Tag: phishing
-
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts.The multi-stage campaign, codenamed Operation DragonReturn by Seqrite Labs, involves sending spear-phishing emails impersonating the Income Tax Department of India. First seen on thehackernews.com…
-
Passwortlos gegen Phishing-Angriffe – Passwörter sind der größte Angriffsvektor Zeit für phishing-resistente Identitäten
First seen on security-insider.de Jump to article: www.security-insider.de/rsa-id-iq-report-2026-identitaetsbasierte-angriffe-ki-phishing-a-434412b15a2192f3be56a78ba2ffb6de/
-
FIFA World Cup Phishing Scam Uses Fake Reward Pages to Steal Credit Card Data
A sophisticated email phishing campaign exploiting the global excitement around the 2026 FIFA World Cup is deceiving fans with counterfeit reward pages designed to harvest credit card information rather than deliver promised prizes. Security researchers have identified a multi-stage attack chain that begins with an authentication-passing email, progresses through geo-cloaked redirectors, and culminates in a…
-
Hackers Use RedLine C2 Infrastructure to Target South Korean Maritime Industry
A single RedLine Stealer command-and-control (C2) indicator has revealed a focused spear-phishing campaign targeting the South Korean maritime industry, exposing a cluster of attacker-owned domains and mail infrastructure used to distribute credential-stealing payloads. The initial signal originated from a VMRay UniqueSignal feed: an IP observed running RedLine activity on a non-standard high port (194[.]156.79.122:55615). That…
-
Hackers Use Server-Side Geofencing to Deliver Ousaban Banking Trojan in Spain and Portugal
A targeted campaign that delivers the Ousaban banking Trojan to users in Spain and Portugal using sophisticated server-side geofencing and multi-stage delivery. The adversary begins with a socially engineered phishing PDF that impersonates a corrupted document and coerces victims into visiting a malicious webpage through an “Atualizar” (Update) prompt. The PDF’s JavaScript is hex-escaped to…
-
4 ways to combat the endless stream of phishing attacks
First seen on scworld.com Jump to article: www.scworld.com/perspective/4-ways-to-combat-the-endless-stream-of-phishing-attacks
-
Armored Likho APT Deploys BusySnake Stealer Against Government and Power Sector Targets
A focused phishing campaign operated by a previously unreported APT we’ve named Armored Likho (also tracked under the provisional alias Eagle Werewolf). The group is targeting government agencies and the electric power sector across Russia, Brazil and Kazakhstan, and demonstrates an evolving toolkit that blends commodity and bespoke tooling to support both financially motivated operations…
-
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls.Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse functions under one First seen on thehackernews.com Jump to article: thehackernews.com/2026/07/new-avalon-malware-framework-packs.html
-
ARToken PhaaS exposes EvilTokens’ Microsoft 365 phishing toolkit
A new phishing-as-a-service (PhaaS) platform dubbed “ARToken” appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/artoken-phaas-exposes-eviltokens-microsoft-365-phishing-toolkit/
-
Government and Healthcare Are the Weakest Links in Global Email Security
Government and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks. Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard email authentication protocols: SPF, DMARC, DKIM, and MTA-STS. The results…
-
Why a Windows Hello PIN Beats a Password for Enterprise Security
As phishing campaigns, AI-driven identity attacks, and Windows migration planning raise authentication stakes, IT teams should recheck how Windows Hello PIN security works. The post Why a Windows Hello PIN Beats a Password for Enterprise Security appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-windows-hello-pin-security/
-
Phishing Campaign Uses Fake Invoice PDF to Drop AsyncRAT, VenomRAT, and XWorm
A sophisticated phishing campaign that uses a fake invoice PDF to mask the delivery of multiple remote access trojans primarily AsyncRAT, but also VenomRAT and XWorm via layered shortcuts. TryCloudflare quick tunnels, and disguised Python packages. The campaign echoes an August attack previously analysed by X”‘Labs and reinforces the group’s 2025 Future Insights prediction that…
-
Cybercriminals Pose as Interpol in Phishing Emails to Infect Victims With Ransomware
Bitdefender researchers warned of curious ransomware campaign which has targeted businesses around the world First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cybercriminals-pose-interpol/
