← BACK TO FEED
TAG

phishing19 articles

£8K Phishing Kit Promises to Plant Fake Passkeys and Haunt Compromised Accounts Long After You've Changed Your Password

A $10,000 phishing kit called iAuthFlow v2, advertised on Russian-language cybercrime forums, uses a browser-in-the-middle technique to hijack authentication sessions and secretly enroll attacker-controlled passkeys on compromised accounts — allowing persistent access even after victims change their passwords. The kit relays the victim's login interaction through an attacker-controlled browser, then exploits the authenticated session to register a rogue passkey, reportedly completing the process within seconds. Security researchers warn that incident response must go beyond password resets and session revocation, requiring a thorough audit of all post-compromise account changes, including newly enrolled passkeys, OAuth grants, and recovery methods.

23 Aug 2026

Three Russian Spy Groups Are Running OAuth Phishing Ops Against Western Targets

Google's Threat Intelligence Group has identified three suspected Russian cyber-espionage groups — UNC6293, UNC7005, and UNC5976 — conducting highly targeted phishing campaigns against individuals in government, academia, aerospace, and think tanks across Europe and the US. The groups, likely linked to Russia's SVR intelligence service, have increasingly abused legitimate OAuth authentication flows to steal account access tokens, making their attacks harder to detect as malicious. Targets are urged to be vigilant about unsolicited calendar invites, conference invitations, and file-sharing requests, which the operatives use as lures to compromise personal and professional accounts.

22 Aug 2026

France's Tax Authority Breach: 600,000 Affected, Private Messages Included

France's tax authority (DGFiP) has confirmed a data breach affecting approximately 600,000 individuals and businesses, with stolen information including tax identification numbers, personal details, and for around 250 people, the actual contents of private messages exchanged with the authority. Affected parties are being notified and warned of potential follow-on attacks such as phishing and impersonation scams exploiting the stolen data. The incident is the latest in a series of significant cybersecurity breaches targeting French public sector organisations in 2025.

21 Aug 2026

SVR Operatives Are Turning Hotel Wi-Fi Into Malware Traps

Russian SVR operatives (Storm-2945/Midnight Blizzard) are compromising public Wi-Fi captive portal networks at hotels and conference centres to deliver sophisticated malware, in a campaign Microsoft calls "CaptiveCrunch." By manipulating DNS and HTTP traffic to position themselves as adversary-in-the-middle, attackers use ClickFix-style fake prompts — disguised as OS updates or driver repairs — to trick users into installing malware, including a full-featured Windows RAT called CornFlake and an in-memory credential-stealing tool called ChocoShell. The campaign also incorporates device code phishing to hijack victims' Microsoft 365 accounts, with Microsoft advising users to avoid public Wi-Fi where possible and organisations to disable device code authentication flows to limit exposure.

4 Aug 2026

Pope's Prayer App Exposes 700,000 Users Because Nobody Bothered to Check Auth

The Pope's official prayer app, Click To Pray, has exposed the personal data of over 700,000 users — including names, email addresses, and dates of birth — due to a basic security flaw known as an Insecure Direct Object Reference (IDOR) bug, which allows anyone to access any user's data simply by changing a number in the API request. Ethical hacker BobDaHacker discovered and reported the vulnerability six months ago but has received no response from the Pope's Worldwide Prayer Network, and the flaw remains unpatched. The situation is made worse by additional security weaknesses in the signup process and poor email authentication, leaving users — many likely elderly and trusting of Vatican-affiliated communications — highly vulnerable to phishing attacks.

25 Jul 2026

Kratos Phishing Kit Dismantled: 200 Servers Down, But 1,800 Customers Still Have the Code

German and US authorities, alongside Indonesian police, have dismantled Kratos, a major phishing-as-a-service platform that enabled around 1,800 criminal customers to run approximately 15,000 phishing campaigns per month, taking more than 200 servers offline and arresting its alleged developer. The kit was particularly dangerous due to its adversary-in-the-middle capability, which stole live Microsoft 365 session cookies alongside credentials, allowing attackers to bypass multi-factor authentication entirely. However, the takedown leaves the kit's existing customer base and their copies of the code untouched, raising concerns that similar operations could resurface under a new name.

23 Jul 2026

Paying Ransomware Criminals Doesn't Make Them Go Away. Surprise.

