< ciso
brief />
Tag Banner

All news with #phishing tag

746 articles · page 19 of 38

ZeroDayRAT Mobile Spyware Targets Android and iOS Users

📱 ZeroDayRAT is a newly documented cross-platform mobile spyware operation targeting Android and iOS, according to iVerify. The toolkit grants persistent access to messages, precise GPS history, notifications, camera, microphone and keystroke capture, and exposes a dedicated web dashboard for rapid device profiling. Infections are commonly initiated via smishing, counterfeit app stores, phishing emails and links shared through messaging apps.
read more →

Weaponized Windows Shortcuts Deliver Global Group Ransomware

📄 Forcepoint X‑Labs researchers have uncovered a Phorpiex‑backed phishing campaign that weaponizes Windows shortcut (.lnk) files to deploy Global Group ransomware. Attackers send messages with the subject "Your Document" and attachments like "Document.doc.lnk", exploiting hidden file extensions and a Word‑style icon to trick recipients. The .lnk uses built‑in utilities (cms.exe and PowerShell) and heavily obfuscated commands to fetch and run a second‑stage payload, leveraging Living‑off‑the‑Land techniques so the ransomware executes locally without external C2 communication.
read more →

Taxing times: Top IRS scams to watch for in 2026 season

🔍Tax season 2026 brings a renewed surge in IRS-related scams as fraudsters exploit email, text and phone channels to steal refunds and personal data. Scammers impersonate the IRS, tax preparers or software vendors with spoofed logos, domains and caller IDs, and may demand unusual payments or coax victims into filing fraudulent returns. Watch for phishing/smishing/vishing, W-2 fraud, fake tax credits and dishonest preparers. Protect accounts with MFA, consider an IP PIN, file early and report suspicious messages to phishing@irs.gov.
read more →

UNC1069 Targets Cryptocurrency with AI-Enabled Lures

🔒 Mandiant links a targeted intrusion to UNC1069 that leveraged AI-enabled social engineering to compromise a cryptocurrency executive and deploy multiple macOS malware families. The attacker used a hijacked Telegram account, a spoofed Zoom meeting allegedly featuring a deepfake video, and a ClickFix paste-and-execute ruse to trick the victim into running troubleshooting commands. The operation dropped WAVESHAPER, HYPERCALL, HIDDENCALL, SUGARLOADER, DEEPBREATH, CHROMEPUSH, and SILENCELIFT to harvest credentials, browser data, and session tokens. GTIG and Mandiant highlight UNC1069's expanding use of GenAI for lures and tooling.
read more →

Exchange Online flags legitimate emails as phishing

📧 Microsoft is investigating an ongoing Exchange Online issue that is mistakenly marking legitimate email messages as phishing and quarantining them. The problem began on February 5 and continues to disrupt customers' ability to send and receive mail. Microsoft traced the fault to a newly introduced URL rule that incorrectly classifies certain links as malicious. The company is releasing quarantined messages and working to unblock legitimate URLs while it completes remediation.
read more →

Authorities Warn of Signal Hijacks Targeting German Officials

🔐 German security agencies warn of an active campaign targeting high‑ranking politicians, soldiers, diplomats and journalists by seizing their Signal accounts. Attackers impersonate support teams to request secret PINs or trick users into approving device pairing via QR codes, then move the account to a number they control. No malware or software vulnerabilities are involved; the campaign relies on social engineering. Authorities note similar methods could be used against WhatsApp, and stress that official support will never request PINs via message.
read more →

Fake Dubai Crown Prince Traced to Nigerian Mansion

🔎 A detailed investigation by OCCRP traced a romance scammer who impersonated the Crown Prince of Dubai and defrauded a Romanian businesswoman of more than US $2.5 million. Over two years the con combined thousands of messages, staged in-person meetings, and an elaborate fake banking site showing a phantom £200 million balance. Photographs and bank-trace evidence led reporters and UK police to identify intermediaries and to locate the suspect at a mansion in Abuja, Nigeria. The case underscores the sophistication and international reach of modern romance and investment scams.
read more →

German Agencies Warn of Signal Phishing Targeting Elites

🔒 Germany's Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) have issued a joint advisory about a likely state‑sponsored phishing campaign that abuses Signal's legitimate features to seize accounts. Threat actors impersonate "Signal Support" or a "Signal Security ChatBot" to solicit SMS PINs or trick victims into scanning QR codes, enabling account registration on attacker‑controlled devices or silent device linking. Authorities recommend enabling Registration Lock, avoiding sharing verification codes, and routinely reviewing linked devices; the same methods can be applied to WhatsApp.
read more →

Germany warns of Signal account hijacking targeting VIPs

⚠️ Germany's domestic intelligence agencies warn of suspected state-backed campaigns that hijack messaging accounts on Signal to target politicians, military officers, diplomats, and journalists. The attacks use social engineering rather than malware, abusing legitimate features such as QR-code pairing and SMS/PIN verification. Two variants are reported: a full account takeover and a silent device pairing that monitors chats and contacts. Authorities advise blocking/reporting support-like messages, enabling Registration Lock, and routinely checking linked devices.
read more →

Phishing campaign hides AsyncRAT in fake disk-mounted PDFs

🛡️ A recent phishing campaign delivers malicious virtual hard disks that masquerade as PDF invoices and purchase orders, enabling attackers to install AsyncRAT. The files are hosted on IPFS and mount as local drives on Windows, which can bypass some built-in protections; inside each disk is a Windows Script File disguised as the expected PDF. Malwarebytes Labs, citing Securonix, identified the Dead#Vax campaign and recommends showing file extensions and exercising caution with disk images.
read more →

Man Pleads Guilty to Hacking Nearly 600 Snapchat Accounts

🔒 Kyle Svara, 26, pleaded guilty in federal court to phishing access codes and hacking nearly 600 Snapchat accounts to steal nude photos that he kept, sold, or traded. Between May 2020 and February 2021 he used social engineering to harvest credentials from roughly 570 victims and accessed at least 59 accounts to download private images. Svara advertised hacking services online, communicated via Kik, and accepted paid jobs including work for former Northeastern coach Steve Waithe. He now faces multiple federal charges, and is scheduled for sentencing on May 18.
read more →

ClickFix 'CrashFix' Variant Deploys ModeloRAT via Python

🛡️Microsoft Defender identified a ClickFix evolution dubbed CrashFix that intentionally crashes victims' browsers and lures users into executing malicious commands. The campaign uses a trojanized Chrome extension impersonating uBlock Origin Lite, delays malicious activity, and reports installation UUIDs to a typosquatted domain to evade attribution. Operators abuse native utilities by copying and renaming finger.exe to ct.exe to retrieve obfuscated PowerShell which drops a portable WinPython package and a Python RAT (ModeloRAT) that establishes persistence and C2 beacons.
read more →

SaaS Abuse at Scale: Phone-Based Scam Campaign Exposed

🔍 Attackers abused legitimate SaaS platforms to generate and distribute authentic-looking, phone-based scam lures by misusing native platform functionality. Rather than compromising services or spoofing domains, the campaign leveraged the trust and authentication posture of vendors to send approximately 133,260 phishing emails, impacting 20,049 organizations. This approach increased delivery success and made detection far more difficult for defenders.
read more →

Zendesk Spam Wave Returns, Flooding Users with Emails

📧 A fresh global spam wave is again exploiting unsecured Zendesk support portals to send automated 'Activate account' and other confirmation emails to large numbers of recipients. Messages appear to originate from legitimate company Zendesk instances and arrive in rapid bursts, sometimes hundreds per inbox, bypassing conventional filters. The activity mirrors a January campaign and suggests exposed ticket forms remain vulnerable.
read more →

AI Drives Rapid Doubling of Phishing Attacks in 2025

📨 Cofense reports that security filters caught a phishing email every 19 seconds in 2025 — more than double the 2024 rate of one every 42 seconds — as AI enables faster, larger-scale campaigns. The vendor's report, The New Era of Phishing: Threats Built in the Age of AI, warns that actors now use AI to generate highly personalized, polymorphic and multi-channel phishing that adapts per victim. It also highlights a 105% rise in remote access tool detections, a 19-fold spike in abuse of .es domains, and a 204% increase in email-delivered malware, urging post-delivery behavioral analysis and human validation.
read more →

OfferUp scams surge: common frauds and protection guidance

🔒 OfferUp users face a range of scams — from counterfeit goods and overpayment ruses to account takeovers, phishing links and empty-box deliveries. The platform provides 48-hour Purchase Protection for qualified on-app purchases but excludes off‑app and cash transactions. Follow advised safeguards: stay in-app, avoid third-party payments, meet at Community Meetup Spots and protect verification codes and personal data.
read more →

Why Smart People Fall for Phishing: Psychological Tactics

🧠 Unit 42 examines why phishing remains effective despite advanced defenses, highlighting the role of human psychology, cognitive bias and AI-enabled deception. The article outlines a three-stage attack model—The Bait, The Hook and The Catch—and common social engineering tactics such as urgency, authority and distraction. It urges a zero-trust mindset, continuous education and a simple habit: pause and verify before acting.
read more →

PDF Phishing Campaign Targets Corporate Dropbox Credentials

🔒Forcepoint X-Labs has warned of a multi-stage phishing campaign that uses short, business-themed emails and PDF attachments to harvest corporate Dropbox credentials. The PDFs contain embedded AcroForm links that limit scanning by security tools and redirect victims to a legitimate cloud-hosted portal serving a spoofed login page. By leveraging reputable cloud infrastructure, the attackers reduce suspicion and bypass many automated reputation checks. Submitted credentials are exfiltrated to a Telegram channel, enabling account takeover and follow-on abuse.
read more →

Multi-stage PDF phishing uses Dropbox to harvest logins

📄 Forcepoint researchers describe a multi-stage phishing campaign that uses attached PDFs to redirect victims through cloud-hosted content to a fake Dropbox sign-in page. Attackers exploit spoofed or compromised senders and trusted services to bypass filters and authentication checks like SPF, DKIM, and DMARC. If credentials are entered they’re exfiltrated to attacker-controlled infrastructure for account takeover and fraud. The campaign succeeds because each step appears legitimate in isolation, exploiting habitual trust in PDFs and mainstream cloud services.
read more →

CTM360 Warns of Global Surge in Fake HYIP Investment Scams

🔍 CTM360 reports a global uptick in fraudulent High‑Yield Investment Programs (HYIPs) that promise implausible, guaranteed returns. Their WebHunt telemetry identified 4,200+ HYIP sites and 485+ incidents in December 2025, showing persistent, scalable activity. Two dominant variants — crypto trading and forex/stock trading facades — use polished interfaces, fake performance and recycled templates. Scams spread via paid social ads, Telegram, WhatsApp and referral schemes; many sites use fake licenses and KYC delays to freeze withdrawals before vanishing.
read more →