Tag: phishing campaign

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
News

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

Since at least April 2025, there has been an active phishing campaign that uses legitimate Remote Monitoring and Management (RMM) software to target several vectors and establish persistent remote access to compromised machines. According to Securonix, the operation, dubbed VENOMOUS#HELPER, has affected more than 80 organizations, the majority of which are located in the United States. It has overlaps with clusters that Red Canary and Sophos previously tracked; the latter has given it the name STAC6405. The cybersecurity firm claimed that the campaign is consistent with a financially driven Initial Access Broker (IAB) or a ransomware precursor operation, albeit it is unclear who is behind it. According to a report provided with The Hacker News by researchers Akshay Gaikwad, Shikha S...
Phishing campaign targets freight and logistics orgs in the US and Europe
News

Phishing campaign targets freight and logistics orgs in the US and Europe

52 domains are being used in phishing attempts by a financially driven threat group called "Diesel Vortex" to steal credentials from freight and logistics businesses in the United States and Europe. The threat actor has been stealing 1,649 distinct credentials from platforms and service providers that are essential to the freight industry since September 2025. DAT Truckstop, TIMOCOM, Teleroute, Penske Logistics, Girteka, and Electronic Funds Source (EFS) are a few of the victims of Diesel Vortex. The typosquatting monitoring platform's researchers After discovering an exposed repository that contained a SQL database from a phishing operation that the threat actor named Global Profit and sold to other cybercriminals under the alias MC Profit Always, Have I Been Squatted discovered...
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware
News

Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware

Amnesia RAT is a new multi-stage phishing campaign that uses ransomware and a remote access virus to target users in Russia. In a technical analysis released this week, Fortinet FortiGuard Labs analyst Cara Lin stated, "The attack starts with social engineering lures delivered via business-themed documents crafted to appear routine and benign." While malicious activity operates in the background in silence, these papers and the scripts that go with them work as visual distractions, leading victims to fictitious chores or status updates. There are two distinctive aspects to the campaign. First, it distributes various types of payloads via several public cloud services. Dropbox is utilized to stage binary payloads, whereas GitHub is mostly used for script distribution. This division e...
Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign
News

Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign

A fresh round of attacks against Kazakhstan's energy sector has been linked to a threat actor, potentially of Russian origin. Operation BarrelFire, the codename for the operation, is associated with a new threat organization that Seqrite Labs is tracking as Noisy Bear. Since at least April 2025, the threat actor has been active. According to security researcher Subhajeet Singha, the campaign is directed at KazMunaiGas or KMG employees. The threat entity sent a phony document pertaining to the KMG IT department, imitating official internal communications and utilizing themes like policy updates, internal certification processes, and pay adjustments. A phishing email with a ZIP attachment that contains a Windows shortcut (LNK) downloader, a phony KazMunaiGas document, and a README....
Phishing Campaign Uses UpCrypter in Fake Voicemail Emails to Deliver RAT Payloads
News

Phishing Campaign Uses UpCrypter in Fake Voicemail Emails to Deliver RAT Payloads

Researchers studying cybersecurity have discovered a new phishing effort that distributes the malware loader UpCrypter by posing as purchase orders and voicemails. According to Cara Lin, a researcher at Fortinet FortiGuard Labs, the effort uses expertly constructed emails to spread malicious URLs that lead to plausible phishing pages. The purpose of these pages is to persuade users to download JavaScript files that serve as UpCrypter droppers. Since the beginning of August 2025, attacks that spread the malware have mostly targeted the manufacturing, technology, healthcare, construction, and retail/hospitality industries worldwide. Among other places, Austria, Belarus, Canada, Egypt, India, and Pakistan have reported the great bulk of the infections. An attacker can gain complete ...
Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign
News

Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Application specific passwords, also known as app passwords, are a Google account feature that threat actors with suspected Russian connections have been seen using as part of a new social engineering technique to access victims' emails. Google Threat Intelligence Group (GTIG) and Citizen Lab revealed details of the highly targeted campaign, claiming that the activity aims to mimic the U.S. Department of State. According to GTIG experts Gabby Roncone and Wesley Shields, this actor targeted well-known academics and Russian critics from at least April to early June 2025. They frequently used a lot of rapport-building and specially designed lures to persuade the target to create application-specific passwords (ASPs). The attackers have continuous access to the victim's email when th...
WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors
News

WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors

A widespread phishing campaign that targets WooCommerce customers by posing as a security alert and asking them to download a "critical patch" but really deploying a backdoor is being warned about by cybersecurity researchers. The activity, according to WordPress security firm Patchstack, was clever and a variation of a different operation that was noticed in December 2023 and used a phony CVE trick to compromise websites using the well-known content management system (CMS). The most recent attack wave is thought to be either the work of the same threat actor or a new cluster that closely resembles the previous one due to the similarities in the phishing email lures, the fake websites, and the identical techniques used to hide the malware read more about WooCommerce Users Targeted b...
Russian Star Blizzard Targets WhatsApp Accounts in New Spear-Phishing Campaign
News

Russian Star Blizzard Targets WhatsApp Accounts in New Spear-Phishing Campaign

A new spear-phishing campaign targeting victims' WhatsApp accounts has been attributed to the Russian threat actor Star Blizzard, which deviates from its usual tactics in an apparent effort to avoid detection. According to a Microsoft Threat Intelligence team report shared with The Hacker News, Star Blizzard's targets are typically related to government or diplomacy (both current and former position holders), defense policy or international relations researchers whose work touches on Russia, and sources of aid to Ukraine related to the war with Russia. A threat activity cluster associated with Russia, Star Blizzard (previously SEABORGIUM) is well-known for its credential harvesting efforts. It has been in operation since at least 2012 and is also known by the moniker Blue Callisto r...
New QR Code Phishing Campaign Exploits Microsoft Sway to Steal Credentials
News

New QR Code Phishing Campaign Exploits Microsoft Sway to Steal Credentials

Researchers in cybersecurity are alerting the public to a new campaign of QR code phishing, often known as quishing, which uses Microsoft Sway infrastructure to host phony websites. This underscores the misuse of trustworthy cloud services for malevolent intent. According to Jan Michael Alcantara, a researcher at Netskope Threat Labs, an attacker can help victims accept the content by employing genuine cloud applications, which give them legitimacy. A victim can also be convinced of the legitimacy of a Sway page by using their Microsoft 365 account, into which they are already logged in. Additionally, Sway can be shared via an iframe installed read more about New QR Code Phishing Campaign Exploits Microsoft Sway to Steal Credentials. Get up to date on the latest cybersecurity new...
Ukraine Warns of New Phishing Campaign Targeting Government Computers
News

Ukraine Warns of New Phishing Campaign Targeting Government Computers

The Computer Emergency Response Team of Ukraine (CERT-UA) has issued a warning regarding a recent phishing effort that disseminates malware with the ability to access remote desktops by impersonating the Security Service of Ukraine. Under the code UAC-0198, the organization is keeping tabs on the action. Since July 2024, an estimated 100 or more computers—including those connected to the nation's federal agencies—have become infested. Attack chains use a large-scale email distribution method to send a ZIP archive file that contains an MSI installer file, which when opened, releases malware known as ANONVNC. ANONVNC enables covert illegal access to the compromised computers and is based on the open-source remote management application MeshAgent read more about Ukraine Warns of New...