phishing11 articles
Brazilian Gov Websites Hijacked to Deliver Malware in Active Banking Campaign
A cyberattack campaign called PhantomEnigma has compromised more than 20 Brazilian government websites, turning them into malware delivery channels targeting banks and public agencies. The operation uses fake police-themed documents sent via authenticated emails and trusted `.gov.br` domains to deceive victims into installing a modular backdoor capable of stealing credentials, establishing persistence, and delivering additional payloads. The campaign's abuse of legitimate government infrastructure and rotating command-and-control domains makes it particularly difficult to detect using conventional security tools, with behavioral analysis recommended as a more reliable defence.
OkoBot Malware Serves Fake Recovery Pages Inside Real Ledger and Trezor Apps
OkoBot is a Windows malware framework active since April 2025 that targets hardware wallet users through a module called SeedHunter, which injects fake recovery phrase prompts directly into legitimate Ledger and Trezor desktop applications rather than replacing them. The malware is delivered via ClickFix lures or trojanized software on GitHub, establishing persistent access through reverse SSH tunnels, patched RDP components, and a scheduled task called "Apple Sync," before deploying over 20 surveillance and theft modules. Kaspersky's research identified hundreds of victims across 25+ countries, but attribution remains unclear beyond soft indicators suggesting Russian-speaking threat actors.
Botnets in Your Living Room, Ransomware in Your Browser, and AI That Follows the Wrong Orders: This Week in Security
This week's cybersecurity recap highlights how attackers exploited ordinary, trusted systems rather than sophisticated vulnerabilities. Key incidents included Google and the FBI disrupting the NetNut residential proxy botnet (comprising at least 2 million devices), a fake GitHub PoC repository delivering the ChocoPoC RAT via a malicious dependency, and AI-generated browser ransomware leveraging Chromium's File System Access API. Additional notable stories covered WhatsApp username impersonation concerns, a Scattered Spider suspect extradited to the US, and multiple phishing-as-a-service toolkits emerging in the wild. The overarching theme was misplaced trust — in home devices, clean-looking code, identity reset flows, and browser permissions — underscoring that attackers need little more than a familiar, overlooked entry point.
VEIL#DROP: How Attackers Are Hiding Malware Inside Google's Blogger
The VEIL#DROP attack chain uses a disguised JavaScript file to trigger a multi-stage malware infection, leveraging Google's Blogger platform to host payloads and bypass reputation-based security defences. The infection employs advanced evasion techniques including dynamic URL generation, runtime script mutation, fileless in-memory execution, and abuse of trusted Microsoft-signed binaries (Living-off-the-Land) to avoid detection. The ultimate goal is to deploy PureLogs Stealer, a .NET-based malware-as-a-service infostealer capable of harvesting sensitive data and potentially enabling deeper network compromise.
Avalon Malware Framework Bundles Ransomware, Credential Theft and AI-Assisted Development Into One Nasty Package
Cybersecurity researchers have uncovered a modular malware framework called **Avalon**, distributed via phishing emails, which combines credential theft, lateral movement, remote access, and ransomware (internally named CrownX) into a single toolkit. The framework employs sophisticated evasion techniques targeting major security vendors and shows signs of AI-assisted development, highlighting how AI is lowering the barrier to entry for malware creation. These findings coincide with other emerging AI-driven threats, including a fully autonomous LLM-powered ransomware attack and a novel malware that uses a public LLM API to translate plain-language attacker instructions into shell commands — requiring no coding knowledge whatsoever.
EvilTokens Phishing Kit Is Far Nastier Than Anyone Realised
EvilTokens, a device-code phishing kit capable of bypassing multi-factor authentication on Microsoft 365, has been found to be more sophisticated than previously understood, with Cisco Talos uncovering a linked phishing-as-a-service operator panel called "ARToken." Talos revealed how the phishing lures reach victims' inboxes, describing a targeted approach that exploits real vendor relationships and abuses legitimate SharePoint domains to evade detection. Beyond simple credential theft, ARToken includes a comprehensive post-exploitation toolkit with full business email compromise capabilities, making it a complete BEC operations platform rather than just a phishing kit.
Ousaban Banking Trojan Is Hunting Iberian Bank Customers via Fake PDF Lures
Ousaban, a Brazilian banking trojan also known as Javali, is targeting Windows users in Spain and Portugal through phishing PDFs that trick victims into downloading malware hidden inside an image file using steganography. Once installed, it monitors banking activity, capturing keystrokes and screenshots, and gives attackers remote control to hijack live banking sessions at over two dozen Iberian banks. The campaign uses geofencing to restrict delivery to genuine targets in the two countries, and evades detection through a rotating daily command server address and a custom encryption scheme that has proved resilient for years.
NFCShare Malware Evolves: Fake Banking App Updates Delivered Via GitHub
A new Android malware called NFCShare is being distributed through fake banking app updates hosted on GitHub, targeting customers of banks primarily in Italy and Spain. The malware tricks victims into scanning their payment cards near their phone's NFC chip under the guise of a security verification, stealing card details and PINs which are then sent to attackers for use in NFC payment relay fraud. Android users are advised to only download banking apps from Google Play, enable Play Protect, and be wary of any requests to scan their cards through an app.
Meet Atlas RAT: The Chinese Cybercrime Group Now Targeting Europe
A Chinese-speaking cybercrime group known as TA4922 has expanded its operations into Europe, targeting organisations in Germany, Italy, the UK, and South Africa using newly documented malware including the Atlas RAT backdoor. The group employs localised phishing lures mimicking payroll notices, tax filings, and government communications, and has dramatically increased its activity since March 2026, conducting more unique campaigns than any other tracked cybercrime actor. Researchers at Proofpoint note that the malware's surveillance capabilities — including keylogging, screen capture, and webcam recording — could potentially be sold to or leveraged by espionage groups.
Kali365 Phishing Kit Graduates From Microsoft Nuisance to Multi-Platform Menace
Kali365, a phishing-as-a-service platform previously flagged by the FBI for bypassing Microsoft 365 MFA, has significantly expanded its targets to include AWS, Okta, Xerox DocuShare, and major Russian platforms such as MAX Messenger, Mail.ru, and Yandex. The platform exploits **device code phishing**, abusing OAuth 2.0 authentication workflows to capture access tokens after tricking victims into completing login steps on behalf of attackers — rendering MFA ineffective as a defence. Security researchers at Arctic Wolf identified 126 active malicious hosts in May 2026, highlighting Kali365's growing scale and the broader surge in device code phishing kits, of which at least 14 are now available to threat actors.
Drainer-as-a-Service: How Crypto Wallet Theft Became a Subscription Business
Crypto drainers have evolved into sophisticated "Drainer-as-a-Service" (DaaS) platforms, where operators maintain the technical infrastructure while affiliates drive victims to fake crypto or DeFi websites, tricking them into approving malicious wallet transactions that instantly transfer their assets. An analysis of the "Lucifer DaaS" operation reveals it functions much like a legitimate SaaS business, complete with software updates, affiliate commissions, automated deployment tools, and operational resilience strategies such as migrating to decentralized hosting after takedowns. Users can protect themselves by being cautious of unsolicited wallet connection requests, unexpected approval prompts, urgent claims, and suspicious links received via social media or messaging platforms.