Tag: Phishing campaigns

Phishing Campaigns Use Real-Time Checks to Validate Victim Emails Before Credential Theft
News

Phishing Campaigns Use Real-Time Checks to Validate Victim Emails Before Credential Theft

Researchers studying cybersecurity are drawing attention to a novel kind of credential phishing attempt that makes sure the stolen data is linked to legitimate online accounts. Cofense has dubbed the approach precision-validating phishing, claiming that it uses real-time email validation to ensure that the phony login screens are only shown to a limited number of high-value targets. Since the threat actors simply interact with a pre-harvested list of legitimate email accounts, this strategy not only increases their chances of gaining useable credentials, according to the business. In contrast to "spray-and-pray" credential harvesting attacks, which usually entail sending out large quantities of spam emails in an attempt to indiscriminately capture victims' login credentials read ...
Lucid PhaaS Hits 169 Targets in 88 Countries Using iMessage and RCS Smishing
News

Lucid PhaaS Hits 169 Targets in 88 Countries Using iMessage and RCS Smishing

The way Lucid circumvents conventional SMS-based detection methods by weaponizing trustworthy communication platforms is its unique selling proposition. In a technical analysis provided to The Hacker News, Swiss cybersecurity firm PRODAFT stated that its scalable, subscription-based approach allows attackers to carry out extensive phishing campaigns to obtain credit card information for financial crime. By utilizing Android's RCS technology and Apple iMessage, Lucid circumvents conventional SMS spam filters and greatly boosts delivery and success rates. According to assessments, Lucid was created by a Chinese-speaking hacker collective known as the XinXin gang (also known as Black Technology) read more about Lucid PhaaS Hits 169 Targets in 88 Countries Using iMessage and RCS Smis...
Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans
News

Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans

A new phishing effort has targeted Russian-speaking users, using the open-source phishing toolkit Gophish to spread DarkCrystal RAT (also known as DCRat) and PowerRAT, an unreported remote access trojan. According to a Tuesday analysis by Cisco Talos researcher Chetan Raghuprasad, the campaign uses modular infection chains that are either HTML-based or Maldoc-based infections and need the victim's interaction to start the infection chain. The language used in the phishing emails, the bait content in the malicious documents, links that pose as Yandex Disk ("disk-yandex[.]ru"), and HTML web pages that pose as VK, a social network that is mostly utilized in the nation, are all used to determine that Russian-speaking people are being targeted read more about Gophish Framework Used in Ph...
Latrodectus Malware Loader Emerges as IcedID’s Successor in Phishing Campaigns
News

Latrodectus Malware Loader Emerges as IcedID’s Successor in Phishing Campaigns

Beginning in early March 2024, cybersecurity researchers have noticed an increase in email phishing efforts that distribute Latrodectus, a newly developed malware loader that is thought to be the IcedID virus's successor. Researchers Daniel Stepanic and Samir Bousseaden of Elastic Security Labs stated that "these campaigns usually involve a recognizable infection chain involving oversized JavaScript files that utilize WMI's ability to invoke msiexec.exe and install a remotely-hosted MSI file, remotely hosted on a WEBDAV share." Latrodectus has the usual features one would anticipate from malware that is meant to release extra payloads like QakBot, DarkGate, and PikaBot, enabling threat actors to carry out a range of post-exploitation operations. A thorough examination of the most...
Monday.com removes “Share Update” feature abused for phishing attacks
News

Monday.com removes “Share Update” feature abused for phishing attacks

Monday.com, a project management software, has eliminated its "Share Update" feature due to misuse by malicious actors during phishing campaigns. With the use of automated processes and dashboards, teams can manage and organize their work with Monday.com, a cloud-based project management tool. Among the 225,000 users of the platform include Coca-Cola, Canva, LionsGate, Oxy, Compass, and Zippo. Customers of Monday.com informed BleepingComputer on Tuesday that they had received phishing emails from the company's email accounts and were worried that the company had been compromised. These emails, which originated from notifications@monday.com and were sent via SendGrid, successfully passed DKIM, DMARC, and SPF authentication. Under the guise of a "Human Resources" department, the...
NetSupport RAT Infections Targeting Government and Business Sectors
News

NetSupport RAT Infections Targeting Government and Business Sectors

With a remote access trojan called NetSupport RAT, threat actors are aiming their attacks at the business services, government, and education sectors. According to a report shared with The Hacker News by VMware Carbon Black researchers, "the delivery mechanisms for the NetSupport RAT encompass fraudulent updates, drive-by downloads, utilization of malware loaders (such as GHOSTPULSE) and various forms of phishing campaigns." In the past few weeks, the cybersecurity company claimed to have found at least 15 new NetSupport RAT-related infections. Although NetSupport Manager was initially intended to be a legitimate remote administration tool for technical help and support read more NetSupport RAT Infections Targeting Government and Business Sectors. Get up to date on the latest cyb...
IRS Phishing Emails Used to Distribute Emotet
News

IRS Phishing Emails Used to Distribute Emotet

Security professionals have cautioned US taxpayers not to fall for a fresh phishing scheme that uses the IRS as an enticement to install the nasty Trojan Emotet on their computers. Tax filing season has historically been a time for con artists to deceive consumers, and the most recent attempt discovered by Malwarebytes is no exception. The phishing emails in question include the subject "IRS Tax Forms W-9" and a counterfeit "IRS Online Center" sender address. In the email's body, there are numerous mistakes in the brief message read more IRS Phishing Emails Used to Distribute Emotet. Stay up-to-date with the latest cybersecurity news and increase your cybersecurity awareness through ReconBee.com‘s in-depth coverage of the newest threats, breaches, and solutions.