Tag: social-engineering
-
Russia used social engineering to breach prominent messaging accounts, Ukraine says
Ukraine’s SBU described a long-running Russian operation that used fake tech-support workers to persuade people to hand over credentials to their messaging apps. First seen on therecord.media Jump to article: therecord.media/russia-ukraine-social-engineering-messaging-accounts
-
Scammers Abuse Shopify to Send Fake Invoices and Steal Credentials via Fake Support Calls
Scammers are increasingly exploiting Shopify’s ecosystem and its Shop order-tracking app to deliver fraudulent invoices directly into users’ purchase histories, marking a shift from traditional email-based phishing to in-app social engineering attacks. Security researchers Luis Corrons and Jakub Vavra from Gen have identified multiple campaigns in which fake receipts appear in the Shop app, impersonating…
-
Künstliche Intelligenz im Cybercrime Zwischen Faszination und Existenzangst
Sophos veröffentlicht neue Erkenntnisse der Sophos Counter Threat Unit (CTU). Die Experten analysierten in einer aktuellen Untersuchung, dass Cyberkriminelle der künstlichen Intelligenz (KI) nach wie vor ambivalent gegenüberstehen. In Untergrund-Foren und Darknet-Marktplätzen wird KI nicht nur zunehmend als potenzieller Game-Changer thematisiert, sondern auch als potenzieller Killer für kriminelle Geschäftsmodelle. Betrug auf Autopilot: Wie KI Social-Engineering…
-
2026 FIFA World Cup Faces Surge in Cyber Threats
Persistent cybercrime, social engineering, and infrastructure threats continue to plague the FIFA 2026 World Cup across the US, Canada, and Mexico. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/2026-fifa-world-cup-faces-surge-cyber-threats
-
Securing the service desk: Why social engineering attacks keep succeeding
Service desks have become a favored target for attackers seeking password resets, MFA changes, and access to corporate accounts. Specops Software breaks down how service desk social engineering attacks work and how organizations can defend against them. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/securing-the-service-desk-why-social-engineering-attacks-keep-succeeding/
-
Hackers Abuse Indian Tax Notice Lures to Deliver PE Loader and libsvcs.dll Payload
A targeted malware distribution campaign that abuses a counterfeit Indian Income Tax Department assessment notice to deliver a multi-stage Remote Access Trojan (RAT)-style payload. The threat actors hosted a fake tax-assessment portal on harivo[.]vip and used social-engineering lures official branding, tax terminology, legal references, penalties, and a “Download Assessment Order & Workings” prompt to persuade…
-
Hackers Abuse UI Spoofing and Hidden iFrames to Push Malicious Installer Downloads
A sophisticated Browser-in-the-Browser (BitB) campaign that combines UI spoofing, concealed iframes and multiple anti-analysis checks to coerce victims into manually installing malware. The operation uses highly convincing fake browser windows layered over legitimate pages to simulate stalled document loads and “out of date” software dialogs, social-engineering users into downloading an executable and running it themselves.…
-
Angreifer nutzen geopolitische Unruhen für Phishing, Spendenbetrug und Social Engineering
Der wirksamste Schutz liegt deshalb im eingeübten Reflex, jede unerwartete Nachricht kritisch zu prüfen. Unternehmen sollten diesen Reflex durch regelmäßige Awareness-Trainings stärken. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/angreifer-nutzen-geopolitische-unruhen-fuer-phishing-spendenbetrug-und-social-engineering/a45551/
-
Top 10 Best Cybersecurity Awareness Training Platforms 2026
Tags: awareness, cyber, cybercrime, cybersecurity, defense, phishing, social-engineering, tactics, technology, trainingIn the complex digital landscape of 2026, technology alone is no longer enough to protect an organization from cyber threats. The human element, often cited as the weakest link, is now recognized as a critical line of defense the human firewall. Cybercriminals are increasingly targeting employees through sophisticated social engineering tactics like phishing, vishing, and…
-
Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT
