Tag: phishing
-
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Large language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone else can, then hosting phishing pages on them to catch traffic that AI tools point their way.Palo Alto Networks’ Unit 42 calls the trick phantom squatting, and its new research shows it is already happening…
-
Attackers Register AI-Hallucinated Domains to Deliver Phishing Kits and Malware
An emergent supply-chain attack vector they term >>phantom squatting,<< in which large language models (LLMs) routinely hallucinate plausible but nonexistent domains for legitimate brands and adversaries then preemptively register those domains to host phishing kits, malware, and other malicious infrastructure. By systematically probing two distinct LLM families across temperature settings, Unit 42 generated a 2.1…
-
Photo-themed phishing campaign targets European and Asian hotels with Node.js implant
Tags: phishingFirst seen on scworld.com Jump to article: www.scworld.com/brief/photo-themed-phishing-campaign-targets-european-and-asian-hotels-with-node-js-implant
-
New EvilTokens Attack Exposes Browser Visibility Gap in Enterprise SOCs
EvilTokens phishing hides takeover clues until browser execution leaving SOC teams needing deeper visibility to validate threats faster and reduce account risk. First seen on hackread.com Jump to article: hackread.com/eviltokens-attack-browser-visibility-gap-enterprise-socs/
-
Singpass to roll out passkeys in fight against phishing scams
The passwordless feature will launch for iPhone users on 1 July 2026 with a device-bound model to avoid the security risks of cloud-synced passkeys First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645129/Singpass-to-roll-out-passkeys-in-fight-against-phishing-scams
-
DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains
Officials from the US Department of Justice seized nearly 400 domains linked to illegal World Cup streams and warned viewers about the risks of malware, phishing, and data theft. The post DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-doj-illegal-world-cup-streaming-domains/
-
Hackers Leverage Blockchain to Hit Japan’s Hotels Through Booking.com Phishing
A wave of phishing emails sent to Booking.com partner accommodations in Japan in May led to blockchain-hosted malware First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hackers-blockchain-japan-hotels/
-
Phishing reicht aus: Wie Angreifer in wenigen Minuten dauerhaften Zugriff erhalten
Eine aktuelle Untersuchung von Barracuda Networks zeigt, wie schnell sich ein einzelner Phishing-Vorfall zu einer schwerwiegenden Sicherheitsverletzung entwickeln kann. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/phishing-angreifer-dauerhaft-zugriff
-
Japan Hotel Industry Targeted With TONResolver RAT and Guest Complaint Phishing Emails
Japan’s hotel sector is the latest target of a sophisticated phishing and remote-access trojan (RAT) campaign that leverages guest-complaint lures and an unusual resilience mechanism: a TON blockchainbased dead-drop resolver. Beginning in late May 2026, attackers sent highly targeted emails to Booking.com partner properties in Japan with subject lines such as “é‡è¦ï¼šã‚²ã‚¹ãƒˆæ»žåœ¨ãƒ¬ãƒ“ューä¾é ¼” (Important: Guest Stay…
-
Nach Signal-Attacken: USA bieten üppiges Kopfgeld für russische Hacker
Wer Infos über die Akteure hinter den ständigen Phishing-Angriffen auf Signal-Nutzer hat, bekommt dafür bei der US-Regierung eine Menge Geld. First seen on golem.de Jump to article: www.golem.de/news/nach-signal-hacks-usa-bieten-10-millionen-us-dollar-kopfgeld-fuer-russische-hacker-2606-210321.html
-
Product showcase: Scam calls, phishing, and data breaches? Meet AVG Mobile Security
AVG Mobile Security for iOS helps protect users against online threats with features including Web Guard, VPN, Scam Guardian Pro, Hack Alerts, and Photo Vault. It also … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/product-showcase-avg-mobile-security-ios/
-
DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains
The DOJ seized nearly 400 illegal World Cup streaming domains, warning that piracy sites also pose malware and phishing risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/doj-seizes-400-illegal-fifa-world-cup-streaming-domains/
-
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App.The templates power bogus cryptocurrency exchanges, multi-language pig-butchering operations, WhatsApp phishing networks, fake gambling platforms, brand-impersonation First seen on thehackernews.com Jump to article: thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
-
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025.Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Gamaredon against new targets, with most of them taking place in the second half of the…
