< ciso
brief />
Tag Banner

All news with #business email compromise tag

130 articles

Agent Tesla v4 uses emoji obfuscation to evade detection

πŸ›‘οΈ KnowBe4 has identified a new Agent Tesla v4 campaign using emoji-based obfuscation and a JScript dropper to bypass detection and steal credentials. The lure leveraged a convincing BEC email spoofing a Philippine bank and instructing finance staff to open an attachment. The dropper embeds Unicode emoji characters to disrupt signature matching, then uses DonutLoader for reflective PE injection so the final binary never touches disk. Researchers advise updating email security and creating YARA rules that combine emoji patterns with JScript function calls to detect the threat.
read more β†’

Ransomware Forces Shift Toward Enterprise Resilience

πŸ”’ Ransomware has evolved from simple encryption schemes into multifaceted campaigns that combine data theft, extortion, and operational disruption. Attackers increasingly leverage AI and target third parties, expanding the attack surface and complicating detection. CISOs must now prioritize business continuity, vendor risk, and AI governance alongside traditional security controls to maintain trust and operational resilience.
read more β†’

Communication Channels and Identity Risks in SaaS Era

πŸ›‘οΈ Enterprise collaboration platforms are now central to business workflows and have become part of the identity attack surface. Threat actors increasingly misuse trusted collaboration tools for identity phishing, impersonation, credential theft and malware delivery, often leveraging compromised accounts, external federation or guest access. Unit 42 observations show a significant rise in malicious activity tied to collaboration tools, and defenders may lack visibility into actions that occur after authentication. The report reviews techniques attackers use and offers detection and mitigation guidance, noting enhanced protection through Palo Alto Networks products.
read more β†’

Using Crime Script Analysis to Explain Cyber Attacks

πŸ” Crime script analysis (CSA) breaks cyber attacks into sequences of actions, decisions, and situational requirements, making complex campaigns accessible to non-technical audiences. CSA complements models like MITRE ATT&CK and the Lockheed Martin Cyber Kill Chain by offering a narrative view that highlights practical "choke points" for disruption. The post illustrates CSA with a business email compromise (BEC) example and explains how AI can both enable attackers and provide new detection opportunities. Practical mitigations include honeypot canary organizations, provider-side detection of malicious LLM use, email rate-limiting, and stricter payment verification processes.
read more β†’

OpenAI Disrupts Cambodia-Based Scam Network

πŸ›‘οΈ OpenAI says it dismantled a Poipet-based scam operation that used ChatGPT to run investment, romance, gambling, and law-enforcement impersonation schemes. The company banned a coordinated cluster of accounts tied to Poipet that created fake personas, generated promotional content, translated messages, and handled administrative tasks. OpenAI investigated in partnership with WhatsApp and highlighted the hybrid, opportunistic nature of modern scam networks.
read more β†’

Phishing service spoofs RingCentral to steal Microsoft 365

πŸ“§ The Greatness phishing-as-a-service platform has expanded to adversary-in-the-middle and device-code phishing targeting Microsoft 365 users across several countries. Operators abused RingCentral to bypass filters by leveraging whitelisting and fraudulent verification banners to lower suspicion. Victims were routed to AiTM or device-code flows that captured MFA-approved tokens, enabling long-lived access to mailboxes, Teams, SharePoint, OneDrive, and more.
read more β†’

Interpol: AI now drives majority of African cybercrime

πŸ” Interpol reports that AI-driven cybercrime accounted for 55% of all reported digital crime in Africa in its African Cyberthreat Assessment Report 2026. The report, compiled from data provided by 36 member countries, links AI-powered scams, social engineering and credential harvesting to a rise in losses from $192m in 2024 to $484m in 2025. It highlights threats such as AI-enabled deepfake sextortion, sophisticated BEC campaigns, AI-driven ransomware, and the growth of Cybercrime-as-a-Service platforms.
read more β†’

LogoKit uses live site screenshots for phishing

πŸ›‘οΈ Barracuda researchers observed LogoKit phishing campaigns that build a unique login page for each victim in real time by pulling a live screenshot of the target organization’s website as the page background. The kit extracts the victim email from the URL, identifies the employer domain, and uses commercial services like Thum.io and Clearbit to assemble a convincing, per-victim page. Credential harvesting is routed via a Telegram bot, and victims are redirected to the genuine site, complicating detection and takedown.
read more β†’

Spanish police dismantle €140M cyber fraud ring

πŸ” Spanish police dismantled an industrial-scale cybercrime and money-laundering operation that stole €140 million via investment fraud and business email compromise. Four suspects were arrested across Spain, Portugal, and Panama after raids on multiple premises and an international operation with Interpol and Europol. Authorities seized digital devices, froze €3 million in proceeds, and identified hundreds of mule accounts used to launder funds.
read more β†’

Forg365 PhaaS Targets Microsoft 365 Accounts

πŸ›‘οΈ A new phishing-as-a-service operation named Forg365 targets Microsoft 365 by combining device-code phishing, AitM tactics, antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram and offered as a subscription, the kit uses legitimate delivery infrastructure like Amazon SES and SendGrid to blend into normal email flows before redirecting victims to attacker-controlled domains. The platform includes a clearnet operator panel, OAuth and token handling, and a Chromium extension called ForgCookie that automates cookie refresh and sustained access to compromised accounts.
read more β†’

