Tag: phishing
-
Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit
A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermining detection approaches built around file hashes, fixed HTML identifiers, and static JavaScript signatures. The campaign came to light after a phishing message submitted to the SANS Internet Storm Center (ISC) pointed recipients to a URL…
-
RMM Phishing Campaign Spans 46 Countries as Attackers Abuse Trusted IT Tools
A global RMM phishing campaign is abusing trusted remote access tools across 46 countries, with US activity accounting for about 45%. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/phishing/news-rmm-phishing-remote-access/
-
Cloud-Sicherheit – Phishing-Abwehr in der Cloud: Warum der Kontext entscheidend ist
First seen on security-insider.de Jump to article: www.security-insider.de/phishing-cloud-saas-workflows-kontext-erkennen-a-be45d8f27dab475efdf114c02b3bcc44/
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
KlarnaFalle: Betrüger ködern Amazon-Kunden mit 129,45 Euro
Tags: phishingKlarna-Phishing-Falle mit 129,45 Euro: Betrüger ködern Amazon-Kunden mit einer Fake-Rückerstattung und wollen an sensible Daten gelangen. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/online-betrug/klarna-phishing-falle-amazon-129-45-euro-333028.html
-
StrongestLayer: Move Past The ‘Noisy’ Attack Zone, Just 3.6% of Phishing Is Behind (Nearly) All Risk
StrongestLayer research points to what the company calls a “stark disconnect” between the attacks companies see most often, when compared to those that pose the greatest financial risk. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/strongestlayer-phishing-genome-report-risk-analysis/
-
Russian Hackers Phish EU Officials Over Messaging Apps
EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/russian-hackers-phish-eu-officials-messaging-apps
-
JavaScript obfuscation: From party trick to phishing kit
Tags: phishingLearn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/
-
Kalender-Phishing: Wie Angreifer .ics-Dateien für Credential Harvesting missbrauchen
Kriminelle nutzen vertrauenswürdige Kalendereinladungen und .ics-Dateien, um E-Mail-Filter zu umgehen und Zugangsdaten zu stehlen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/kalender-phishing-2
-
Phishing mit Cloud-Diensten – Kaspersky warnt vor Cloud-Phishing
First seen on security-insider.de Jump to article: www.security-insider.de/phishing-angriffe-ueber-cloud-dienste-microsoft-365-a-ef827c205788e6aae74642c0671e53e4/
-
Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Tags: access, authentication, credentials, cyber, espionage, exploit, flaw, infrastructure, phishing, russia, softwareRussian-linked cyber espionage operators are expanding account-compromise operations by combining OAuth abuse, device-code phishing, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups. GTIG assesses with moderate confidence that UNC6293 is an initial-access subcluster of ICE RELIC, formerly tracked as APT29, Cozy Bear, and Midnight Blizzard. Rather than exploiting a software flaw, the operators abuse legitimate authentication…
-
AnonyMousKIT PhaaS Automates Apple ID, Device Passcode, and Live 2FA Harvesting Across Five Channels
AnonyMousKIT, an AI-enabled Phishing-as-a-Service (PhaaS) platform built to turn stolen Apple devices into monetizable assets. The service automates the collection of an owner’s device passcode, Apple ID credentials and live two-factor authentication (2FA) codes information that can enable criminals to remove Activation Lock and resell a stolen device. Rather than relying on a single phishing…
-
AnonyMousKIT phishing service targets Apple credentials and Activation Lock
First seen on scworld.com Jump to article: www.scworld.com/brief/anonymouskit-phishing-service-targets-apple-credentials-and-activation-lock
-
AnonyMousKIT phishing service targets Apple credentials and Activation Lock
First seen on scworld.com Jump to article: www.scworld.com/brief/anonymouskit-phishing-service-targets-apple-credentials-and-activation-lock
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
Phishing ohne Link und Malware: Wenn ein Telefonanruf zum eigentlichen Angriff wird
Eine Debt-Relief-Phishing-Kampagne trifft mehr als 9.000 Organisationen. Angreifer nutzen Telefonnummern statt Links und verlagern den Angriff ins Gespräch. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/phishing-ohne-link-und-malware-wenn-ein-telefonanruf-zum-eigentlichen-angriff-wird/a46266/
-
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/anonymouskit-phishing-stolen-iphone/
-
‘NovaCookies’ Kit Steals Microsoft 365 Sessions for $320 a Month
The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/novacookies-steals-microsoft-365-sessions-320-a-month
-
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process.In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that First seen on…
-
Debt-Relief-Phishing-Kampagne gegen mehr als 9.000 Organisationen
Check Point Software Technologies hat eine groß angelegte E-Mail-Phishing-Kampagne identifiziert und blockiert. In dieser werden betrügerische Angebote zur finanziellen Entlastung und Schuldenerleichterung genutzt, um Empfänger zu Anrufen bei vom Angreifer kontrollierten Telefonnummern zu verleiten. In den vergangenen 14 Tagen beobachtete Check Point rund 24.700 E-Mails im Zusammenhang mit der Kampagne, die sich an Nutzer in…
-
Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.
Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning developer infrastructure into a phishing delivery layer. OX Security said it identified 24 malicious npm packages containing identical HTML code designed to render a fake CAPTCHA page and redirect visitors to attacker-controlled infrastructure. The campaign does…
-
AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
Mexico’s financial sector is facing an industrialized phishing Balonx Sistema, a Mexico-focused Phishing-as-a-Service (PhaaS) platform that has harvested credentials and financial data from more than 1,100 banking users since at least October 2025. The service targets over 20 Mexican financial institutions and combines live phishing, Android malware, and AI-driven voice fraud in one subscription-based operation.…
-
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures…
-
KI-Phishing nach iPhone-Diebstahl durch FakeSupport
Nach einem iPhone-Diebstahl rufen KI-Agenten wie ‘Alice vom Apple Support” Opfer an, um Entsperrcodes für den Wiederverkauf zu erbeuten. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-phishing-iphone
-
CISA Red Team Achieves Full Domain Compromise Across Critical Infrastructure Networks
CISA’s latest red team assessment shows how common failures in Active Directory, cloud identity, and SOC processes can turn a phishing foothold into an enterprise-wide compromise. The August 25 advisory contrasts two critical-infrastructure organizations: one missed the intrusion entirely, while the other contained initial access quickly but still exposed major identity and cloud security weaknesses.…
-
WhatsApp Passkeys Now Protect Over 1 Billion Users Against Account Takeover Attacks
WhatsApp has announced that over one billion people now use passkeys to secure their accounts, enhancing phishing-resistant authentication across one of the world’s largest messaging platforms. This update, revealed on August 25, introduces support for multiple passkeys, stronger two-step verification credentials, and additional context for calls from unknown numbers. These changes target common account takeover…
-
MyChart Portal Phishing Scams Target Patients Nationwide
Dozens of Health Systems Warn of Emails, Texts and Calls Using Epic’s MyChart Brand. Dozens of U.S. healthcare systems are warning patients about potential email phishing, text and phone scams involving their MyChart patient portals. MyChart vendor Epic also issued a public warning about the scams, which offer patients a senior package, Medicare wellness benefits…
-
Hackers abuse npm mirrors to host phishing redirect pages
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/

