Advertisement
Top

Tag: Phishing


Cyber-crime, Malware

The Impact of AI on Social Engineering Cyber Attacks

November 8, 2023

Via: SecureWorld

Social engineering attacks have long been a threat to businesses worldwide, statistically comprising roughly 98% of cyberattacks worldwide. The average business faces more than 700 of these types of attacks every single year. Whether manifesting itself in a sophisticated phishing […]


Cyber warfare, Cyber-crime

MuddyWater has been spotted targeting two Israeli entities

November 3, 2023

Via: Security Affairs

Iran-linked APT group MuddyWater (aka SeedWorm, TEMP.Zagros, and Static Kitten) is targeting Israeli entities in a new spear-phishing campaign, Deep Instinct’s Threat Research team reported. The phishing messages were aimed at deploying a legitimate remote administration tool called Advanced Monitoring […]


Data loss, Threats & Malware

Okta tells 5,000 of its own staff that their data was accessed in third-party breach

November 2, 2023

Via: The Register

Okta has sent out breach notifications to almost 5,000 current and former employees, warning them that miscreants breached one of its third-party vendors and stole a file containing staff names, social security numbers, and health or medical insurance plan numbers. […]


Cyber-crime, Phishing

Ingenious Phishing Tactics in the Modern Scammer’s Toolbox

October 30, 2023

Via: SecureWorld

When it comes to impactful types of internet-borne crime, phishing is the name of the game. And for good reason. It serves as a vessel for various strains of malware, including ransomware, and underlies data-stealing campaigns that target large organizations […]


Editorial

Understanding Bulletproof Hosting: The Dark Underbelly of Cybercrime

October 23, 2023

Via: Natalie Dunn

The digital landscape has revolutionized our lives, connecting people across the globe. However, alongside the many positive aspects, there exists a dark underbelly of cybercrime, where hackers operate with impunity. One essential tool in the arsenal of these malicious actors […]


Threats & Malware, Virus & Malware

How to stop ransomware thieves WORMing their way into your data

October 6, 2023

Via: The Register

Most of us dislike cyber criminals, but not many of us dislike them quite as much as Anthony Cusimano. The director of technical marketing at storage company Object First was on the sharp end of an identity theft attack after […]


Mobile, Mobile security

Xenomorph malware is back after months of hiatus and expands the list of targets

September 26, 2023

Via: Security Affairs

Researchers from ThreatFabric uncovered a new campaign spreading Xenomorph malware to Android users in the United States and all over the world. In February 2022, researchers from ThreatFabric first spotted the Xenomorph malware, which was distributed via the official Google […]


Cyber-crime, Phishing

W3LL Store: How a Secret Phishing Syndicate Targets 8,000+ Microsoft 365 Accounts

September 6, 2023

Via: The Hacker News

A previously undocumented “phishing empire” has been linked to cyber attacks aimed at compromising Microsoft 365 business email accounts over the past six years. “The threat actor created a hidden underground market, named W3LL Store, that served a closed community […]


Threats & Malware, Virus & Malware

Phishing-as-a-Service Gets Smarter: Microsoft Sounds Alarm on AiTM Attacks

August 29, 2023

Via: The Hacker News

Microsoft is warning of an increase in adversary-in-the-middle (AiTM) phishing techniques, which are being propagated as part of the phishing-as-a-service (PhaaS) cybercrime model. In addition to an uptick in AiTM-capable PhaaS platforms, the tech giant noted that existing phishing services […]


Threats & Malware, Vulnerabilities

WinRAR Security Flaw Exploited in Zero-Day Attacks to Target Traders

August 24, 2023

Via: The Hacker News

A recently patched security flaw in the popular WinRAR archiving software has been exploited as a zero-day since April 2023, new findings from Group-IB reveal. The vulnerability, cataloged as CVE-2023-38831, allows threat actors to spoof file extensions, thereby making it […]