New data from Proofpoint reveals that paying ransomware demands offers no guarantee of safety, with 22% of UK organisations that paid being extorted a second time. Globally, 54% of victim organisations paid ransoms, yet 2% never recovered their files at all, and law enforcement takedowns like Operation Cronos confirmed that criminals routinely retain victim data even after receiving payment. AI is increasingly being used to enhance the phishing and credential-harvesting attacks that precede ransomware, though experts stress that building organisational cyber-resilience remains a far more effective strategy than paying attackers.

22 Jul 2026

Misconfigured Server Blows Cover on AI-Assisted Phishing Operation Targeting Mexico

Rapid7 discovered an exposed malware delivery server containing over 1,000 files that revealed a mid-development phishing operation targeting Windows users in Mexico, using a WebDAV working-directory hijack (CVE-2025-33053) to deliver an infostealer disguised as a government ID document. The exposed toolkit showed strong evidence of AI-assisted development, with LLM-formatted documentation, test matrices, and emoji-heavy code suggesting the operator used an open-source AI coding agent to rapidly build, test, and scale the campaign. Over roughly five and a half days the panel logged over 77,000 requests, with Mexico accounting for the vast majority of traffic, and both identified campaign chains ultimately delivered the known .NET malware PureRAT.

22 Jul 2026

Brazilian Gov Websites Hijacked to Deliver Malware in Active Banking Campaign

A cyberattack campaign called PhantomEnigma has compromised more than 20 Brazilian government websites, turning them into malware delivery channels targeting banks and public agencies. The operation uses fake police-themed documents sent via authenticated emails and trusted `.gov.br` domains to deceive victims into installing a modular backdoor capable of stealing credentials, establishing persistence, and delivering additional payloads. The campaign's abuse of legitimate government infrastructure and rotating command-and-control domains makes it particularly difficult to detect using conventional security tools, with behavioral analysis recommended as a more reliable defence.

19 Jul 2026

OkoBot Malware Serves Fake Recovery Pages Inside Real Ledger and Trezor Apps

OkoBot is a Windows malware framework active since April 2025 that targets hardware wallet users through a module called SeedHunter, which injects fake recovery phrase prompts directly into legitimate Ledger and Trezor desktop applications rather than replacing them. The malware is delivered via ClickFix lures or trojanized software on GitHub, establishing persistent access through reverse SSH tunnels, patched RDP components, and a scheduled task called "Apple Sync," before deploying over 20 surveillance and theft modules. Kaspersky's research identified hundreds of victims across 25+ countries, but attribution remains unclear beyond soft indicators suggesting Russian-speaking threat actors.

17 Jul 2026

Botnets in Your Living Room, Ransomware in Your Browser, and AI That Follows the Wrong Orders: This Week in Security

This week's cybersecurity recap highlights how attackers exploited ordinary, trusted systems rather than sophisticated vulnerabilities. Key incidents included Google and the FBI disrupting the NetNut residential proxy botnet (comprising at least 2 million devices), a fake GitHub PoC repository delivering the ChocoPoC RAT via a malicious dependency, and AI-generated browser ransomware leveraging Chromium's File System Access API. Additional notable stories covered WhatsApp username impersonation concerns, a Scattered Spider suspect extradited to the US, and multiple phishing-as-a-service toolkits emerging in the wild. The overarching theme was misplaced trust — in home devices, clean-looking code, identity reset flows, and browser permissions — underscoring that attackers need little more than a familiar, overlooked entry point.

12 Jul 2026

VEIL#DROP: How Attackers Are Hiding Malware Inside Google's Blogger

The VEIL#DROP attack chain uses a disguised JavaScript file to trigger a multi-stage malware infection, leveraging Google's Blogger platform to host payloads and bypass reputation-based security defences. The infection employs advanced evasion techniques including dynamic URL generation, runtime script mutation, fileless in-memory execution, and abuse of trusted Microsoft-signed binaries (Living-off-the-Land) to avoid detection. The ultimate goal is to deploy PureLogs Stealer, a .NET-based malware-as-a-service infostealer capable of harvesting sensitive data and potentially enabling deeper network compromise.