A sophisticated malvertising and social-engineering campaign that pivoted from weaponized GitLab Pages to abusing claude.ai’s shared chat feature, enabling operators to deliver an in-memory remote-access trojan (RAT) via a China-themed loader chain. Across seven weeks (April 8June 14, 2026) investigators tracked 106 unique malicious hostnames across six attack waves, revealing rapid infrastructure rotation, targeted geographic…
-
ClickFix Attack Deploys Potemkin Loader, RMMProject RAT, and EtherRAT Across 11 Hosts
A sophisticated ClickFix social engineering campaign in May 2026 triggered a full hands-on-keyboard intrusion spanning 11 hosts, deploying a novel trio of malicious tools: Potemkin loader, RMMProject RAT, and EtherRAT. The attack chain began when the user visited a compromised website and pasted a base64-encoded PowerShell command into Win+R. This command abused pcalua.exe as a LOLBIN to…
-
ClickFix-Kampagnen verbreiten neue Malware-Loader
Angreifer nutzen ClickFix-Social-Engineering und gefälschte Updates, um neue Malware-Loader wie BabaDeda, Lorem Ipsum und Potemkin auf Systeme zu bringen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/clickfix-kampagnen-malware-loader
-
Rokarolla Malware Abuses Android Accessibility Services to Steal Banking Credentials
Tags: android, banking, control, credentials, crypto, cyber, infrastructure, malicious, malware, service, social-engineeringRokarolla, a new Android banking trojan named after its Command-and-Control (C2) infrastructure, that combines sophisticated social engineering, broad permissions abuse, and a flexible command set to harvest credentials from 217 targeted banking and cryptocurrency apps. Distributed via malicious websites that masquerade as popular apps (examples include a disguised landing page at hxxps://infocontablidades[.]it[.]com/). Rokarolla uses a…
-
Malware Uses Deno Permission Flags to Run Commands and Proxy Internal Network Traffic
A recent intrusion demonstrates how threat actors are shifting toward scripting runtimes to evade traditional detection: attackers delivered a modular Remote Access Trojan (RAT) built on Deno, using social engineering to install a multi-process JavaScript implant that executes commands and proxies internal network traffic. The campaign combined high-volume mailbombing with Microsoft Teams impersonation to trick…
-
CEO-Fraud 2.0: KI als Booster für Social Engineering und Deepfake-Angriffe
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/ceo-fraud-2-0-ki-booster-social-engineering-deepfake-angriffe
-
Silent Ransom Group Targets US Legal Firms With Voice Phishing and Data Theft Extortion
A concentrated data theft extortion campaign by UNC3753 also reported as Luna Moth, Chatty Spider, and Silent Ransom Group targeting dozens of U.S. professional, legal, and financial services firms. The cluster’s hallmark is fast, human-centric intrusions that combine voice phishing (vishing), social engineering, abuse of legitimate remote support tools, and in some cases physical office…
-
Silent Ransom Group Targets US Legal Firms With Voice Phishing and Data Theft Extortion
A concentrated data theft extortion campaign by UNC3753 also reported as Luna Moth, Chatty Spider, and Silent Ransom Group targeting dozens of U.S. professional, legal, and financial services firms. The cluster’s hallmark is fast, human-centric intrusions that combine voice phishing (vishing), social engineering, abuse of legitimate remote support tools, and in some cases physical office…
-
The Beginning of the End of Social Engineering
AI-native operating systems are shifting the responsibility to stay vigilant against social engineering cyberattacks from the user onto the system itself. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/beginning-end-social-engineering
-
APT37 Hackers Use NarwhalRAT Malware With MS-Themed Phishing and Dead-Drop C2
Tags: backdoor, cyber, data, hacker, malicious, malware, microsoft, phishing, powershell, social-engineering, spear-phishing, theftAPT37 is using NarwhalRAT in a tightly engineered intrusion chain that starts with Microsoft-themed spear-phishing, pivots through malicious LNK files and PowerShell, and ends with a Python-based backdoor with dead-drop C2 via pCloud. The campaign is notable for its layered tradecraft: social engineering, LOLBin abuse, scheduled-task persistence, in-memory execution, and selective data theft are all…
