Tag: Phishing Attacks

Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine
News

Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine

As part of phishing assaults against Ukrainian companies, a hitherto unidentified threat activity cluster has been seen posing as the Slovak cybersecurity firm ESET. The security group, known as InedibleOchotense, tracks the campaign that was discovered in May 2025 and characterizes it as being aligned with Russia. Unfit for consumptionAccording to ESET's APT Activity Report Q2 2025–Q3 2025, which was provided with The Hacker News, Ochotense sent spear-phishing emails and Signal text messages to several Ukrainian companies that included a link to a trojanized ESET installer. It is determined that InedibleOchotense shares tactical similarities with a campaign reported by CERT-UA as UAC-0212, which it defines as a sub-cluster inside the Sandworm (also known as APT44) hacking group,...
Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks
News

Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks

Researchers studying cybersecurity are drawing attention to a dangerous effort that uses malicious JavaScript injections to attack WordPress websites in an attempt to divert people to dubious websites. In an investigation released last week, Sucuri researcher Puja Srivastava claimed that malware-driven material, such as phony Cloudflare verification, is inserted into websites. The website security firm claimed that after one of its clients' WordPress websites displayed questionable third-party JavaScript to site visitors, it launched an investigation and discovered that the attackers had made malicious changes to a file connected to the theme ("functions.php"). Probably in an effort to avoid discovery, the code added to "functions.php" includes references to Google Ads. However, ...
Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks
News

Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks

According to new research from ReliaQuest, threat actors are exploiting Microsoft's Direct Send functionality in combination with HTTP client tools like Axios to create a "highly efficient attack pipeline" in recent phishing attempts. According to a study published with The Hacker News, Axios user agent activity increased 241% between June and August 2025, outpacing the 85% growth of all other flagged user agents combined. Axios was responsible for 24.44% of all activity among the 32 flagged user agents that were seen during this period. Account takeover (ATO) attacks on Microsoft 365 systems were previously reported by Proofpoint in January 2025, which detailed campaigns that used HTTP clients to send HTTP requests and get HTTP answers from web servers. ReliaQuest told The Hacke...
Iranian APT35 Hackers Targeting Israeli Tech Experts with AI-Powered Phishing Attacks
News

Iranian APT35 Hackers Targeting Israeli Tech Experts with AI-Powered Phishing Attacks

A spear-phishing campaign targeting prominent cyber security professionals, computer science academics, and journalists in Israel has been traced to an Iranian state-sponsored hacking outfit affiliated with the Islamic Revolutionary Guard Corps (IRGC). According to a report released Wednesday by Check Point, in some of those efforts, attackers used emails and WhatsApp conversations to approach Israeli technology and cyber security specialists who were pretending to be assistants to technology executives or academics. Victims who interacted with the threat actors were sent to phoney Google Meet invitations or Gmail login sites. Educated Manticore, which overlaps with APT35 (and its sub-cluster APT42), CALANQUE, Charming Kitten, CharmingCypress, Cobalt Illusion, ITG18, Magic Hound, Mi...
Former Black Basta Members Use Microsoft Teams and Python Scripts in 2025 Attacks
News

Former Black Basta Members Use Microsoft Teams and Python Scripts in 2025 Attacks

Former participants in the Black Basta ransomware operation have been seen continuing to use their tried-and-true methods of Microsoft Teams phishing and email bombing to gain ongoing access to target networks. According to a study released to The Hacker News, attackers have recently added Python script execution to these strategies, utilizing cURL queries to retrieve and distribute malicious payloads. Even though the Black Basta brand took a serious hit and saw a fall following the public release of its internal chat logs earlier this February, the development shows that the threat actors are still reorganizing and changing course. According to the cybersecurity firm, 42% of the Teams phishing attacks over the same period occurred on compromised domains, and half of the attacks ...
Windows NTLM hash leak flaw exploited in phishing attacks on governments
News