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
Ransomware im Anmarsch: Hacker greifen mit fieser Interpol-Masche an
Angreifer geben sich in Phishing-Mails als Personal von Interpol aus und locken mit angeblichen Beweismitteln. Doch stattdessen gibt es Ransomware. First seen on golem.de Jump to article: www.golem.de/news/ransomware-im-anmarsch-hacker-greifen-mit-fieser-interpol-masche-an-2607-210436.html
-
Hackers Use Geofenced Webpages to Deliver Ousaban Banking Trojan in Spain and Portugal
A targeted phishing campaign delivering the Ousaban banking Trojan to users in Spain and Portugal, notable for its use of geofenced webpages, layered evasion techniques, and a modular delivery chain. The threat actor repurposes a playbook seen previously in Brazil but has refined access controls and server-side checks to ensure malware reaches only the intended…
-
Phishing Tactics Target Session Tokens and Deliver Malware
Barracuda found phishing attacks increasingly abuse Microsoft authentication, session tokens, and fileless malware. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/phishing-tactics-target-session-tokens-and-deliver-malware/
-
Crafty Phishing Campaigns Auto-Adapt to Victim’s Device, OS
Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/phishing-campaigns-auto-adapt-victims-device-os
-
Cisco Talos Exposes ARToken Microsoft 365 Phishing Kit
Cisco Talos uncovered ARToken, a Microsoft 365 phishing platform built for persistent access and BEC attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cisco-talos-exposes-artoken-microsoft-365-phishing-kit/
-
Microsoft Uncovers Widespread Hotel Phishing Campaign in Japan
Microsoft and Trend Micro found hotel phishing attacks using fake guest complaints and photo links to target staff in Japan. The post Microsoft Uncovers Widespread Hotel Phishing Campaign in Japan appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-hotel-phishing-apac-japan/
-
Webinar: Why traditional email security is no longer enough
Modern phishing, business email compromise, and account takeover attacks increasingly exploit trusted identities and legitimate business workflows, making them harder for traditional email defenses to detect. This webinar explores how behavioral AI can help organizations automate detection and response. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-why-traditional-email-security-is-no-longer-enough/
-
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
A Brazilian banking trojan called Ousaban is going after Windows users who bank in Spain and Portugal. Fortinet’s FortiGuard Labs identified the campaign in May 2026.It opens with a phishing PDF disguised as a corrupted file, checks that the visitor is really in Spain or Portugal, and hides its real payload inside an image.The goal…
-
Turning Indicators into Intelligence in OpenCTI with Criminal IP
Threat intelligence is only as useful as the context behind it. Criminal IP explains how its integration enriches threat indicators in OpenCTI with risk scoring, infrastructure intelligence, and phishing analysis. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/turning-indicators-into-intelligence-in-opencti-with-criminal-ip/
-
Brazilian Banking Trojan Ousaban Targets Spain and Portugal
FortiGuard says the Brazilian banking trojan Ousaban is targeting Spain and Portugal via phishing First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ousaban-banking-trojan-spain/
-
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Talos has identified “ARToken,” a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/
-
This phishing kit looks more like BEC-as-a-service
Cisco Talos’ research on ARToken builds on what’s known about the related EvilTokens phishing-as-a-service. First seen on cyberscoop.com Jump to article: cyberscoop.com/artoken-bec-platform-cisco-talos/
-
The ARToken phishing panel targets Microsoft 365 accounts
Accounts-payable staff at U.S. companies keep receiving invoice emails that look like they come from vendors they already work with. One landed at a life-sciences company in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/01/artoken-phishing-panel-microsoft-365-accounts/
-
RedLine Infostealer Thread Reveals Hidden Maritime Phishing and BEC Infrastructure
A routine threat-feed alert for a RedLine Stealer command-and-control (C2) IP morphed into a full-scale pivot investigation that exposed a tailored maritime spear”‘phishing and business email compromise (BEC) ecosystem. The starting signal a UniqueSignal entry from VMRay identified 194[.]156.79.122:55615 as a RedLine-associated host. That solitary indicator, combined with targeted forensic pivots across VirusTotal, FOFA, Censys…

