< ciso
brief />
Tag Banner

All news with #phishing tag

747 articles · page 11 of 38

Phishing Paradox: Trusted Brands as Attack Vectors

📧 In Q1 2026, Check Point Research found Microsoft was the most impersonated brand in phishing campaigns, accounting for 22% of brand impersonation attempts. Apple (11%), Google (9%), Amazon (7%) and LinkedIn (6%) followed, reflecting attackers’ focus on both enterprise and consumer ecosystems tied to identity, devices and payments. The report underscores a persistent trend: threat actors exploit trusted brands to harvest credentials and gain initial access to personal and corporate environments.
read more →

PowMix PowerShell Botnet Targets Czech Workforce Campaign

🔍 Cisco Talos identified an active PowerShell-based botnet dubbed PowMix, operating since at least December 2025 and targeting organizations and job applicants in the Czech Republic. The campaign deploys phishing ZIP archives containing LNK shortcuts that launch an obfuscated PowerShell loader which bypasses AMSI and executes a decrypted payload in memory. Talos observed tactical overlap with ZipLine and published IOCs and detection guidance.
read more →

UAC-0247 Campaign Targets Ukrainian Clinics, Hospitals

🛡️CERT-UA has disclosed a campaign, dubbed UAC-0247, that between March and April 2026 targeted government and municipal healthcare organizations — primarily clinics and emergency hospitals — to deliver credential-stealing malware. Attacks begin with spear-phishing links leading to compromised or AI-generated sites that drop a Windows Shortcut (LNK) executing an HTA via mshta.exe, which loads multi-stage loaders and payloads such as RAVENSHELL, AGINGFLY, and the PowerShell-based SILENTLOOP. The intrusions enable reconnaissance, lateral movement, and theft of data from Chromium-based browsers and WhatsApp; CERT-UA advises restricting execution of LNK/HTA/JS, limiting use of abused utilities, and blocking suspicious connections.
read more →

n8n Abuse: Threat Actors Weaponize AI Workflow Platforms

⚠️ Cisco Talos details how attackers are misusing the AI workflow automation platform n8n to run sophisticated phishing and malware campaigns. Between October 2025 and March 2026, researchers observed a sharp increase in emails containing n8n webhook URLs that serve dynamic HTML payloads and CAPTCHA-protected bait to initiate downloads. These flows mask malicious payloads behind trusted domains and have been used to deploy modified RMM tools and to fingerprint recipients. Talos urges behavioral detection, IOC sharing, and AI-enhanced email defenses to mitigate this abuse.
read more →

Microsoft Adds Protections for Malicious RDP Files Now

🔒 Microsoft has added new protections in the April 2026 cumulative updates to help block malicious Remote Desktop (.rdp) files commonly used in phishing campaigns. After the update users see a one-time educational prompt and, on subsequent opens, a security dialog that lists local resource redirections with every option disabled by default. Unsigned files receive a 'Caution: Unknown remote connection' warning and unknown publisher label. Administrators can temporarily disable the dialog via a registry policy but Microsoft advises keeping the protections enabled.
read more →

FBI and Indonesia Dismantle W3LL Phishing Platform

🔒 The FBI Atlanta Field Office and Indonesian authorities dismantled the W3LL phishing platform and seized infrastructure, leading to the arrest of the alleged developer. The W3LL kit, sold for $500, enabled adversary-in-the-middle attacks to capture credentials, session cookies and one-time MFA tokens, allowing attackers to bypass multifactor protections. Its marketplace, W3LLSTORE, facilitated the sale of over 25,000 compromised accounts and contributed to attempts exceeding $20 million in fraud.
read more →

FBI, Indonesian Police Dismantle W3LL Phishing Network

🛡️The FBI, with the Indonesian National Police, dismantled the infrastructure of the W3LL phishing network, detained the alleged developer identified as G.L., and seized key domains used to harvest credentials. The off‑the‑shelf W3LL toolkit—marketed for about $500—enabled adversary‑in‑the‑middle attacks that bypassed MFA and targeted primarily Microsoft 365 accounts. Authorities say the operation attempted more than $20 million in fraud and was linked to tens of thousands of compromised accounts.
read more →