-
Bluekit Phishing Kit Uses Browserthe-Middle Attacks to Evade Detection
A new phishing-as-a-service (PHaaS) platform called Bluekit is letting cybercriminals steal user accounts using a tricky method. While… First seen on hackread.com Jump to article: hackread.com/bluekit-phishing-uses-browser-in-the-middle-attacks/
-
FBI and CISA Warn Russian Hackers Stealing Verification Codes and Account PINs From Signal Users
U.S. cybersecurity authorities have issued a new warning about Russian intelligence-linked threat actors targeting secure messaging platforms, specifically highlighting the increased risk for Signal users. These threat actors are employing sophisticated phishing campaigns designed to steal verification codes and account PINs. In a joint Public Service Announcement (PSA) published on June 26, 2026, the Cybersecurity…
-
Brand Indicators for Message Identification auf dem Prüfstand – Lookalike-Domains machen BIMI-Logos zur potenziellen Phishing-Falle
Tags: phishingFirst seen on security-insider.de Jump to article: www.security-insider.de/bimi-lookalike-domains-phishing-email-sicherheit-a-8a01f15bcfcb423bf9ed5e26c9479336/
-
FBI Sounds Alarm Over Russian Intelligence Signal Phishing
The FBI claims Russian spies are targeting Signal backup keys First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fbi-alarm-russian-intelligence/
-
Ghostwriter Hackers Use Real-Time WebSocket Relay to Bypass SMS and OTP MFA
UNC1151 tracked by many as Ghostwriter or FrostyNeighbor has advanced a credential-phishing technique that uses a real-time WebSocket relay to defeat SMS and OTP-based multi-factor authentication (MFA). The method was observed in a recent campaign that targeted Belarusian politician Yury Hubarevich and multiple Ukrainian portals, and Censys pivots show the infrastructure spans dozens of domains…
-
DCloud Uni-App Framework Powers 236,000+ Scam Domains Across Global Fraud Economy
DCloud Uni-App has become a mass-production layer for fraud, with more than 236,000 distinct scam domains tied to a sprawling ecosystem of fake exchanges, wallet drainers, phishing portals, and investment schemes. The scale matters because it shows scam operations are no longer bespoke; they are templated, repeatable, and easy to clone across languages, regions, and…
-
Rokarolla Uses Fake Google Play Protect App to Target Banking and Cryptocurrency Users
Rokarolla, a sophisticated Android banking trojan distributed via malicious websites that masquerade as trusted applications such as TikTok, Google Chrome and even Google Play Protect. Unlike simple credential stealers, Rokarolla is a multi-functional fraud platform that targets at least 217 banking and cryptocurrency apps and combines Accessibility Service abuse, phishing overlays, SMS interception, keylogging, screenshot…
-
New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages
FBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover. The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification…
-
New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages
FBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover. The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification…
-
Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails
Microsoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence. Microsoft Threat Intelligence published a detailed analysis on an ongoing hacking campaign against hospitality organizations that has been running since April 2026. The targets are specific: device names observed across compromised environments include strings like…
-
FBI: Russian hackers now target Signal backup recovery keys
The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims’ historical messages. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fbi-russian-hackers-now-target-signal-backup-recovery-keys/
-
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added a step: they now coax targets into handing over their Signal Backup Recovery Key.Hand it over once, and the attacker can restore the account’s backup, read the private and group message history, and take over…
-
Five Eyes Warns AI Could Speed Cyberattacks Within Months
Five Eyes agencies warned that AI could speed cyberattacks within months, raising new risks around prompt injection, phishing, and enterprise AI tools. The post Five Eyes Warns AI Could Speed Cyberattacks Within Months appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-five-eyes-ai-cyberattacks/
-
Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says.The company has not attributed the activity to a known threat actor, and the operators’ end goal is still unclear.The lure…

