< ciso
brief />
Tag Banner

All news with #phishing tag

810 articles · page 20 of 41

UK NCSC Issues Warning on Iranian Cyberattack Risks

⚠️The UK National Cyber Security Centre (NCSC) has issued an advisory warning British organisations of an elevated risk of Iranian cyberattacks amid the ongoing Middle East conflict. While the NCSC says there is not yet a significant change in the direct threat to the UK, state‑sponsored and Iran‑linked actors likely retain some capability despite Iran’s domestic Internet blackout. Organisations with operations or supply chains in the region are urged to follow guidance on DDoS, phishing, and ICS targeting, review external attack surfaces, and increase monitoring.
read more →

Meta Sues Advertisers Over Celeb-Bait and Cloaking Scams

🛡️ Meta said it is suing deceptive advertisers in Brazil, China, and Vietnam, suspending their payment methods, disabling related accounts, and blocking domains used in scams. The company also issued cease-and-desist letters to eight marketing consultants accused of offering ways to evade ad-policy enforcement, including fake 'un-ban' services and renting access to trusted accounts. Meta highlighted targeted celeb‑bait schemes and cloaking tactics, and said its protections now cover more than 500,000 celebrity and public-figure images.
read more →

Dohdoor DoH Backdoor Targeting Education and Healthcare

🚨 Cisco Talos reports an ongoing campaign by UAT-10027 using a new backdoor called Dohdoor since December 2025. Dohdoor leverages DNS-over-HTTPS (DoH) for stealthy command-and-control, downloads and executes payloads within legitimate Windows processes, and employs phishing, PowerShell abuse, and DLL sideloading. The campaign targets U.S. education and health care organizations with C2 infrastructure hidden behind reputable services.
read more →

Darktrace: 32M High-Confidence Phishing Emails in 2025

📧 Darktrace detected more than 32 million high-confidence phishing emails in 2025, signaling a major escalation in identity-driven attacks and automated campaigns. Over 8.2 million of those targeted VIPs, while 1.6 million originated from newly created domains and 1.2 million included malicious QR codes. The vendor reported 70% of phishing passed DMARC, 41% were spear-phishing and 38% used novel social-engineering techniques, highlighting attackers’ growing sophistication and emphasis on credential compromise.
read more →

Talos: Dohdoor DoH Backdoor Targets US Education, Healthcare

🛡️ Cisco Talos reports an active campaign, observed since December 2025, in which actor UAT-10027 deployed a previously undocumented backdoor called Dohdoor that uses DNS-over-HTTPS (DoH) for covert C2. The multi-stage chain leverages phishing-delivered PowerShell to fetch a batch dropper that sideloads a disguised DLL into legitimate Windows binaries and tunnels C2 through Cloudflare’s edge. Dohdoor decrypts and reflectively executes payloads in memory, unhooks ntdll to evade EDR, and was observed targeting U.S. education and healthcare organizations.
read more →

Android expands AI-powered scam protections to devices

🔒 Android is expanding its AI-driven Scam Detection protections for calls and messages, bringing on-device Gemini models to more Pixel and Samsung Galaxy devices. A real-world example describes a Pixel user who avoided a convincing bank scam after receiving a timely Scam Detection warning during the call. Google Messages protections now cover 20+ countries and multiple languages and have improved detection for sophisticated threats like job-offer and romance “pig butchering” scams. Processing occurs on-device, data aren’t stored or shared, and the feature is off by default and excluded for contacts.
read more →

Variations of ClickFix technique and evolving delivery

🔒 The Kaspersky Team outlines evolving variations of the ClickFix social‑engineering technique, where attackers trick users into executing malicious commands on their own machines. Recent campaigns abuse legitimate utilities such as mshta.exe, nslookup and the legacy Finger protocol, and have used platforms like TikTok, Pastebin and fake extension pages to prompt victims to run code. Observed payloads include infostealers and remote access trojans such as ModeloRAT. Organizations are advised to prioritize user awareness and robust endpoint and XDR controls to mitigate these risks.
read more →

Fake Zoom Meeting Installs Covert Employee Surveillance

🔒 Malwarebytes researchers warn of a convincing fake Zoom meeting page that silently downloads and installs a covert build of Teramind on Windows endpoints. Victims see scripted participants and an “Update Available” countdown that triggers a silent download while a fake Microsoft Store screen displays a staged installation. Because the payload is a repackaged commercial monitoring tool, many defenses may not flag it, so prompt verification and training are essential.
read more →

Phishing Campaign Steals Credentials from Freight Firms

📧 A financially motivated threat group dubbed Diesel Vortex has run an extensive phishing campaign since September 2025 targeting freight and logistics operators across the U.S. and Europe, using roughly 52 domains to harvest credentials. Researchers at Have I Been Squatted and partner Ctrl-Alt-Intel discovered exposed repositories and Telegram webhook logs revealing the group's tooling, communications, and an internal mind map describing a call-center style operation. The campaign stole 1,649 unique credential pairs and employed sophisticated evasion — Cyrillic homoglyphs, a nine-stage cloaking chain, voice phishing, Telegram infiltration, and pixel-perfect clones — before coordinated takedowns disrupted the infrastructure.
read more →

1Campaign Cloaking Service Enables Malicious Google Ads

🛡️ 1Campaign is a cloaking service that helps threat actors run malicious Google Ads by passing automated screening and serving benign pages to security researchers while exposing real users to phishing and crypto-drainer content. According to Varonis, the platform offers a dashboard for targeting by geography, ISP, and device, and assigns fraud risk scores to filter out cloud-based and researcher traffic. It also includes a Google Ads launcher that aids operators in bypassing policy checks and impersonating brands, allowing malicious ads to remain online until manually reported.
read more →

Recognizing Red Flags of Business Email Compromise

🔎 Business Email Compromise (BEC) exploits social engineering and subtle technical deception to manipulate employees and bypass controls. Attackers use domain tweaks, display-name spoofing, urgent off-hours requests, and impersonation to pressure finance, HR, or operations into transfers or data disclosure. Inspect headers and SPF/DKIM/DMARC, enforce MFA, run phishing simulations, and maintain a strict verification culture.
read more →

Bitpanda Phishing Campaign Uses Fake MFA to Harvest Data

🔒 A sophisticated phishing campaign impersonating cryptocurrency broker Bitpanda has been uncovered by Cofense, employing a near-perfect fake login to steal credentials. Victims are guided through a staged MFA flow that requests names, phone numbers, addresses and dates of birth, enabling account takeover and identity abuse. The fraudulent landing page uses deceptive domains and urgent messaging before redirecting users to the real login page. Users should verify sender addresses, hover over links and access platforms via bookmarks rather than email links.
read more →

AI-enabled Cyber Attacks Nearly Double in 2025 - CrowdStrike

⚠️ CrowdStrike's Global Threat Report 2026 warns that AI-enabled cyber-attacks rose 89% in 2025 as adversaries used machine learning and LLMs to scale and refine phishing, disinformation and malware operations. Researchers observed LLMs producing multilingual, convincing phishing lures and automating campaign creation, while some actors embedded prompting into malware (eg, LameHug) for reconnaissance. CrowdStrike recommends strong identity controls, AI-focused awareness training and threat-intel monitoring to mitigate the accelerating threat.
read more →

How Attackers Use Generative AI to Exploit Systems

🔐 Cybercriminals increasingly employ generative AI to automate and scale established attack techniques, from highly convincing phishing and deepfakes to AI-assisted malware creation and accelerated vulnerability exploitation. Adversaries are building custom LLMs, hijacking cloud LLM resources, and orchestrating multi-agent campaigns that speed reconnaissance and weaponization. Organizations should adopt layered defenses, monitor API and AI usage, tighten identity and access, and leverage AI-based detection to mitigate these evolving threats.
read more →

Typosquatting Tactics: How Actors Evade Detection Today

🔍Typosquatting remains a highly effective deception tactic where attackers register look-alike domains to phish, harvest credentials, and deliver malware. CrowdStrike describes how adversaries exploit weak registrar verification and craft convincing WHOIS records while using techniques such as strategic HTTP redirects, geo-targeted content and fake sale pages to evade detection. Organizations should monitor registrations, protect brands, and use Falcon Adversary Intelligence to detect and disrupt campaigns.
read more →

Starkiller phishing service proxies real login flows

🔐 Starkiller is a phishing-as-a-service that dynamically loads live login pages and proxies user interactions through attacker-controlled infrastructure. It generates deceptive URLs that visually mimic legitimate domains (for example using an @-based URL trick), spins up containerized headless browsers, and records every keystroke, session token, and MFA code. The platform streams sessions in real time, harvests cookies and MFA codes, and delivers campaign analytics and Telegram alerts to customers.
read more →

TrustConnect: Fake RMM Service Used by Cybercriminals

⚠️ Proofpoint uncovered TrustConnect, a malware-as-a-service that masquerades as a legitimate remote monitoring and management (RMM) product and is advertised at about $300 per month. The operation uses a polished public website and a backend portal that functions as a web-based command-and-control dashboard for paying customers. Attackers primarily rely on social engineering — phishing lures and signed installers impersonating Zoom, Teams, Adobe Reader and others — to trick victims into running the RAT, which auto-registers infected hosts in the portal. Researchers disrupted parts of the infrastructure but observed resilient activity and a related variant called DocConnect.
read more →

ClickFix Campaign Uses Compromised Sites to Deploy MIMICRAT

🔒 Elastic Security Labs disclosed a ClickFix campaign that leverages compromised legitimate websites to deliver a new remote access trojan named MIMICRAT. Attackers inject JavaScript to load an externally hosted PHP lure that shows a fake Cloudflare verification page and tricks victims into running a PowerShell command. A multi-stage PowerShell chain performs ETW and AMSI bypasses, then drops a Lua-based in-memory loader which decrypts shellcode to install the RAT. MIMICRAT communicates over HTTPS on port 443 using profiles that mimic web analytics and supports localized lures in 17 languages to widen impact.
read more →

Device-Code Phishing Uses OAuth to Bypass Microsoft 365

🔐 Researchers at KnowBe4 discovered a campaign aimed at North American businesses that tricks employees into entering a “Secure Authorization” code on a legitimate Microsoft 365 login page. Unknown to victims, the code actually authorizes an attacker-controlled device through the OAuth 2.0 Device Authorization Grant, issuing access and refresh tokens that grant persistent access to Outlook, Teams, OneDrive and other services. Recommended mitigations include allowlisting OAuth apps, disabling device-code flow in Entra conditional access where feasible, auditing integrations, and ongoing employee awareness training.
read more →

Industrial-Scale Fake Coretax Apps Drive $2M Fraud

🔍 Group-IB uncovered a sophisticated campaign that impersonated Indonesia’s official Coretax service to distribute malicious Android APKs, causing an estimated $1.5m–$2m in losses nationwide. Attackers combined phishing sites, WhatsApp impersonation and vishing to coerce victims into installing RATs such as Gigabud.RAT and MMRat, enabling remote access and unauthorized banking transfers. The operation produced 996 phishing URLs, 228 new malware samples and used infrastructure that impersonated over 16 trusted brands, suggesting a scalable MaaS model.
read more →