Tag: phishing attack

Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access
News

Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access

A novel dual-vector campaign that uses credentials that have been obtained to install authentic Remote Monitoring and Management (RMM) software for ongoing remote access to vulnerable computers has been revealed by cybersecurity researchers. According to researchers Jeewan Singh Jalal, Prabhakaran Ravichandhiran, and Anand Bodke of KnowBe4 Threat Labs, "attackers are circumventing security perimeters by weaponizing the essential IT tools that administrators trust, rather than deploying custom viruses." "By stealing a 'skeleton key' to the system, they turn legitimate Remote Monitoring and Management (RMM) software into a persistent backdoor." Threat actors use phony invitation notifications to obtain victim credentials, which they then use to deploy RMM tools to create persistent ac...
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
News

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

Using a Rust-based implant nicknamed RustyWater, the Iranian threat actor known as MuddyWater has been linked to a spear-phishing campaign that targets Middle Eastern financial, telecom, marine, and diplomatic organizations. According to a report released this week by CloudSEK resetter Prajwal Awasthi, the campaign delivers Rust-based implants with asynchronous C2, anti-analysis, registry persistence, and modular post-compromise capability augmentation using icon spoofing and malicious Word documents. The most recent development is indicative of the ongoing evolution of MuddyWater's tradecraft, which has steadily but gradually decreased its reliance on reputable remote access software as a post-exploitation tool in favor of a varied custom malware arsenal that includes tools like re...
Blind Eagle Uses Proton66 Hosting for Phishing, RAT Deployment on Colombian Banks
News

Blind Eagle Uses Proton66 Hosting for Phishing, RAT Deployment on Colombian Banks

The use of the Russian bulletproof hosting service Proton66 has been strongly linked to the threat actor known as Blind Eagle. In a report released last week, Trustwave SpiderLabs claimed that by diverging from digital assets associated with Proton66, it was able to establish this connection and uncover an active threat cluster that uses Visual Basic Script (VBS) files as its initial attack vector and installs commercially available remote access trojans (RATS). A lot of threat actors use bulletpro.Even though Visual Basic Script (VBS) may seem antiquated, hosting companies like Proton66 continue to use it because they willfully disregard abuse reports and requests for legal takedowns. This facilitates the uninterrupted operation of malware delivery systems, command-and-control serv...
Midnight Blizzard deploys new GrapeLoader malware in embassy phishing
News

Midnight Blizzard deploys new GrapeLoader malware in embassy phishing

A new spear-phishing attack targeting diplomatic institutions in Europe, including embassies, is being carried out by the Russian state-sponsored espionage group Midnight Blizzard. The state-sponsored cyberespionage outfit Midnight Blizzard, also known as "Cozy Bear" or "APT29," is associated with Russia's Foreign Intelligence Service (SVR). Check Point Research claims that the current campaign introduces a new version of the 'WineLoader' backdoor as well as a malware loader known as 'GrapeLoader,' which had not been seen before. The phishing campaign began in January 2025 and starts with an email invited to a wine tasting event from 'bakenhof[.]com' or'silry[.]com,' posing as a Ministry of Foreign Affairs. The malicious link in the email causes a ZIP archive read more about M...
Gamma AI Platform Abused in Phishing Chain to Spoof Microsoft SharePoint Logins
News

Gamma AI Platform Abused in Phishing Chain to Spoof Microsoft SharePoint Logins

Gamma, a presentation platform driven by artificial intelligence (AI), is being used by threat actors in phishing attacks to trick unwary users into visiting fake Microsoft login sites. In an investigation published Tuesday, researchers Hinman Baron and Piotr Wojtyla of Abnormal Security claimed that attackers use Gamma, a relatively new AI-based presentation tool, as a weapon to provide a link to a phony Microsoft SharePoint login process. A phishing email, sometimes sent from authentic, compromised email accounts, is the first step in the attack chain. Its purpose is to trick recipients into opening an embedded PDF document. When the victim clicks on the links in the PDF attachment, they are taken to a presentation hosted on Gamma, where they are prompted read more about Gamma ...
Phishing Campaigns Use Real-Time Checks to Validate Victim Emails Before Credential Theft
News

