< ciso
brief />
Tag Banner

All news with #phishing tag

747 articles · page 16 of 38

Europol-Led Operation Disrupts Tycoon 2FA Phishing Service

🛡️ A Europol-led coalition of law enforcement and private cybersecurity firms dismantled Tycoon 2FA, a subscription-based phishing-as-a-service toolkit that enabled adversary-in-the-middle credential and session harvesting at scale. The platform provided a web console for crafting campaigns, harvesting passwords, MFA codes and session cookies, and forwarding stolen data to Telegram for near-real-time monitoring. Authorities seized 330 domains and disrupted infrastructure that generated tens of millions of phishing emails per month, affecting organizations worldwide.
read more →

Microsoft-led Takedown Disrupts Tycoon2FA Phishing Network

🔒 Microsoft led a court-authorized disruption of Tycoon2FA, a prominent phishing-as-a-service operation, seizing 330 active domains and coordinating infrastructure seizures with Europol and partner law enforcement. Private-sector partners including Cloudflare, Coinbase, Intel471, Proofpoint, the Shadowserver Foundation, SpyCloud and Trend Micro assisted in removing control panels and fraudulent login pages. Microsoft estimates Tycoon2FA accounted for roughly 62% of phishing attempts it blocked by mid-2025 and linked to about 96,000 victims since 2023.
read more →

Phishing campaign uses fake LastPass support email threads

🔒 LastPass warns of a targeted phishing campaign that spoofs support email threads to trick users into revealing vault credentials. The messages impersonate a LastPass representative by abusing the display name and use subject lines that mimic forwarded internal conversations about changing an account's primary email. Recipients are urged to click links such as “report suspicious activity” that lead to a fake login page on the domain "verify-lastpass[.]com". LastPass says its systems were not compromised and reminds users never to disclose their master password and to report suspicious messages to abuse@lastpass.com.
read more →

Europol Disrupts Tycoon2FA Phishing-as-a-Service campaigns

🔒 Europol coordinated an international law enforcement operation that disrupted Tycoon2FA, a prolific phishing-as-a-service platform that intercepted credentials and session cookies via reverse proxies to bypass MFA and hijack authenticated sessions. Authorities seized 330 domains and removed control panels and phishing pages across multiple countries, with technical disruption led by Microsoft and support from private partners including Trend Micro and Cloudflare. The action aims to curb tens of millions of monthly phishing messages and protect nearly 100,000 targeted organizations while urging defenders to revoke active sessions and monitor for unauthorized access.
read more →

Inside Tycoon2FA: Scale and AiTM Phishing Operations

🔎 Tycoon2FA emerged in August 2023 as a phishing-as-a-service platform that provided adversary-in-the-middle (AiTM) capabilities to relay authentication flows and capture session cookies. Its web-based admin panel centralized templates, redirects, hosting, CAPTCHA, and exfiltration controls while exposing real-time metrics. Fast-moving short-lived domains, Cloudflare hosting, and heavy obfuscation let low-skill operators run scalable campaigns against MFA-protected accounts worldwide.
read more →

Global Takedown Disrupts Tycoon2FA Phishing Service

🛡️ Microsoft and Europol, supported by industry partners, seized infrastructure linked to the phishing-as-a-service operator Tycoon2FA, removing over 300 domains used in large-scale MFA-bypass campaigns. The PhaaS offering used adversary-in-the-middle techniques to intercept live authentication sessions and capture credentials, one‑time passcodes and session cookies in real time. Investigators say Tycoon2FA had roughly 2,000 users and leveraged more than 24,000 domains since launching in August 2023. Security firms recommend adopting phishing‑resistant authentication, strict conditional access and advanced email protections.
read more →

Browser-in-the-Browser Phishing Now Used Against Facebook

🔒 Browser-in-the-browser (BitB) phishing renders convincing fake login pop-ups inside malicious pages, and Kaspersky reports attackers are now using this technique in real campaigns to steal Facebook credentials. Threat actors create counterfeit authentication dialogs and even fake address bars so visual inspection is unreliable. Use a password manager — it checks the actual origin before auto-filling — and enable 2FA, adopt passkeys, and use unique passwords to reduce risk.
read more →

APT41-Linked Silver Dragon Targets Europe and Asia

🔒 Check Point disclosed an advanced persistent threat dubbed Silver Dragon, active since mid-2024 and assessed to operate under the APT41 umbrella. The group gains access via vulnerable public servers and phishing, deploying loaders such as MonikerLoader and the C++ BamboLoader to stage Cobalt Strike beacons. Post-exploitation tools include screen capture, SSH utilities, and a Google Drive backdoor used for file-based C2.
read more →

Hackers Abuse OAuth Error Redirects to Deliver Malware

🔐 Microsoft warns that attackers are abusing legitimate OAuth error redirection to bypass email and browser phishing protections and deliver malware. Campaigns target government and public-sector organizations with lures such as e-signature requests, meeting invites, and financial notices that contain OAuth redirect URLs. Attackers register malicious OAuth apps and invoke silent-auth parameters or invalid scopes to trigger error redirects to attacker-controlled pages. Those pages can host credential-phishing frameworks or automatically deliver ZIP packages that launch PowerShell loaders and DLL side‑loading routines, enabling final payload execution.
read more →

AI and Deepfakes Accelerate Cybercriminal Capabilities

⚠️ A new Cloudflare Threat Report warns that widespread access to large language models and AI tools has lowered the barrier to entry for cybercriminals, enabling rapid, scalable attacks. Attackers are using LLMs to craft convincing phishing, generate malware, and map networks in real time, increasing impact and reach. The report highlights AI-generated deepfakes and fraudulent IDs used to bypass hiring filters and embed malicious insiders, with state actors like North Korea exploiting this vector. Cloudflare urges organisations to adopt real-time intelligence and proactive defenses to counter the industrialisation of cyber threats.
read more →

Compromised cPanel Access Fuels Cybercrime Markets

🔐 Flare researchers found widespread trading of compromised cPanel credentials across fraudulent groups, observing over 200,000 posts in a seven-day sample that reveal a highly commoditized, templated marketplace. Sellers advertise tiered pricing and bulk discounts (e.g., bundles of 100–1,000 accounts), and buyers use panels to host phishing kits, create SMTP accounts, deploy backdoors, and exfiltrate data. Because access uses valid credentials, abuse often bypasses traditional defenses; organizations should enable MFA, enforce strong unique passwords, restrict admin IPs, and monitor file integrity and outbound SMTP.
read more →

OAuth redirect abuse lets phishers hide malicious pages

🔗 Microsoft warns attackers are abusing a legitimate OAuth redirect behavior to send victims from trusted identity-provider endpoints—like Microsoft Entra ID and Google Workspace—to attacker-controlled landing pages. Phishing lures such as e-signature requests, HR notices, Teams invites and password resets embed links that point to real authorization endpoints but use broken parameters (for example, prompt=none plus invalid scopes) so the provider silently redirects to a malicious URI. Microsoft has disabled multiple malicious OAuth apps, published client IDs and initial redirect IOCs, and supplied KQL hunting queries for Defender XDR customers. Analysts say the old advice to “hover and check the link” is no longer sufficient and urge validating context and tightening OAuth governance.
read more →

Starkiller phishing suite proxies real sites to bypass MFA

🔒 Cybersecurity researchers disclosed Starkiller, a commercial phishing suite marketed by a group calling itself Jinkusu that proxies legitimate login pages to bypass multi-factor authentication. The platform launches a headless Chrome instance inside a Docker container and acts as an AitM reverse proxy, relaying keystrokes, form submissions and session tokens. Abnormal warns the toolkit centralizes deployment, URL masking and session monitoring to give low-skill criminals effective MFA-bypass capabilities at scale.
read more →