10 Jul 2026

Avalon Malware Framework Bundles Ransomware, Credential Theft and AI-Assisted Development Into One Nasty Package

Cybersecurity researchers have uncovered a modular malware framework called **Avalon**, distributed via phishing emails, which combines credential theft, lateral movement, remote access, and ransomware (internally named CrownX) into a single toolkit. The framework employs sophisticated evasion techniques targeting major security vendors and shows signs of AI-assisted development, highlighting how AI is lowering the barrier to entry for malware creation. These findings coincide with other emerging AI-driven threats, including a fully autonomous LLM-powered ransomware attack and a novel malware that uses a public LLM API to translate plain-language attacker instructions into shell commands — requiring no coding knowledge whatsoever.

8 Jul 2026

EvilTokens Phishing Kit Is Far Nastier Than Anyone Realised

EvilTokens, a device-code phishing kit capable of bypassing multi-factor authentication on Microsoft 365, has been found to be more sophisticated than previously understood, with Cisco Talos uncovering a linked phishing-as-a-service operator panel called "ARToken." Talos revealed how the phishing lures reach victims' inboxes, describing a targeted approach that exploits real vendor relationships and abuses legitimate SharePoint domains to evade detection. Beyond simple credential theft, ARToken includes a comprehensive post-exploitation toolkit with full business email compromise capabilities, making it a complete BEC operations platform rather than just a phishing kit.

6 Jul 2026

Ousaban Banking Trojan Is Hunting Iberian Bank Customers via Fake PDF Lures

Ousaban, a Brazilian banking trojan also known as Javali, is targeting Windows users in Spain and Portugal through phishing PDFs that trick victims into downloading malware hidden inside an image file using steganography. Once installed, it monitors banking activity, capturing keystrokes and screenshots, and gives attackers remote control to hijack live banking sessions at over two dozen Iberian banks. The campaign uses geofencing to restrict delivery to genuine targets in the two countries, and evades detection through a rotating daily command server address and a custom encryption scheme that has proved resilient for years.

3 Jul 2026

NFCShare Malware Evolves: Fake Banking App Updates Delivered Via GitHub

A new Android malware called NFCShare is being distributed through fake banking app updates hosted on GitHub, targeting customers of banks primarily in Italy and Spain. The malware tricks victims into scanning their payment cards near their phone's NFC chip under the guise of a security verification, stealing card details and PINs which are then sent to attackers for use in NFC payment relay fraud. Android users are advised to only download banking apps from Google Play, enable Play Protect, and be wary of any requests to scan their cards through an app.

10 Jun 2026

Meet Atlas RAT: The Chinese Cybercrime Group Now Targeting Europe

A Chinese-speaking cybercrime group known as TA4922 has expanded its operations into Europe, targeting organisations in Germany, Italy, the UK, and South Africa using newly documented malware including the Atlas RAT backdoor. The group employs localised phishing lures mimicking payroll notices, tax filings, and government communications, and has dramatically increased its activity since March 2026, conducting more unique campaigns than any other tracked cybercrime actor. Researchers at Proofpoint note that the malware's surveillance capabilities — including keylogging, screen capture, and webcam recording — could potentially be sold to or leveraged by espionage groups.

4 Jun 2026

Kali365 Phishing Kit Graduates From Microsoft Nuisance to Multi-Platform Menace

Kali365, a phishing-as-a-service platform previously flagged by the FBI for bypassing Microsoft 365 MFA, has significantly expanded its targets to include AWS, Okta, Xerox DocuShare, and major Russian platforms such as MAX Messenger, Mail.ru, and Yandex. The platform exploits **device code phishing**, abusing OAuth 2.0 authentication workflows to capture access tokens after tricking victims into completing login steps on behalf of attackers — rendering MFA ineffective as a defence. Security researchers at Arctic Wolf identified 126 active malicious hosts in May 2026, highlighting Kali365's growing scale and the broader surge in device code phishing kits, of which at least 14 are now available to threat actors.

3 Jun 2026

Drainer-as-a-Service: How Crypto Wallet Theft Became a Subscription Business

Crypto drainers have evolved into sophisticated "Drainer-as-a-Service" (DaaS) platforms, where operators maintain the technical infrastructure while affiliates drive victims to fake crypto or DeFi websites, tricking them into approving malicious wallet transactions that instantly transfer their assets. An analysis of the "Lucifer DaaS" operation reveals it functions much like a legitimate SaaS business, complete with software updates, affiliate commissions, automated deployment tools, and operational resilience strategies such as migrating to decentralized hosting after takedowns. Users can protect themselves by being cautious of unsolicited wallet connection requests, unexpected approval prompts, urgent claims, and suspicious links received via social media or messaging platforms.

21 May 2026