Cyber-crime, Malware

New Telegram Bot “Telekopye” Powering Large-scale Phishing Scams from Russia

August 24, 2023

Via: The Hacker News

A new financially motivated operation is leveraging a malicious Telegram bot to help threat actors scam their victims. Dubbed Telekopye, a portmanteau of Telegram and kopye (meaning “spear” in Russian), the toolkit functions as an automated means to create a […]


Cyber-crime, Malware

Russian Hackers Use Zulip Chat App for Covert C&C in Diplomatic Phishing Attacks

August 17, 2023

Via: The Hacker News

An ongoing campaign targeting ministries of foreign affairs of NATO-aligned countries points to the involvement of Russian threat actors. The phishing attacks feature PDF documents with diplomatic lures, some of which are disguised as coming from Germany, to deliver a […]


Cyber-crime, Phishing

Interpol Busts Phishing-as-a-Service Platform ’16Shop,’ Leading to 3 Arrests

August 10, 2023

Via: The Hacker News

Interpol has announced the takedown of a phishing-as-a-service (PhaaS) platform called 16Shop, in addition to the arrests of three individuals in Indonesia and Japan. 16Shop specialized in the sales of phishing kits that other cybercriminals can purchase to mount phishing […]


Cyber-crime, Phishing

Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target Executives

August 10, 2023

Via: The Hacker News

Threat actors are increasingly using a phishing-as-a-service (PhaaS) toolkit dubbed EvilProxy to pull off account takeover attacks aimed at high-ranking executives at prominent companies. According to Proofpoint, an ongoing hybrid campaign has leveraged the service to target thousands of Microsoft […]


Threats & Malware, Virus & Malware

Russian Hacking Group Shakes Up Its Infrastructure

August 3, 2023

Via: DataBreach Today

A Russia-linked hacking group is shifting its online infrastructure likely in response to public disclosures about its activity. Recorded Future’s Insikt Group traced over the last five months the revamped infrastructure of a group it tracks as “BlueCharlie,” which overlaps […]


Cyber-crime, Phishing

Phishers Exploit Salesforce’s Email Services Zero-Day in Targeted Facebook Campaign

August 2, 2023

Via: The Hacker News

A sophisticated Facebook phishing campaign has been observed exploiting a zero-day flaw in Salesforce’s email services, allowing threat actors to craft targeted phishing messages using the company’s domain and infrastructure. “Those phishing campaigns cleverly evade conventional detection methods by chaining […]


Cyber-crime, Phishing

BlueBravo Deploys GraphicalProton Backdoor Against European Diplomatic Entities

July 28, 2023

Via: The Hacker News

The Russian nation-state actor known as BlueBravo has been observed targeting diplomatic entities throughout Eastern Europe with the goal of delivering a new backdoor called GraphicalProton, exemplifying the continuous evolution of the threat. The phishing campaign is characterized by the […]


Network security, Security

Where from, Where to — The Evolution of Network Security

June 14, 2023

Via: The Hacker News

For the better part of the 90s and early aughts, the sysadmin handbook said, “Filter your incoming traffic, not everyone is nice out there” (later coined by Gandalf as “You shall not pass”). So CIOs started to supercharge their network […]


Application security, Security

Adversary-in-the-Middle Attack Campaign Hits Dozens of Global Organizations

June 13, 2023

Via: The Hacker News

“Dozens” of organizations across the world have been targeted as part of a broad business email compromise (BEC) campaign that involved the use of adversary-in-the-middle (AitM) techniques to carry out the attacks. “Following a successful phishing attempt, the threat actor […]


Threats & Malware, Virus & Malware

Stealth Soldier: A New Custom Backdoor Targets North Africa with Espionage Attacks

June 9, 2023

Via: The Hacker News

A new custom backdoor dubbed Stealth Soldier has been deployed as part of a set of highly-targeted espionage attacks in North Africa. “Stealth Soldier malware is an undocumented backdoor that primarily operates surveillance functions such as file exfiltration, screen and […]