Microsoft Warns OAuth Redirect Abuse Targets Government Orgs

🔒 Microsoft warned on Mar 3, 2026 of phishing campaigns that leverage OAuth redirect URLs to bypass email and browser defenses and deliver malware to government and public-sector targets without directly stealing tokens. Attackers register malicious applications and manipulate identity providers like Entra ID and Google Workspace to craft redirect links sent in emails or embedded in PDFs. The delivery chain uses ZIP -> LNK-triggered PowerShell -> MSI -> DLL sideloading to execute in-memory payloads and contact external C2; some campaigns also used AitM kits such as EvilProxy. Microsoft removed identified malicious apps and recommends limiting consent, auditing app permissions, and removing unused or overprivileged applications.
read more →

LLMs Close the Invisible Phishing Detection Gap at Scale

🔍 Cloudflare integrated Large Language Models (LLMs) into its email security pipeline to surface previously invisible phishing behaviors and move from reactive to proactive defense. LLMs tag messages with granular categories such as Sales Outreach and PrizeNotification, providing high-fidelity, near-real-time signals for analysts. From those tags Cloudflare curated targeted corpora, extracted sentiment and intent features, and trained specialized classifiers that emit risk scores. Those scores are combined with reputation and link signals to enforce blocking or quarantine, reducing user-reported misses and accelerating updates.
read more →

Fake Google Security PWA Steals OTPs, Wallets, Proxies

🔒 A phishing campaign impersonating Google directs victims to a malicious PWA on google-prism[.]com that harvests contacts, clipboard contents, GPS data, and one-time passcodes. The PWA leverages a service worker, Periodic Background Sync, and the WebOTP API while checking an /api/heartbeat endpoint for commands. It can act as an HTTP proxy via a WebSocket relay and uses push notifications to prompt users to reopen the app so it can access data. An optional Android APK escalates access with dozens of permissions and persistence mechanisms.
read more →

OAuth Redirect Abuse Enables Phishing and Malware Delivery

🔒Microsoft Defender researchers observed phishing campaigns that abused OAuth redirection mechanics to route victims from trusted identity domains to attacker-controlled hosts. Attackers used silent authorization requests (for example prompt=none and intentionally invalid scopes) and embedded target addresses in the state parameter to trigger error redirects that landed users on malicious pages or download hosts without yielding tokens. Microsoft flagged correlated activity across email, identity, and endpoints; Microsoft Entra disabled the identified applications, though related activity persists and requires continued monitoring.
read more →

UK NCSC Issues Warning on Iranian Cyberattack Risks

⚠️The UK National Cyber Security Centre (NCSC) has issued an advisory warning British organisations of an elevated risk of Iranian cyberattacks amid the ongoing Middle East conflict. While the NCSC says there is not yet a significant change in the direct threat to the UK, state‑sponsored and Iran‑linked actors likely retain some capability despite Iran’s domestic Internet blackout. Organisations with operations or supply chains in the region are urged to follow guidance on DDoS, phishing, and ICS targeting, review external attack surfaces, and increase monitoring.
read more →

Meta Sues Advertisers Over Celeb-Bait and Cloaking Scams

🛡️ Meta said it is suing deceptive advertisers in Brazil, China, and Vietnam, suspending their payment methods, disabling related accounts, and blocking domains used in scams. The company also issued cease-and-desist letters to eight marketing consultants accused of offering ways to evade ad-policy enforcement, including fake 'un-ban' services and renting access to trusted accounts. Meta highlighted targeted celeb‑bait schemes and cloaking tactics, and said its protections now cover more than 500,000 celebrity and public-figure images.
read more →

Dohdoor DoH Backdoor Targeting Education and Healthcare

🚨 Cisco Talos reports an ongoing campaign by UAT-10027 using a new backdoor called Dohdoor since December 2025. Dohdoor leverages DNS-over-HTTPS (DoH) for stealthy command-and-control, downloads and executes payloads within legitimate Windows processes, and employs phishing, PowerShell abuse, and DLL sideloading. The campaign targets U.S. education and health care organizations with C2 infrastructure hidden behind reputable services.
read more →