< ciso
brief />
Tag Banner

All news with #phishing tag

806 articles · page 6 of 41

ConsentFix: OAuth-based Microsoft 365 account hijacking

🛡️Researchers uncovered a new ClickFix variant called ConsentFix that tricks users into granting OAuth tokens, enabling attackers to access Microsoft 365 accounts without stealing passwords. Attackers use deceptive pages and social engineering—often via phishing emails imitating file-sharing services—to induce victims to drag a tokenized URL onto an attacker-controlled page. Once obtained, the OAuth token can expose Outlook, Teams, OneDrive, SharePoint and other services depending on the organization’s license and privileges, enabling data exfiltration, BEC and lateral movement. The technique is widely shared on cybercrime forums with tutorials and turnkey tools, increasing its prevalence and lowering the barrier for novice threat actors.
read more →

Exposed server reveals AI-assisted phishing toolkit

🧩 Rapid7 found an exposed delivery server containing 1,048 files: lure templates, tests, droppers, builder notes, and two campaign chains. One campaign targeted Windows users in Mexico via a fake government ID lookup and delivered an infostealer through a WebDAV-hosted exploit. The artifacts included README notes, test matrices, and logs that indicate the operator used generative AI (an open-source coding agent) to create, test, and document phishing delivery at scale. The kit heavily probed a WebDAV working-directory hijack (CVE-2025-33053) and contained tests for other file-handling flaws, while active delivery logs showed thousands of launch events concentrated in Mexico.
read more →

Fake TTF loader used in global phishing campaign

🛡️ Fortinet's FortiGuard Labs reports a global phishing campaign using obfuscated JavaScript and a Lua-based loader disguised as a TrueType Font (.ttf) to evade detection. The attack chain delivers RATs and infostealers such as Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant, employing in-memory execution and various anti-analysis techniques. Researchers noted business- and payment-themed lures, compressed archives with script loaders, and Donut shellcode to avoid writing payloads to disk. Defenders are advised to combine identity controls, application restrictions, and behavior-based detection.
read more →

The TTF Trap: Lua Loader Campaign Analysis

🔍 Since late March 2026, FortiGuard Labs documented a global phishing campaign that uses heavily obfuscated JScript droppers and AutoIt/Lua-based loaders disguised as .ttf files to deploy RATs and infostealers. Attackers impersonate reputable organizations to deliver malicious archives that stage multi-layered loaders with low detection rates. The campaign ultimately deploys payloads like Agent Tesla, Remcos, XWorm, and Snake-derived keyloggers, enabling remote control and data theft.
read more →

LastPass and Bitwarden Users Targeted by Phishing Alerts

🔔 LastPass warns of an active phishing campaign using fake corporate-style security notices that redirect recipients to fraudulent landing pages impersonating DocuSign. The emails, claiming to announce policy updates, come from addresses like hello@lastpassnewsletter.com and lead to domains such as lastpasscompliance[.]com, which have been flagged as malicious. Bitwarden users have received similar messages from hello@bitwardennewsletter.com redirecting to bitwardencompliance[.]com. LastPass confirms its systems were not breached and urges users to never share their master password and to report suspicious messages to abuse@lastpass.com.
read more →

New phishing kits target Microsoft 365 and evade MFA

🛡️ Two new phishing kits, Jalisco and OmegaLord, are being used to target Microsoft 365 accounts and bypass multi-factor authentication. Jalisco leverages the OAuth 2.0 device-code flow to trick victims into authorizing attacker-controlled devices, while OmegaLord poses as a PDF reader to harvest credentials and phone numbers. Researchers at ReliaQuest analyzed both toolkits and found attackers quickly exfiltrate data from SaaS platforms before demanding extortion. The report recommends tightening device-registration limits and blocking device-code authentication to reduce risk.
read more →

Forg365 phishing service lowers M365 takeover barrier

🔒 A phishing-as-a-service platform called Forg365 is lowering the technical barrier to Microsoft 365 account takeovers by offering AI-assisted lure creation, device-code abuse, and adversary-in-the-middle techniques. Distributed via Telegram with subscription pricing and a free trial, the service automates phishing workflows, email delivery, mailbox monitoring, and post-compromise persistence. Researchers advise restricting device-code authentication, deploying phishing-resistant MFA such as FIDO2/WebAuthn, and thoroughly revoking tokens, sessions, and unauthorized devices after compromise.
read more →

Lidl warns customers after third‑party data theft

🛡️ Lidl has alerted customers in Germany, Belgium and the Netherlands after personal data was stolen from a third‑party IT provider. The retailer said the online shop itself was not affected but a separately stored file containing names, phone numbers, emails, birth dates and customer numbers was accessed. Lidl stated passwords, payment details and delivery addresses are not impacted and urged vigilance against phishing. Forensics experts and authorities have been engaged and customers are advised to verify senders and avoid clicking unknown links.
read more →

Microsoft makes passkeys default for Entra ID

🔒 Microsoft Entra ID will begin rolling out passkeys as the default phishing-resistant authentication method starting September 1, 2026. Users currently using SMS or voice for MFA will be auto-enabled for passkeys and prompted to register on their next sign-in. Microsoft will retire native SMS and voice delivery on February 1, 2027, after which telecom partners via the Microsoft Security Store will be required for those methods.
read more →