-
Chinesische PhaaS-Plattformen professionalisieren Phishing-Angriffe mit KI und Echtzeit-Tools
Die Analyse zeigt deutlich: Technische Schutzmaßnahmen allein reichen nicht aus. Unternehmen müssen ihre Mitarbeitenden kontinuierlich über Phishing und Social Engineering aufklären. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/chinesische-phaas-plattformen-professionalisieren-phishing-angriffe-mit-ki-und-echtzeit-tools/a45489/
-
Hackers Abuse NinjaOne RMM Agent to Gain Remote Access to Brazilian Organizations
Tags: access, business, cyber, exploit, finance, hacker, malware, monitoring, phishing, social-engineeringAn active phishing campaign that weaponizes a legitimate NinjaOne Remote Monitoring and Management (RMM) agent to gain persistent remote access to Brazilian organizations. Rather than relying on bespoke malware, the operators exploit familiar business workflows and Portuguese-language social engineering to trick finance, procurement, accounting and administrative staff into installing a digitally signed NinjaOne agent that…
-
Weaponized DMG Files Deliver macOS Infostealer Malware
A recent surge in macOS-targeted campaigns shows threat actors favoring weaponized disk images (.dmg) as the primary delivery mechanism for infostealer malware. Attackers are leveraging convincing, branded DMG installers and social-engineering tricks to bypass Gatekeeper and trick users into executing payloads that rapidly harvest credentials, cookies, authentication tokens, and cryptocurrency wallets before disappearing without persistence.…
-
Hackers Exploit ChatGPT, Claude, DeepSeek Brands in Credential Phishing Attacks
Threat actors are increasingly weaponizing the global fascination with large language models and generative AI by impersonating major AI brands ChatGPT, Anthropic’s Claude, DeepSeek, and others to trick users into revealing credentials, payment information, and to install malware. These campaigns are not breaches of the vendor platforms; they are classic social engineering and distribution techniques…
-
WhatsApp says it disrupted new NSO spyware phishing attacks
WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/whatsapp-says-it-disrupted-new-nso-spyware-phishing-attacks/
-
Pink Hacking Group Targets Enterprises to Steal Cloud Passwords
A newly observed extortion brand called Pink (CL-CRI-1147) that is actively targeting enterprise users to harvest cloud storage credentials and bypass multi-factor authentication. The group’s leak site went live on May 31, 2026, and its operations combine social engineering with classic credential-phishing to quickly convert compromised accounts into extortion leverage. Pink’s attack chain begins with…
-
Silent Ransom Group targets law firms with fake IT support calls
Tags: attack, cybersecurity, data, extortion, group, law, ransom, service, social-engineering, theftThe Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/silent-ransom-group-targets-law-firms-with-fake-it-support-calls/
-
JINX-0164 Targets Crypto Firms With macOS Malware
A series of targeted intrusions against cryptocurrency organizations, attributing the activity to a newly identified threat actor tracked as JINX-0164. The campaign combines advanced social engineering, custom macOS malware, and deep access into development and CI/CD environments, enabling attackers to pivot from individual developer endpoints to critical software distribution systems. The group primarily targets developers…
-
Cyber Insurance Rates Are Dropping, but Exclusions Widen
Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cyber-insurance-rates-drop-exclusions-widen
-
Malicious Notifications Could Trick Google Gemini Users
A prompt injection flaw in Google Gemini’s voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/malicious-notifications-could-trick-google-gemini-users
-
Silent Ransom Group Targets Law Firms With IT Impersonation Attacks
Silent Ransom Group is using IT impersonation and trusted tools to target law firms in evolving social engineering attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/silent-ransom-group-targets-law-firms-with-it-impersonation-attacks/