Kaspersky introduces AI BEC detection for email

πŸ›‘οΈ Kaspersky explains a new capability to detect AI-generated business email compromise (BEC) messages by identifying both BEC-specific phrases and linguistic patterns typical of machine-generated text. The company notes that cybercriminals increasingly use large language models to craft persuasive phishing and BEC campaigns, and this detection works across eight languages. The feature is integrated into Kaspersky Secure Mail Gateway and available with the KSMS Plus license after the KSMG 3.1 update.
read more β†’

How Check Point stopped a student job phishing scam

πŸ“§ Check Point Research observed a large phishing campaign that used legitimate school accounts and Google Forms to recruit students into a likely money-mule scheme. The emails passed SPF/DKIM/DMARC and contained no malware or fake login pages, making them appear benign. Check Point Email Security evaluates context, sender behavior, message intent, and hosted-form usage to detect such threats before they reach users.
read more β†’

Helix vishing group targets SharePoint data theft

πŸ”’ A new extortion group dubbed Helix uses vishing, device-code phishing, and MFA abuse to access and exfiltrate files from SharePoint environments. Operators impersonate managers via phone calls and spoofed caller IDs to trick employees into granting access, then register authenticators for persistence and bulk-download content. ReliaQuest links Helix tactics and infrastructure to prior groups like ShinyHunters and BlackFile, and recommends disabling device-code authentication and restricting SharePoint to managed devices.
read more β†’

Global Operation First Light 2026 Targets Cybercrime

πŸ›‘οΈ A global anti-fraud operation, Operation First Light 2026, ran from January 15 to April 30, 2026, coordinated by Interpol with support from regional partners and funding from China’s Ministry of Public Security. The crackdown targeted social engineering scams such as romance fraud and BEC, leading to over 5,800 arrests, identification of 15,606 suspects and interception of $293m in illicit assets. Actions included raids, freezing 31,014 bank accounts, seizing devices and using Interpol’s I-GRIP stop-payment mechanism.
read more β†’

INTERPOL-led Operation First Light nets global arrests

πŸ•΅οΈ Law enforcement agencies coordinated Operation First Light 2026 across 97 countries, arresting 5,811 suspects and seizing $293 million in illicit assets. The operation targeted social engineering fraud β€” including BEC, sextortion, impersonation, romance, and investment scams β€” and associated money laundering between January 15 and April 30. Authorities identified over 142,000 victims, blocked 31,014 bank accounts, and analyzed 152,808 cases while additional suspects were identified. INTERPOL coordinated the effort with regional policing bodies and funding support from China's Ministry of Public Security.
read more β†’

Vishing campaign abuses Entra passkey enrollment

πŸ”” A threat actor is using voice-based fake security calls to trick Microsoft 365 users into enrolling a malicious Entra passkey. The attacker directs victims to realistic phishing pages that mimic the Microsoft enrollment flow and uses an operator-controlled PHP kit to capture credentials and MFA responses in real time. Okta attributes the campaign to O-UNC-066, linked to the extortion group Pink, which targets multiple industries and quickly exfiltrates data after account takeover.
read more β†’

Phishing job interview scam targets Google accounts

πŸ“§ A phishing campaign impersonates over 30 major brands to lure marketing professionals with fake job interview invites and steal Google credentials. The attackers abuse legitimate platforms like PeopleForce and an ExactTarget/Salesforce Marketing Cloud-linked domain, chaining redirects through services such as Wise Agent to reach malicious landing pages. The campaign uses real recruiter names and browser-in-the-browser popups to harvest sign-in data.
read more β†’

ARToken PhaaS reveals EvilTokens Microsoft 365 toolkit

πŸ›‘οΈ Cisco Talos uncovered a React-based ARToken management panel exposing 80+ API endpoints and client-side code that reveals expanded phishing capabilities. The platform, tied to the EvilTokens ecosystem, automates Microsoft 365 account compromise by stealing authentication tokens, obtaining persistent Primary Refresh Tokens (PRTs), and accessing Outlook, SharePoint, and OneDrive. ARToken deploys Cloudflare Workers, supports multi-tenant affiliate operations, and includes tools for BEC automation and mailbox monitoring.
read more β†’

Lessons from underground: combating BEC threats

πŸ“£ Flare researchers examined underground forum discussions and tools used to orchestrate Business Email Compromise (BEC) campaigns, finding that attacks extend beyond email to include remote access, cash-out networks, and call centers. Actors target finance and leadership SaaS accounts, increasingly using AI to craft realistic messages and scale operations. Defenders should monitor exposed credentials, enforce MFA, train high-risk staff, and treat multi-channel contacts cautiously.
read more β†’

Fraudulent OpenAI organization invites target security firms

πŸ”” Push Security discovered a campaign where attackers create fraudulent OpenAI tenants impersonating real companies and send legitimate-looking invites to employees. The invites originate from OpenAI notification addresses, pass authentication checks, and assign recipients Owner privileges within the fake organization. Attackers used Gmail accounts to pose as company executives and even attached a billing card to the tenant, likely to reduce suspicion. Push Security warns employees could be tricked into submitting sensitive data into the workspace and advises verification and monitoring of SaaS memberships.
read more β†’