< ciso
brief />
Tag Banner

All news with #spear phishing tag

132 articles

AI‑Assisted AitM Spear‑Phishing Targeting Taiwan

🛡️ Talos observed a mid‑2026 spear‑phishing campaign targeting Taiwan research institutions that used plausible event details and deceptive links. The emails used a reusable, formulaic template with personalized flattery and impersonated legitimate organizations while hiding actor‑controlled registration pages. Malicious posters included altered QR codes to expand the attack surface. The phishing kit replicated Google sign‑in pages across locales and used obfuscated JavaScript, HTTP POST exfiltration, and WebSocket C2 to perform real‑time AitM credential harvesting.
read more →

Brand-deal scam targeting YouTube creators exposed

📧 This article describes a modular phishing campaign that impersonates brands to trick YouTube creators into surrendering Google account access. The attackers start with personalized collaboration emails, direct victims to convincing fake platforms, and then present a Google sign-in or permissions prompt to capture credentials or obtain channel-management rights. Creators are advised to verify offers, check domains and permissions, use strong authentication, and follow recovery steps if compromised.
read more →

New Antino Backdoor Targets Asian Government Entities

🛡️ Cisco Talos attributes a recent espionage campaign to a China-nexus actor tracked as UAT-11587 that has targeted government and policy organizations across Asia using a previously undocumented Rust-compiled Windows backdoor called Antino. The actor employs tailored spear-phishing lures, sender spoofing, and a multi-stage chain that culminates in DLL sideloading to deploy the implant, which uses Microsoft 365 (Outlook and OneDrive) as its native C2 channel. Talos sees overlaps with known China-aligned clusters but treats UAT-11587 as a distinct activity set.
read more →

CloudSyncD macOS backdoor hidden in fake Zoom installer

🛡️ A new macOS backdoor, CloudSyncD, has been distributed inside a fake Zoom installer that prompts users for their login password before launching an embedded second-stage payload. Jamf Threat Labs first observed development builds on September 15 and identified samples targeting live C2 infrastructure two days later, indicating active deployment. The installer instructs users to bypass Gatekeeper, presents a bogus authorization prompt, and validates the entered password locally before using it to escalate the second-stage payload.
read more →

CSuite phishing campaign escalates to account and endpoint access

🔍 ANY.RUN researchers traced a US-focused CSuite phishing campaign across hundreds of sandbox analyses, finding 51% of submissions from the United States and heavy exposure in technology, manufacturing, government, and consulting. The operation uses business-themed lures (Adobe, DocuSign, Zoom, Microsoft 365) to either harvest credentials or deliver droppers that install legitimate remote-access tools like ScreenConnect and Action1. This dual path enables mailbox takeover, financial fraud, persistent RMM access, and lateral misuse of trusted identities, expanding impact beyond typical phishing.
read more →

Star Blizzard uses event lures to deploy CosmicPulse backdoor

🛡️ Microsoft says Russian-linked actor Star Blizzard has used fake event invitations and replying email threads to trick targets into running a Windows backdoor installer. Campaigns since January have targeted organizations tied to Ukraine, mainly in the U.S. and U.K., using hacked WordPress and cPanel accounts and a technique called RedFlick to install the CosmicPulse backdoor via scheduled tasks.
read more →

Threat Actors Use Passkey Phishing to Breach Cloud

🛡️ Microsoft disclosed two related campaigns: one sent over a million CEO-impersonation invoice scams in August 2026 to induce ACH transfers, and the other used passkey-themed social engineering since May 2026 to compromise cloud accounts. The fraud campaign leveraged generative AI, forged threads, and bogus domains to target enterprise finance teams. Cloud intrusions employed voice/SMS pretexts, counterfeit sign-in pages, AitM and device-code flows, and persistent MFA enrollment to enable extensive Microsoft Graph, SharePoint, OneDrive, and mailbox access.
read more →

Attackers exploit gap between Chromium fixes and Chrome

⚠️ Proofpoint researchers, alongside Google, Microsoft, and Volexity, uncovered a new exploit toolkit called BlueMoon that chains multiple Chromium and Windows vulnerabilities to enable one-click full system compromise. The kit leverages two V8-related patch-gap issues and a Windows kernel LPE to escalate privileges after a user clicks a spear-phishing link. Rapid weaponization and sharing across multiple threat clusters—many with suspected China links—underscore the danger of delays between upstream fixes and stable Chrome patches. Immediate patching, detection rule application, and heightened patch cadence and user awareness are recommended.
read more →

Impersonating IT Support to Gain Enterprise Access

🛡️ Microsoft Threat Intelligence observed a human-operated campaign abusing Microsoft Teams external collaboration to impersonate IT support and socially engineer users into granting interactive remote sessions. Attackers install a malicious MSI that stages a portable Node.js runtime and an obfuscated JavaScript implant to provide persistent C2-driven command execution. The operators perform extensive host and Active Directory reconnaissance and pivot enterprise-wide via WinRM, using legitimate tooling to blend into normal operations.
read more →

Distinct Russian-linked clusters targeting individuals

🛡️ Google Threat Intelligence Group (GTIG) reports three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting academia, aerospace and defense, governments, and think tanks across Europe and the US. These groups abuse legitimate authentication flows, including app passwords, OAuth prompts, and device linking, and use persistent, adaptive phishing with sophisticated social engineering. UNC7005 employs website templates, fingerprinting, analysis-evasion scripts, and malicious JavaScript to record audio/video or deliver further compromise.
read more →

