Tag: phishing campaign

New Poco RAT Targets Spanish-Speaking Victims in Phishing Campaign
News

New Poco RAT Targets Spanish-Speaking Victims in Phishing Campaign

From at least February 2024, victims speaking Spanish are the focus of an email phishing operation that distributes a brand-new remote access trojan (RAT) known as Poco RAT. According to cybersecurity firm Cofense, the attacks mostly target the mining, industrial, hotel, and utility sectors. According to the report, the bulk of the malware's custom code seems to be concentrated on anti-analysis, interacting with its command-and-control center (C2), downloading and executing files, with only a little amount of attention going toward monitoring or credential harvesting. Phishing emails with lures related to finance start infection chains by tricking recipients into clicking on an embedded URL that leads to a 7-Zip archive file stored on Google Drive read more about New Poco RAT Tar...
New Phishing Campaign Deploys WARMCOOKIE Backdoor Targeting Job Seekers
News

New Phishing Campaign Deploys WARMCOOKIE Backdoor Targeting Job Seekers

Researchers studying cybersecurity have made public the specifics of a continuous phishing effort that uses baits related to jobs and recruitment to spread the Windows backdoor WARMCOOKIE. According to a recent investigation by researcher Daniel Stepanic of Elastic Security Labs, "WARMCOOKIE appears to be an initial backdoor tool used to scout out victim networks and deploy additional payloads." "Each sample is compiled with a hard-coded [command-and-control] IP address and RC4 key." The backdoor may take screenshots, drop further malicious programs, and fingerprint compromised PCs. The action is being monitored by the company using the code REF6127. Since late April, assault chains have been noticed that utilize emails posing as correspondence from employment agencies such as Ha...
TA547 Phishing Attack Hits German Firms with Rhadamanthys Stealer
News

TA547 Phishing Attack Hits German Firms with Rhadamanthys Stealer

As part of a phishing campaign with an invoice theme, a threat actor identified as TA547 has used an information stealer known as Rhadamanthys to target numerous German firms. According to Proofpoint, this is the first time that researchers have seen TA547 use Rhadamanthys, an information stealer employed by a number of cybercriminal threat actors. Furthermore, it seems that the actor used a PowerShell script that was produced, presumably, by a large language model (LLM). A well-known and financially driven threat actor, TA547 has been active since at least November 2017. He distributes a wide range of malware for Windows and Android, including the ransomware Adhubllka, ZLoader, Gootkit, and Ursnif, via email phishing lures. The organization has developed into an initial access b...
New Phishing Campaign Targets Oil & Gas with Evolved Data-Stealing Malware
News

New Phishing Campaign Targets Oil & Gas with Evolved Data-Stealing Malware

Phishing efforts targeting the oil and gas industry are using a new version of the Rhadamanthys virus, which steals information. According to Cofense researcher Dylan Duncan, the phishing emails impersonate the Federal Bureau of Transportation in a PDF that references a sizable fee for the incident. They also employ a distinctive car incident lure in later stages of the infection chain. The email message contains a malicious link that, when clicked, downloads a ZIP package containing the stealer payload. The malicious link uses an open redirect fault to lead the recipients to a link that appears to be a PDF document. Rhadamanthys, a C++ program, is intended to connect to a command-and-control (C2) server and get private information from infected machines read more New Phishing Ca...
Massive Phishing Campaign Strikes Latin America: Venom RAT Targeting Multiple Sectors
News

Massive Phishing Campaign Strikes Latin America: Venom RAT Targeting Multiple Sectors

A new huge phishing campaign targeting Latin American industries in an attempt to deliver Venom RAT has been linked to the threat actor known as TA558,. The hotel, travel, trade, financial, industrial, manufacturing, and government sectors in Spain, Mexico, the United States, Colombia, Portugal, Brazil, the Dominican Republic, and Argentina were the main targets of the attacks. Being active since at least 2018, TA558 has a history of delivering a range of malware, including Loda RAT, Vjw0rm, and Revenge RAT, to targets in the LATAM region. Idan Tarab, a researcher from Perception Point, claims that the most recent infection chain uses phishing emails as a first point of entry to drop Venom RAT, a Quasar RAT fork with the ability to remotely take over devices and gather sensitive ...
Massive phishing campaign targets Zimbra users
News

Massive phishing campaign targets Zimbra users

A new phishing campaign that aims to steal the login information for Zimbra email accounts has been discovered by ESET researchers. Researchers claim that the campaign, which mostly targets small and medium-sized organisations and public entities, began in April of this year and is currently aggressively spreading. The countries with the most targets are Poland, Ecuador, and Italy. The threat actors behind the attacks have not been found as of yet. An email server and a web client are provided by the open-source collaborative software platform Zimbra Collaboration read more Massive phishing campaign targets Zimbra users. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threats, breaches, and soluti...
Meta support team impostors target celebrity Facebook accounts
News

Meta support team impostors target celebrity Facebook accounts

Today it was revealed that hackers posing as Facebook technical support staff members have been seen attempting to take over the accounts of famous users. Group-IB stated in a blog post published on April 25 that it found more than 3,200 bogus Facebook profiles, 1,200 of which had fraudulent messages purporting to be written by Meta's technical support staff, during the planned phishing campaign in February and March. The posts served as a ruse to use a well-known social engineering tactic, which involved convincing the victim to act quickly so their account wouldn't be "closed" by clicking on a malicious link read more Meta support team impostors target celebrity Facebook accounts. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cyb...
YouTube attribution links exploited in new phishing campaign
News

YouTube attribution links exploited in new phishing campaign

Cybersecurity company Vade said the use of YouTube attribution links was a new tactic for bypassing email filters scanning for suspicious redirects. In a newly discovered phishing campaign, victims receive a spoofed email saying their Microsoft 365 password has expired. The email is personalized and contextualized to create an illusion of legitimacy. Vade researchers noted that the email doesn’t contain misspellings or grammatical errors, which used to be a first telltale sign of a scam. Below the notice of the allegedly expired password, there’s an option for the victim to keep their current password. The button, hyperlinked to a YouTube URL eventually redirects users to a phishing page read more YouTube attribution links exploited in new phishing campaign. With ReconBee.com ...
Major Phishing Campaign Targets Trezor Crypto Wallets
News

Major Phishing Campaign Targets Trezor Crypto Wallets

An ongoing multi-channel phishing attempt aimed at tricking users into allowing access to their wallets has been acknowledged by cryptocurrency hardware company Trezor. In a tweet, the company issued a warning: "The attackers contact the victims by phone call, SMS, and/or email to suggest that there has been a security breach or suspicious activity on their Trezor account. "We did not discover any proof of a recent database intrusion. You won't ever get calls or SMS messages from us. Hardware-based wallets are offered by Trezor allowing consumers to store their cryptocurrencies read more Major Phishing Campaign Targets Trezor Crypto Wallets. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threa...