Phishing Campaigns Use Real-Time Checks to Validate Victim Emails Before Credential Theft

Researchers studying cybersecurity are drawing attention to a novel kind of credential phishing attempt that makes sure the stolen data is linked to legitimate online accounts. Cofense has dubbed the approach precision-validating phishing, claiming that it uses real-time email validation to ensure that the phony login screens are only shown to a limited number of high-value targets. Since the threat actors simply interact with a pre-harvested list of legitimate email accounts, this strategy not only increases their chances of gaining useable credentials, according to the business. In contrast to "spray-and-pray" credential harvesting attacks, which usually entail sending out large quantities of spam emails in an attempt to indiscriminately capture victims' login credentials read ...
E-ZPass toll payment texts return in massive phishing wave
News

E-ZPass toll payment texts return in massive phishing wave

Recently, there has been a significant increase in phishing campaigns that pose as E-ZPass and other toll agencies. The scammers send victims many iMessage and SMS texts in an attempt to obtain their credit card and personal information. The messages contain links that, when clicked, direct the recipient to a phishing website that poses as Florida Turnpike, FasTrak, The Toll Roads, E-ZPass, or another toll authority in an effort to obtain their username, email address, physical address, and credit card details. Although the FBI warned about this scam in April 2024, BleepingComputer has observed and heard numerous complaints of a rise in mobile phishing campaigns. The texts originate from ostensibly random email accounts and get past anti-spam procedures read more about E-ZPass to...
Russian Star Blizzard Targets WhatsApp Accounts in New Spear-Phishing Campaign
News

Russian Star Blizzard Targets WhatsApp Accounts in New Spear-Phishing Campaign

A new spear-phishing campaign targeting victims' WhatsApp accounts has been attributed to the Russian threat actor Star Blizzard, which deviates from its usual tactics in an apparent effort to avoid detection. According to a Microsoft Threat Intelligence team report shared with The Hacker News, Star Blizzard's targets are typically related to government or diplomacy (both current and former position holders), defense policy or international relations researchers whose work touches on Russia, and sources of aid to Ukraine related to the war with Russia. A threat activity cluster associated with Russia, Star Blizzard (previously SEABORGIUM) is well-known for its credential harvesting efforts. It has been in operation since at least 2012 and is also known by the moniker Blue Callisto r...
Rockstar2FA Collapse Fuels Expansion of FlowerStorm Phishing-as-a-Service
News

Rockstar2FA Collapse Fuels Expansion of FlowerStorm Phishing-as-a-Service

Due to a disruption to the phishing-as-a-service (PhaaS) toolkit known as Rockstar 2FA, activity from another emerging product called FlowerStorm has rapidly increased. According to a fresh study released last week by Sophos, it seems that the [Rockstar2FA] group that is in charge of the service suffered at least a partial infrastructure failure, rendering pages related to the service inaccessible. "This seems to be the result of a technical issue with the service's backend rather than a removal action. Late last month, Trustwave published the first documentation of Rockstar2FA, a PhaaS service that enables criminal actors to conduct phishing attacks that may capture session cookies and Microsoft 365 account credentials read more about Rockstar2FA Collapse Fuels Expansion of FlowerS...
Ongoing phishing attack abuses Google Calendar to bypass spam filters
News

Ongoing phishing attack abuses Google Calendar to bypass spam filters

Abusing Google Calendar invites and Google Drawings pages to acquire passwords while evading spam filters is a persistent phishing fraud. Check Point, which has been keeping an eye on the phishing attack, said that in just four weeks, the threat actors sent over 4,000 emails that targeted 300 brands. The assaults targeted a wide range of businesses, including banks, construction firms, healthcare providers, and educational organizations, Check Point informed BleepingComputer. Threat actors begin the attack by sending meeting invites via Google Calendar that appear to be very harmless read more about Ongoing phishing attack abuses Google Calendar to bypass spam filters. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough...