Tag: Phishing Attacks news

Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks
News

Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks

In March 2024, a new phishing attempt was attributed to the Iran-affiliated threat actor MuddyWater (also known as Mango Sandstorm or TA450). The campaign purports to offer a genuine Remote Monitoring and Management (RMM) system called Atera. According to Proofpoint, the operation, which ran from March 7 through the week of March 11, was directed on Israeli companies in the worldwide manufacturing, technology, and information security sectors. According to the corporate security company, "TA450 sent emails with PDF attachments that contained malicious links." Although TA450 is not new to this technique, the threat actor has more lately depended on inserting malicious URLs straight into email message bodies rather than taking an additional step read more Iran Linked MuddyWater Deploy...
Hackers Exploiting Popular Document Publishing Sites for Phishing Attacks
News

Hackers Exploiting Popular Document Publishing Sites for Phishing Attacks

Once again demonstrating how threat actors are repurposing legitimate services for malicious ends, threat actors are using digital document publishing (DDP) sites hosted on platforms such as FlipSnack, Issuu, Marq, Publuu, RelayTo, and Simplebooklet for phishing, credential harvesting, and session token theft. According to Cisco Talos researcher Craig Jackson, hosting phishing lures on DDP sites increases the chance of a successful phishing attack because these sites frequently have a positive reputation, are unlikely to show up on web filter blocklists, and may give users a false sense of security if they recognize them as reputable or familiar. Although adversaries have previously hosted phishing documents using well-known cloud-based services like Google Drive, OneDrive, Dropbox,...
DarkGate and PikaBot Malware Resurrect QakBot’s Tactics in New Phishing Attacks
News

DarkGate and PikaBot Malware Resurrect QakBot’s Tactics in New Phishing Attacks

Phishing campaigns that distribute malware families like DarkGate and PikaBot employ the same strategies that were previously employed in attacks with the defunct QakBot trojan. In a report shared with The Hacker News, Cofense stated, "These include URLs with unique patterns that limit user access, hijacked email threads as the initial infection, and an infection chain nearly identical to what we have seen with QakBot delivery." "The malware families used also follow suit to what we would expect QakBot affiliates to use."Earlier in August, QakBot—also known as QBot and Pinkslipbot—was taken offline as part of Operation Duck Hunt read more DarkGate and PikaBot Malware Resurrect QakBot's Tactics in New Phishing Attacks. Get up to date on the latest cybersecurity news and enhance yo...