FBI and partners dismantle $20M W3LL phishing network

🛡️ The FBI Atlanta field office, together with US and Indonesian authorities, dismantled a large-scale phishing operation built around the W3LL phishing kit. The kit, sold via a members-only marketplace called W3LL Store, enabled attackers to clone login pages and harvest credentials for as little as $500. Investigators seized the w3ll.store domain, identified an alleged developer known as 'G.L.', and say the toolkit may have been used against over 17,000 victims worldwide between 2023 and 2025.
read more →

Operation Atlantic freezes $12M, disrupts crypto scams

🔒 Operation Atlantic, led by the UK's National Crime Agency with US and Canadian partners, froze $12m and disrupted multiple fraud networks after a week-long probe. The operation focused on approval phishing, a technique that tricks victims into granting full access to cryptocurrency wallets via fake alerts or popups. Investigators, supported by private-sector firms including Binance, Coinbase, Tether, and analytics vendors, identified over 20,000 compromised wallets across 30+ countries and contacted 3,000 victims. Authorities also disrupted more than 120 scam domains and flagged an additional $33m believed stolen in related crypto fraud.
read more →

International Crackdown Identifies 20,000 Crypto Victims

🔒 An international law enforcement action led by the U.K.'s National Crime Agency, dubbed Operation Atlantic, identified over 20,000 victims of cryptocurrency fraud across Canada, the UK, and the US. The weeklong operation brought together the NCA, U.S. Secret Service, Ontario authorities and private-sector partners to share real-time intelligence and conduct coordinated victim outreach. Investigators froze more than $12 million in suspected criminal proceeds tied to approval phishing and traced over $45 million in stolen cryptocurrency, and they will continue analyzing intelligence to pursue further criminal activity.
read more →

Recovery Scams Target Fraud Victims for Second Strike

⚠️Recovery fraud preys on people already defrauded, with criminals posing as recovery firms, regulators or law enforcement to charge upfront fees or collect bank and crypto details. Scammers often use 'sucker lists' to identify vulnerable victims and pressure them into untraceable payments or rushed decisions. Never pay fees in advance; verify claims independently and report incidents to the appropriate authorities.
read more →

VENOM PhaaS Phishing Targets C-Suite Microsoft Logins

🔒 Abnormal researchers disclosed a targeted phishing-as-a-service called VENOM that has been active since at least last November and focuses on stealing C-suite Microsoft credentials. The campaign uses personalized SharePoint-style emails, injected fake threads, and Unicode QR codes to move victims to mobile-based landing pages while evading scanners. VENOM hides target addresses using double Base64 in URL fragments and filters out researchers before presenting an AiTM proxy or device-code flow that captures passwords, MFA codes, and session tokens. Researchers recommend FIDO2, disabling unused device-code flows, and tighter conditional access to mitigate token abuse.
read more →

The Threat Hunter’s Gambit: Skills, Signals, and Risks

🔍 William Largent frames threat hunting as a discipline akin to strategy games, where pattern recognition, prediction, and spotting feints reveal an adversary's intent. Cisco Talos warns of a growing Platform-as-a-Proxy (PaaP) tactic in which attackers weaponize legitimate SaaS notification pipelines such as GitHub and Jira to deliver authenticated phishing that circumvents SPF, DKIM, and DMARC. Because users habitually trust system-generated alerts, defenders should adopt zero‑trust controls, ingest SaaS API logs into SIEMs, and require out‑of‑band verification for high-risk actions.
read more →

Investigating Storm-2755: Payroll pirate attacks in Canada

🔒 Microsoft Incident Response researchers detail a Storm-2755 campaign that used malvertising and SEO poisoning to phish Canadian users and capture OAuth tokens and credentials via adversary-in-the-middle (AiTM) proxying. The actor replayed tokens (notably using the Axios/1.7.9 user-agent) to hijack authenticated sessions and bypass non-phishing-resistant MFA. Compromised accounts were used to search for payroll and HR data, create hidden inbox rules, and in some cases directly modify Workday payment information, resulting in at least one confirmed payroll diversion. Microsoft urges immediate token revocation, removal of malicious inbox rules, and adoption of phishing-resistant MFA and device-based conditional access.
read more →

Fake BTS ARIRANG Tour Ticket Websites Target Fans Worldwide

🎟️ Scammers are exploiting BTS's ARIRANG world tour pre-sales by cloning official ticket pages for multiple countries, creating at least 10 fraudulent domains observed in early April. These lookalike sites replicate the purchase flow and pressure fans into instant payments — in Brazil many victims are urged to pay via PIX, sending funds to mule accounts that are difficult to recover. To avoid fraud, fans should use only the official tour page, verify domains, confirm country-specific sales formats, and contact banks immediately if scammed. Enable banking alerts and use security software that blocks phishing sites.
read more →

Google Warns of Extortion Group Targeting BPOs and Helpdesks

🔒 Google Threat Intelligence Group warns that UNC6783, a financially motivated cluster possibly tied to the 'Raccoon' persona, is targeting business process outsourcers (BPOs) and large enterprises via live chat social engineering. The campaign directs employees to spoofed Okta login pages hosted on Zendesk-like domains such as [.]zendesk-support[.]com and uses a phishing kit that steals clipboard contents to bypass MFA and enroll attacker devices for persistence. GTIG also observed fake security updates delivering remote access malware and the use of Proton Mail to deliver ransom notes. Organizations should deploy phishing-resistant MFA like FIDO2 keys, monitor live chat, block unauthorized domains and audit new MFA enrollments.
read more →

Google: UNC6783 targets BPOs to steal Zendesk tickets

🔐 Google warns that UNC6783 is compromising business process outsourcing (BPO) providers to steal corporate support tickets and other sensitive data for extortion. Attackers use social engineering, live-chat phishing, and spoofed Zendesk-style domains plus fake Okta login pages; observed phishing kits can exfiltrate clipboard contents to bypass MFA and register devices. The group also distributes fake security updates to deliver remote access malware and then contacts victims via ProtonMail; Google recommends deploying FIDO2 keys, monitoring live chat, blocking spoofed domains, and auditing MFA enrollments.
read more →

Telehealth Risks in 2026: Medical Data and AI Scams

🔒 Telehealth offers fast, convenient access to care but creates persistent medical records that are highly valuable to criminals. Stolen health data — from diagnoses and prescriptions to insurance IDs and test results — often fetches far more than payment or social-login credentials and enables extortion, fraud, and identity theft. The rise of AI-driven fake clinics and diagnostic tools makes realistic phishing and data-harvesting sites easier to create. Protect yourself by using a dedicated medical email, avoiding social sign-in, enabling 2FA, using clinic-provided encrypted portals, and keeping health devices patched.
read more →

Weaponizing SaaS Notification Pipelines for Phishing

🔔 Cisco Talos observed a rise in campaigns that weaponize SaaS notification pipelines in collaboration platforms to deliver phishing and credential‑harvesting lures. Attackers embed malicious content in GitHub commit messages and in user‑configurable Jira project fields so automated notifications, signed by the platforms, bypass SPF, DKIM, and DMARC checks. Talos describes this as a Platform‑as‑a‑Proxy (PaaP) abuse and recommends moving to Zero‑Trust, instance‑level verification, and API telemetry to detect and block these attacks.
read more →

AI-Enabled Device Code Phishing Campaign Analysis Report

🔒 Microsoft Defender Security Research describes an AI-enabled campaign that abused the OAuth Device Code flow to compromise organizational accounts at scale. Actors used generative AI to craft hyper-personalized lures and automated backend infrastructure (including Railway.com and other PaaS) to generate dynamic device codes at click time, defeating the standard 15-minute expiry. The activity is linked to the PhaaS toolkit EvilToken and shows a marked escalation in automation and scale versus earlier device code phishing campaigns. Post-compromise actions focused on device registration, Microsoft Graph reconnaissance, malicious inbox rules, and email exfiltration.
read more →