Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States…
Tag: phishing
ZeroTokens Phishing Platform Steers Attacks in Real Time
ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both…
Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations
Check Point has identified and blocked a large-scale email phishing campaign using fraudulent financial hardship and debt-relief offers to manipulate…
TikTok phishing: How to spot fake login and verification pages
Scammers use fake TikTok login pages, warnings, and verification offers to trick you into handing over your account details.
Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages
Bank customers searching for a login page can now be led into a trap before they receive a suspicious email or text message. Criminals are manipulating…
Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages
Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to…
Microsoft Teams Phishing Deploys New SynkLoader Malware to Steal Windows Passwords
Microsoft Teams phishing is again being used as a doorway to deliver a malware family called SynkLoader. The campaign relies on a familiar…
Post-DEF CON phishing campaign delivered AMOS and NetSupport malware
A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware…
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security…
Phishing Campaign Exploits COLDCARD Vulnerability Fears to Spread ScreenConnect
A new phishing campaign is taking advantage of concerns over a recently revealed COLDCARD wallet vulnerability and the suspected theft of $88.6 million in…
Phishing-as-a-Service Is Turning Credential Theft Into a Scalable Cybercrime Business
Phishing is no longer limited to technically skilled criminals building fraudulent campaigns from scratch. Through phishing-as-a-service (PhaaS),…
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions…
Russian snoops add OAuth abuse to targeted phishing campaigns
Don’t click on that State Department meeting invite
Amazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Off
Amazon’s less-detailed order emails protect purchase data but may make phishing harder to spot. Learn how to verify order messages safely online.
Def Con Attendees Targeted by Persistent Phishing Campaign
Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in…
Crypto Scammer Uses Claude Code to Screen 100,000+ Phone Numbers in Phishing Operation
Rapid7 found a crypto scammer used Claude Code on more than 100,000 phone numbers in a phishing and vishing operation targeting cryptocurrency holders.
Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps
A Google-sponsored search result for Claude installation instructions is being used to deliver a sophisticated macOS stealer and remote-access trojan…
JWR Phishing Framework Uses Real-Time WebSocket Control and AES Encryption to Steal Banking Credentials
JWR is a phishing framework built for live fraud. It turns a fake payment or bank page into a live channel that lets criminals watch details arrive as…