< ciso
brief />
Tag Banner

All news with #phishing tag

745 articles · page 24 of 38

GhostPairing attack allows remote WhatsApp account linking

⚠️ Researchers at Gen Digital have identified a social-engineering technique dubbed GhostPairing that lets attackers add themselves as a trusted device to a victim’s WhatsApp account without passwords. By sending a malicious message that prompts the user to verify their phone number, attackers forward the generated pairing code and the user inadvertently approves the session. Once linked, the attacker can read and send messages in real time and propagate the scam to the victim’s contacts. Users should check Linked Devices and enable two-step verification.
read more →

OAuth Device Code Phishing Surges, Targeting Microsoft 365

🔐 Proofpoint has observed a sharp increase in phishing campaigns that abuse Microsoft's OAuth device code authorization flow to gain access to Microsoft 365 accounts. Attackers use social engineering — QR codes, embedded buttons and hyperlinks — to trick users into entering device codes on Microsoft's legitimate verification page, which yields valid access tokens. Readily available tools such as SquarePhish2 and Graphish have lowered the bar for both state-aligned and financially motivated actors.
read more →

ThreatsDay Bulletin: Emerging Tactics and Notable Incidents

🔔 This week's ThreatsDay Bulletin highlights a rapid reshaping of old tools and fresh abuse of familiar systems across fraud, malware, and infrastructure. Notable incidents include a cross-border scam ring dismantled in Ukraine that defrauded hundreds for over €10 million, the modular SantaStealer infostealer sold as malware-as-a-service, and a WhatsApp device-linking hijack dubbed GhostPairing. Security teams should verify linked sessions, reduce exposed management endpoints, and prioritize timely patching and credential hygiene.
read more →

HMRC Warns of Over 135,000 Scam Reports to Taxpayers

🛡️ HMRC has received over 135,500 scam reports since February 2025, including about 4,800 tied to its Self Assessment system, and warns scams will rise ahead of the January 31, 2026 filing deadline. Fraudsters impersonate HMRC via phone, email and text to pressure victims into paying fake bills, disclosing personal data or installing malware. HMRC says it shut 25,000 phishing sites and numbers in the last 10 months and urges people to protect, recognize and report suspicious contacts to phishing@hmrc.gov.uk.
read more →

Kimsuky Distributes DocSwap Android RAT via QR Phish

📱 ENKI links the North Korean actor Kimsuky to a campaign delivering a new Android remote-access trojan dubbed DocSwap via QR codes on phishing sites impersonating CJ Logistics. Victims are lured by smishing or phishing to scan a QR that prompts installation of a malicious "SecDelivery.apk," which decrypts and loads an embedded payload and requests broad permissions. The app mimics OTP authentication to reassure users while launching a background service that connects to attacker infrastructure and exposes capabilities including keystroke logging, audio and camera capture, and data exfiltration.
read more →

WhatsApp device-linking abused in GhostPairing campaign

🔒 Threat actors are abusing WhatsApp's legitimate device-linking feature in a campaign named GhostPairing, tricking victims into entering pairing codes on fake verification pages. Once a code is submitted, attackers gain full access to conversations and shared media and can send messages as the victim to propagate the lure. Users should check Settings → Linked Devices for unauthorized sessions, block and report suspicious messages, and enable two-factor authentication.
read more →

APT28 Targets Ukrainian UKR-net Users in Credential Theft

🔒 Recorded Future's Insikt Group observed APT28 conducting a sustained credential-phishing campaign targeting users of UKR.net between June 2024 and April 2025. The actor, tracked as APT28 or BlueDelta and assessed as affiliated with the GRU, used UKR.net-themed login pages hosted on legitimate services like Mocky and chained redirects from link shorteners and Blogger subdomains to capture passwords and 2FA codes. Phishing emails delivered PDFs that directed recipients to these pages, and the group has moved from abusing compromised routers to leveraging proxy tunneling services such as ngrok and Serveo.
read more →

ForumTroll Phishing Targets Russian Scholars via eLibrary

📚 Kaspersky reported a targeted phishing campaign linked to Operation ForumTroll observed in October 2025 that impersonated the Russian eLibrary service. Attackers used a long-aged bogus domain to send personalized emails with one-time links to ZIP archives named for each victim, which contained a .LNK that runs a PowerShell downloader. The chain fetches a staged payload that loads a final DLL, persists via COM hijacking, deploys the Tuoni C2 framework for remote access, and shows a decoy PDF to victims.
read more →

ForumTroll Targets Political Scientists with Tuoni

📧 Kaspersky researchers have uncovered a targeted campaign by the ForumTroll APT that lures political scientists with personalized plagiarism-check links impersonating the eLibrary service. The downloaded archive contained a malicious .lnk and a .Thumbs directory with images used to evade security; filenames included each victim’s full name. When executed on Windows the .lnk ran a PowerShell chain that installed the commercial red-team framework Tuoni, used COM hijacking for persistence, and displayed a decoy PDF named for the target. Kaspersky reports detections and recommends endpoint and mail-gateway protections to stop similar email-delivered threats.
read more →

Deutsche Telekom launches anti-scam call warning system

⚠️ Deutsche Telekom has introduced Call Check, an automated warning feature that flags incoming calls listed in a database as suspicious or fraudulent. When a call from a domestic or foreign number is identified, the recipient's smartphone displays a Caution, possible fraud! message to warn the user. The system is applied automatically to customers on the Telekom network and joins similar protections already deployed by competitors such as Vodafone, while O2 has yet to implement an equivalent service.
read more →