Forg365 PhaaS Targets Microsoft 365 Accounts

🛡️ A new phishing-as-a-service operation named Forg365 targets Microsoft 365 by combining device-code phishing, AitM tactics, antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram and offered as a subscription, the kit uses legitimate delivery infrastructure like Amazon SES and SendGrid to blend into normal email flows before redirecting victims to attacker-controlled domains. The platform includes a clearnet operator panel, OAuth and token handling, and a Chromium extension called ForgCookie that automates cookie refresh and sustained access to compromised accounts.
read more →

Kaspersky introduces AI BEC detection for email

🛡️ Kaspersky explains a new capability to detect AI-generated business email compromise (BEC) messages by identifying both BEC-specific phrases and linguistic patterns typical of machine-generated text. The company notes that cybercriminals increasingly use large language models to craft persuasive phishing and BEC campaigns, and this detection works across eight languages. The feature is integrated into Kaspersky Secure Mail Gateway and available with the KSMS Plus license after the KSMG 3.1 update.
read more →

How Check Point stopped a student job phishing scam

📧 Check Point Research observed a large phishing campaign that used legitimate school accounts and Google Forms to recruit students into a likely money-mule scheme. The emails passed SPF/DKIM/DMARC and contained no malware or fake login pages, making them appear benign. Check Point Email Security evaluates context, sender behavior, message intent, and hosted-form usage to detect such threats before they reach users.
read more →

Forg365 PhaaS Targets Microsoft 365 with AI

🛡️ Forg365 is a phishing-as-a-service platform that targets Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device-code phishing with integrated AI-assisted lure generation. The service offers an admin dashboard for campaign management, OAuth and SMTP configuration, token handling, and a browser extension called ForgCookie for persistent cookie harvesting. Researchers at ZeroBEC found the operation uses legitimate delivery services like Amazon SES and SendGrid-hosted resources to blend malicious emails into normal traffic.
read more →

Phishing job interviews steal Google credentials

🔒 Security teams have uncovered a targeted phishing campaign impersonating over 30 major brands to lure candidates into fake job interviews and harvest Google account passwords. Attackers use realistic recruiter names, photos and PeopleForce-sent messages to appear legitimate, and links redirect through trusted domains to a calendar booking page that prompts a Google sign-in. The scheme leverages a browser-in-the-browser trick where a fake Google auth pop-up captures credentials, though password managers can often block autofill. The campaign has operated for months and highlights growing sophistication in recruitment scams amid workplace uncertainty.
read more →

Global Operation First Light 2026 Targets Cybercrime

🛡️ A global anti-fraud operation, Operation First Light 2026, ran from January 15 to April 30, 2026, coordinated by Interpol with support from regional partners and funding from China’s Ministry of Public Security. The crackdown targeted social engineering scams such as romance fraud and BEC, leading to over 5,800 arrests, identification of 15,606 suspects and interception of $293m in illicit assets. Actions included raids, freezing 31,014 bank accounts, seizing devices and using Interpol’s I-GRIP stop-payment mechanism.
read more →

INTERPOL-led Operation First Light nets global arrests

🕵️ Law enforcement agencies coordinated Operation First Light 2026 across 97 countries, arresting 5,811 suspects and seizing $293 million in illicit assets. The operation targeted social engineering fraud — including BEC, sextortion, impersonation, romance, and investment scams — and associated money laundering between January 15 and April 30. Authorities identified over 142,000 victims, blocked 31,014 bank accounts, and analyzed 152,808 cases while additional suspects were identified. INTERPOL coordinated the effort with regional policing bodies and funding support from China's Ministry of Public Security.
read more →

Dual‑RAT phishing targets India tax filers this season

🛡️ Researchers at Cyderes uncovered a phishing campaign impersonating the Indian Tax Department that delivers two remote access trojans via a multi-stage infection chain. Victims receive fake tax assessment emails that prompt them to download a seemingly legitimate ITR utility, which abuses signed Windows binaries to sideload malicious DLLs and perform in-memory execution and process injection. The campaign deploys a Gh0st RAT derivative and a .NET implant related to the QuasarRAT/AsyncRAT family, each communicating with separate C2 servers, providing redundant access even if one implant is blocked.
read more →

ESET H1 2026: Threats, AI, and Ransomware Trends

🔍 The first half of 2026 sees attackers adapting established techniques to new platforms and behaviours, with AI increasingly shaping operations. ESET analyzed nearly 900,000 AI skills and found tens of thousands suspicious and thousands malicious, while AI features began appearing inside malware such as the Android PromptSpy. Other trends include expanded click-based social engineering, surging QR-code phishing, and persistent ransomware activity using EDR killers.
read more →

Fake Microsoft Teams support call scam targets files

📢 Palo Alto Networks’ Unit 42 warns of a new campaign targeting Microsoft Teams users that begins with a survey email and a malicious PDF. If opened, victims soon receive a voice call claiming to be Microsoft Support; the fake agent requests permission to install a remote access tool and additionally deploys Ether RAT. The Trojan gives attackers full access to the compromised machine, enabling theft of sensitive information and files. Users should be cautious of unsolicited surveys and support calls.
read more →

RedWing malware: Android bank-fraud service rental

🛡️ RedWing is a commercially rented Android malware operation sold via Telegram that enables low-skill criminals to take over victims' phones and harvest banking credentials and one-time codes. Zimperium's zLabs links it to an earlier rent-a-malware family and says a Telegram bot builds custom malicious apps on demand. Infection begins with phishing to a fake app-store page that persuades users to sideload and authorize intrusive permissions like Accessibility and default SMS handling. Once installed, RedWing can present overlays, read SMS OTPs, forward calls, stream the screen, record input, and exfiltrate files and location.
read more →