland China with a known malware called ValleyRAT.The attacks leverage a multi-stage loader dubbed PNGPlug to deliver the ValleyRAT payload, Intezer said in a technical report published last week.The infection chain commences with a…
-
Warnung vor neuer Phishing-Angriffskampagne über Reisebüro-Konten
Tags: phishingFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/warnung-neuheit-phishing-angriffskampagne-reisebuero-konten
-
Phishing Attacks Are the Most Common Smartphone Security Issue for Consumers
New hands-on testing results show that most devices are unable to catch phishing emails, texts, or calls, leaving users at risk. First seen on darkreading.com Jump to article: www.darkreading.com/mobile-security/phishing-attacks-are-most-common-smartphone-security-consumer-issue
-
Hackers Weaponize MSI Packages PNG Files to Deliver Multi-stage Malware
Researchers have reported a series of sophisticated cyber attacks aimed at organizations in Chinese-speaking regions, including Hong Kong, Taiwan, and mainland China. These attacks employ a multi-stage loader known as PNGPlug to deliver a malware payload identified as ValleyRAT. The attack chain begins with a phishing webpage that entices victims into downloading a malicious Microsoft…
-
Phishing über Reisebüro-Konten: Tausende Unternehmen betroffen
Check Point warnt vor einer groß angelegten Phishing-Kampagne, die bereits über 7.300 Unternehmen und 40.000 Einzelpersonen betroffen hat. Besonders stark betroffen sind die USA (75 Prozent der Fälle) sowie die Europäische Union (10 Prozent). First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/phishing-ueber-reisebuero-konten-tausende-unternehmen-betroffen
-
Telegram-Based >>Sneaky 2FA<< Phishing Kit Targets Microsoft 365 Accounts
Sneaky 2FA: New Phishing-as-a-Service targets Microsoft 365, leveraging sophisticated evasion techniques and a Telegram-based platform to steal credentials…. First seen on hackread.com Jump to article: hackread.com/telegram-sneaky-2fa-phishing-kit-microsoft-365-accounts/
-
Black Basta Exploits Microsoft Teams for Phishing Attacks
NVISO Labs has uncovered a sophisticated phishing campaign attributed to the ransomware group Black Basta, leveraging Microsoft Teams First seen on securityonline.info Jump to article: securityonline.info/black-basta-exploits-microsoft-teams-for-phishing-attacks/
-
Scammers Exploit Truth Social to Launch Phishing and Fraud Campaigns
Truth Social, the social media platform launched by Trump Media & Technology Group in 2022, has become a First seen on securityonline.info Jump to article: securityonline.info/scammers-exploit-truth-social-to-launch-phishing-and-fraud-campaigns/
-
Star Blizzard Shifts Tactics: Spear-Phishing Campaign Targets WhatsApp Accounts
Microsoft Threat Intelligence has uncovered a new spear-phishing campaign orchestrated by the Russian threat actor known as Star First seen on securityonline.info Jump to article: securityonline.info/star-blizzard-shifts-tactics-spear-phishing-campaign-targets-whatsapp-accounts/
-
Sneaky 2FA: A New Adversarythe-Middle Phishing-asService Threat
SEKOIA’s Threat Detection & Research (TDR) team has exposed a new Adversary-in-the-Middle (AiTM) phishing kit, dubbed “Sneaky 2FA.” First seen on securityonline.info Jump to article: securityonline.info/sneaky-2fa-a-new-adversary-in-the-middle-phishing-as-a-service-threat/
-
Star Blizzard hackers abuse WhatsApp to target high-value diplomats
Russian nation-state actor Star Blizzard has been running a new spear-phishing campaign to compromise WhatsApp accounts of targets in government, diplomacy, defense policy, international relations, and Ukraine aid organizations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/star-blizzard-hackers-abuse-whatsapp-to-target-high-value-diplomats/
-
‘Sneaky Log’ phishing kits slip by Microsoft 365 accounts
First seen on scworld.com Jump to article: www.scworld.com/news/sneaky-log-phishing-kits-slip-by-microsoft-365-accounts
-
Hackers use Google Search ads to steal Google Ads accounts
Ironically, cybercriminals now use Google search advertisements to promote phishing sites that steal advertisers’ credentials for the Google Ads platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-use-google-search-ads-to-steal-google-ads-accounts/
-
Google Ads Users Targeted in Malvertising Scam Stealing Credentials and 2FA Codes
Cybersecurity researchers have alerted to a new malvertising campaign that’s targeting individuals and businesses advertising via Google Ads by attempting to phish for their credentials via fraudulent ads on Google.”The scheme consists of stealing as many advertiser accounts as possible by impersonating Google Ads and redirecting victims to fake login pages,” Jérôme Segura, senior director…
-
Suspected Ukrainian hackers impersonating Russian ministries to spy on industry
Researchers have recently observed phishing emails purportedly from Russia’s Ministry of Industry and Trade laden with remote access malware.]]> First seen on therecord.media Jump to article: therecord.media/suspected-ukraine-hackers-russian-phishing
-
Hotel chain ditches Google search for DuckDuckGo, ‘subjected to fraud attempts daily’
Tags: apple, attack, authentication, browser, chrome, cloud, control, cybercrime, cybersecurity, data-breach, fraud, google, jobs, malware, mfa, monitoring, phishing, privacy, ransomware, risk, scam, service, tool, windowsAt the end of 2021, Nordic Choice Hotels, now renamed Strawberry, was hit by a major ransomware attack that paralyzed operations for just over a week. Everything had to be done manually, says Martin Belak, who is responsible for the hotel chain’s technical security.”The receptionists worked with whiteboards to keep track of which rooms were…