Windows NTLM hash leak flaw exploited in phishing attacks on governments

Hackers are now actively leveraging a Windows vulnerability that exposes NTLM hashes using.library-ms files in phishing efforts aimed at both private and governmental organizations. Microsoft patched the vulnerability known as CVE-2025-24054 on March 2025. At first, it was considered 'less likely' to be exploited and not indicated as such. Only a few days after updates were made available, however, Check Point researchers report seeing active exploitation activity for CVE-2025-24054, which culminated between March 20 and 25, 2025. There is insufficient information to make a firm attribution, even though one of the IP addresses responsible for these assaults was previously connected to the state-sponsored threat group APT28 read more about Windows NTLM hash leak flaw exploited in ...
Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail
News

Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail

According to research from Palo Alto Networks Unit 42, threat actors are focusing on Amazon Web Services (AWS) settings in order to distribute phishing attempts to unwary targets. The activity cluster is being monitored by the cybersecurity firm under the moniker TGR-UNK-0011, which stands for a threat group with unclear motive. The company claims that this group overlaps with JavaGhost. Since 2019, TGR-UNK-0011 has been known to be operational. Historically, the organization concentrated on vandalizing websites, according to security expert Margaret Kelley. They switched to sending phishing emails in 2022 in order to make money. It is important to note that these attacks do not take use of any AWS vulnerabilities. Instead, the threat actors use environmental misconfigurations th...
Experts Uncover 70,000 Hijacked Domains in Widespread ‘Sitting Ducks’ Attack Scheme
News

Experts Uncover 70,000 Hijacked Domains in Widespread ‘Sitting Ducks’ Attack Scheme

Sitting Ducks is an attack tactic that has been used for years by a number of threat actors to take over legitimate domains and use them in investment fraud schemes and phishing attacks. According to Infoblox, around 9% (70,000) of the over 800,000 vulnerable registered domains it discovered over the previous three months have since been hijacked. In a comprehensive analysis published with The Hacker News, the cybersecurity firm claimed that since 2018, cybercriminals have exploited this mechanism to take over tens of thousands of domain names. Governmental organizations, non-profits, and well-known brands are examples of victim domains read more about Experts Uncover 70000 Hijacked Domains in Widespread 'Sitting Ducks' Attack Scheme. Get up to date on the latest cybersecurity ne...
Monday.com removes “Share Update” feature abused for phishing attacks
News

Monday.com removes “Share Update” feature abused for phishing attacks

Monday.com, a project management software, has eliminated its "Share Update" feature due to misuse by malicious actors during phishing campaigns. With the use of automated processes and dashboards, teams can manage and organize their work with Monday.com, a cloud-based project management tool. Among the 225,000 users of the platform include Coca-Cola, Canva, LionsGate, Oxy, Compass, and Zippo. Customers of Monday.com informed BleepingComputer on Tuesday that they had received phishing emails from the company's email accounts and were worried that the company had been compromised. These emails, which originated from notifications@monday.com and were sent via SendGrid, successfully passed DKIM, DMARC, and SPF authentication. Under the guise of a "Human Resources" department, the...
US govt sanctions Iranians linked to government cyberattacks
News

US govt sanctions Iranians linked to government cyberattacks

Four Iranian nationals have been sanctioned by the Treasury Department's Office of Foreign Assets Control (OFAC) for their involvement in cyberattacks against private enterprises, defense contractors, and the U.S. government. Additionally, OFAC declared sanctions against two front companies for the Iranian Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC), a branch of the Iranian Armed Forces that oversees the nation's cyberwarfare operations: Dadeh Afzar Arman (DAA) and Mehrsam Andisheh Saz Nik (MASN), formerly known as Mahak Rayan Afzar. While working for MASN, two of the sanctioned cybercriminals—Aliereza Shafie Nasab and Reza Kazemifar Rahman—targeted American organizations. Kazemifar also launched spear phishing attacks on the Department of the Treasury. ...