Telegram Mini App Phishing Exploits NFT Gifts Airdrops

🔒 Kaspersky describes a phishing campaign that abuses Telegram Mini Apps to harvest credentials by promising free NFT-style 'gifts' and airdrops. Attackers embed convincing fake Mini Apps inside the official Telegram client, exploiting users' trust in in-app content and minimal platform vetting. Kaspersky urges users to verify sources, avoid entering login codes inside Mini Apps, enable two-step verification and passkeys, and store credentials in a password manager.
read more →

AI-Enhanced Phishing and Social Scams Surge Before Christmas

⚠️ Check Point reports a surge in Christmas-themed phishing and social scams, detecting 33,500 unique phishing emails and over 10,000 seasonal social ads in a recent two-week period. Threat actors are using AI to produce flawless local-language messages, build fake e-commerce sites with working checkouts, and generate deepfake audio and smishing that mimic delivery alerts. Consumers should watch for spoofed URLs, unusual payment requests, new or inactive accounts and emotional triggers, and avoid clicking unsolicited links or sharing credentials.
read more →

Phantom Stealer delivered via ISO-based phishing chain

📧 Seqrite Labs has uncovered a Russian-origin phishing campaign, tracked as Operation MoneyMount-ISO, that delivers the Phantom information stealer through a multi-stage attachment chain. Attackers distribute a ZIP containing an ISO that auto-mounts and displays a disguised executable; running it triggers a loader that decrypts a malicious DLL and injects the stealer into memory while performing extensive anti-analysis checks. The campaign targets Russian-speaking finance, procurement and HR roles, harvesting passwords, cookies, crypto wallets, keystrokes and Discord tokens, then exfiltrating data via Telegram bots, Discord webhooks and FTP.
read more →

2025 Phishing Trends: Omni-channel Attacks and PhaaS

🔒2025 saw substantial attacker innovation in phishing, with identity-focused techniques becoming more effective and pervasive. Phishing moved beyond email into omni-channel vectors such as LinkedIn DMs, malicious search results, compromised sites and malvertising, which evade traditional email defenses. Criminal PhaaS kits (Tycoon, Sneaky2FA, Evilginx variants and others) commoditized AiTM and MFA-bypass capabilities. Security teams are urged to expand detection into the browser and close visibility gaps with browser-based response.
read more →

Christmas 2025 Scams: AI-Driven Phishing and Fake Deals

🎄 AI and automation are enabling more sophisticated holiday scams in 2025, making fraudulent emails, fake retail sites, and social media giveaways harder to detect. Check Point researchers flagged over 33,500 Christmas-themed phishing emails and more than 10,000 suspicious holiday ads within a 14-day window, underscoring a global surge. Practical guidance emphasizes recognizing red flags, validating sellers, and using multi-factor authentication and updated security tools to protect holiday shoppers.
read more →

Phantom Stealer Delivered via ISO Phishing in Russia

🛡️ Cybersecurity researchers have disclosed Operation MoneyMount-ISO, a phishing campaign that delivers Phantom Stealer via malicious ISO images attached inside ZIP archives targeting Russian finance, accounting, procurement, legal and payroll teams. The ISO, labeled as a bank transfer confirmation, mounts as a virtual CD and executes an embedded DLL named CreativeAI.dll to launch the stealer. Phantom harvests browser-stored crypto wallets, Discord tokens, passwords, cookies, credit cards, and can log keystrokes and monitor the clipboard. Stolen data is exfiltrated over Telegram, Discord webhooks or FTP.
read more →

PayPal Subscriptions Abused to Send Fake Purchase Emails

⚠️ BleepingComputer warns that attackers are abusing PayPal's Subscriptions feature to send legitimate-looking emails from service@paypal.com that include fake purchase notifications embedded in the Customer Service URL field. The messages pass DKIM/SPF and originate from PayPal mail servers, but include manipulated metadata or API-supplied text and obfuscated Unicode to evade filters. Recipients are advised to ignore the phone number in such emails and verify charges directly in their PayPal account.
read more →

New AI-enabled Phishing Kits Escalate Credential Theft

🔒Four newly documented phishing kits — BlackForce, GhostFrame, InboxPrime AI, and Spiderman — enable large-scale credential theft and advanced MFA bypass techniques. BlackForce (first seen August 2025) uses Man‑in‑the‑Browser (MitB) capabilities to capture OTPs and exfiltrate data to Telegram/C2 panels, while GhostFrame hides phishing pages inside iframes. InboxPrime AI automates high-quality mass mailings with generative assistance, and Spiderman offers full-stack banking replicas with ISP and geofence filtering. Researchers warn these kits lower the bar for attackers and recommend layered defenses including phishing-resistant MFA, strong email validation, anomaly detection, and user training.
read more →

Tracing Stolen Data After Phishing: Market and Risks

🔒 Kaspersky examines the lifecycle of personal data stolen through phishing, showing how information is harvested, traded, verified and repeatedly reused across the shadow market. Stolen records are collected via forms and transmitted by email, Telegram bots or specialized admin panels before being bundled into bulk dumps, analyzed and resold. The report highlights targeted categories, average resale values for different account types and practical protections such as using 2FA, passkeys and a password manager, plus immediate steps to take if your data has been exposed.
read more →

Spiderman phishing kit targets dozens of European banks

🕷️Spiderman is a newly observed phishing kit that replicates banking and cryptocurrency login flows to capture credentials, 2FA codes, credit card details, and wallet seed phrases. Researchers at Varonis report it targets customers across five European countries and major brands including Deutsche Bank, ING, CaixaBank, PayPal, and crypto wallets such as Ledger and Metamask. The kit’s modular control panel lets operators filter victims by country or device, intercept PhotoTAN and OTP codes in real time, export harvested data with one click, and redirect non-targeted visitors.
read more →