Back-to-School Cyber Risks Hit Education Hard

📚 Check Point Research reports that the education sector was the most targeted industry between January and July 2026, averaging 4,696 weekly attacks per organization—more than double the global cross-industry average. Attack volumes rose further in July, while APAC saw the highest regional pressure and Europe and Latin America recorded the fastest growth. Researchers also observed surges in newly registered education-themed domains and coordinated phishing campaigns targeting students and staff, often leveraging counterfeit sites and compromised legitimate pages.
read more →

Sandworm targets IT pros with trojanized VPN client

🔒 A Ukrainian CERT report details a social-engineering campaign by a Sandworm-linked cluster, UAC-0145, targeting system administrators and IT professionals with fake job offers and interviews. Attackers move conversations to Telegram, conduct Zoom interviews, then instruct candidates to install a trojanized WireGuard client named "SopraVPN" from SourceForge. The modified client includes a nonstandard SymmetricKey option that decrypts and executes embedded PowerShell on Windows and retrieves executables via VPN on Linux, while using a custom Base64 alphabet to hinder analysis.
read more →

Levi Strauss reports corporate data theft after breach

🔒 Levi Strauss & Co. disclosed that attackers used social engineering on three employees to access company-issued machines and exfiltrate corporate data. The company says rapid response contained the intrusion and no consumer data was impacted, with no disruption to business operations. An investigation is ongoing and Levi’s will provide additional notifications as required; some reporting links the incident to voice-phishing campaigns.
read more →

Police point to Dutch suspects in Odido breach

🔎 The Dutch National Police report strong indications that Dutch-speaking attackers were involved in the February breach of telecom provider Odido. Investigators recovered traces including a phone call where an impersonator posing as an Odido IT employee used social engineering to enable a phishing-based data theft. Odido disclosed the incident affected millions of customers and that exposed records may include names, addresses, contact details, IBANs, and some ID numbers, while call records, billing data and passwords were not exposed. The extortion group ShinyHunters claimed responsibility and released a large archive of stolen records, and the gang has been linked to multiple vishing and SSO-targeting campaigns affecting major providers.
read more →

Suspected China-Nexus Campaign Targets Indian Taxpayers

🛡️ Seqrite Labs uncovered a targeted multi-stage phishing operation, dubbed Operation DragonReturn, impersonating India's Income Tax Department to deliver a remote access trojan. First observed on May 18, 2026, the campaign uses carefully crafted bilingual lures, malicious PDF attachments, and a ZIP-based DLL side-loading chain to install persistence and exfiltrate sensitive financial and credential data. The activity shows links to China-hosted infrastructure and overlaps with known tax-themed threat groups.
read more →

Armored Likho targets governments and utilities

🛡️ Kaspersky attributes a newly documented threat actor, Armored Likho, to espionage and financially motivated campaigns against government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. The group's toolkit includes obfuscated Python stealers (BusySnake), modular RATs, Go2Tunnel for reverse SSH, and droppers delivered via spear-phishing or weaponized LNK files exploiting CVE-2025-9491. The malware emphasizes persistence, credential theft, and dynamic module delivery tailored to victims.
read more →

US offers $10M for info on hackers targeting Signal and WhatsApp

🔔 The U.S. Department of State is offering up to $10 million through its Rewards for Justice program for information identifying members of UNC5792 and UNC4221, two groups tied to Russian intelligence and military services. The bounty follows FBI and CISA updates that these groups conducted phishing campaigns targeting Signal and WhatsApp users, including attempts to steal Signal Backup Recovery Keys by impersonating support agents. Targets included U.S. and NATO officials, journalists, NGOs, and researchers.
read more →

Mustang Panda uses cloud service for stealth C2

🛡️ A China-aligned espionage group, Mustang Panda, has run two campaigns targeting Indian government and hydropower-related networks, using new malware and abusing Zoho WorkDrive as a covert command-and-control channel. Acronis Threat Research Unit found active compromises affecting senior administrative systems, worked with CERT-In for remediation, and detailed three tools: SHARDLOADER, MINIRECON, and ZOHOMURK. The intrusions leveraged DLL sideloading via signed binaries and spear-phishing lures themed to hydropower and bilateral memoranda, with beaconing recorded from June 12–22, 2026.
read more →

Gamaredon expands malware and exfiltration tactics

🛡️ ESET observed 35 spear-phishing campaigns by the Russian APT group Gamaredon across 2025, primarily targeting Ukrainian government and military entities. Campaigns used HTML smuggling, archive attachments and a patched WinRAR flaw (CVE-2025-8088) to deploy HTA downloaders that drop payloads like PteroSand. The group enhanced persistence and lateral movement via PteroLNK, PteroPaste and PteroSetup while increasingly abusing tunnel and serverless services to hide infrastructure.
read more →

Windows SprySOCKS variants used in gov’t targeting

🔎 ESET researchers report Windows versions of the SprySOCKS malware, linked to the Chinese threat actor Earth Lusca, were used in 2023–2024 attacks against government organizations in Taiwan, Thailand, Pakistan, and Honduras. The Windows family includes WIN_DRV with kernel drivers for rootkit-like stealth and WIN_PLUS, a lighter backdoor. Both support TCP/UDP/WebSocket communications, SOCKS proxying, extensive C2 commands, file and process management, and data collection such as keystrokes and clipboard contents.
read more →