Tag: phishing

Phishing poses as big-brand job interview to steal Google accounts
News

Phishing poses as big-brand job interview to steal Google accounts

In order to obtain Google account credentials from marketing professionals, a phishing effort is posing as more than thirty well-known companies, such as Adobe, Netflix, Coca-Cola, and OpenAI, in fictitious job interviews. Before sending the receiver to a malicious landing site, the operation abuses a domain connected to the Salesforce Marketing Cloud service and the legal cloud-based PeopleForce human resources platform. The threat actor is exploiting the names and images of actual recruiters at fictitious companies in order to further foster trust and boost the likelihood of success. After analyzing the campaign, Will Thomas, senior advisor at cybersecurity intelligence and threat hunting firm Team Cymru, found that the phishing email poses as a recruiter seeking candidates for...
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
News

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Web addresses that don't exist are constantly being created by large language models. In order to obtain traffic that AI tools direct to them, attackers have begun purchasing those fictitious domains before anybody else can, then hosting phishing pages on them. The tactic known as "phantom squatting" is already occurring in the wild, according to new research from Palo Alto Networks' Unit 42. Trust is the reason it counts. The links that a model returns are increasingly regarded as authentic by developers and AI helpers. When a model creates a brand-new domain, all of that mistaken faith is transferred to the first person to register it; phishing emails and dangerous advertisements are not necessary. Unit 42 asked two AI models 685,339 questions regarding 913 well-known businesse...
Microsoft Teams phishing targets employees with A0Backdoor malware
News

Microsoft Teams phishing targets employees with A0Backdoor malware

Employees at financial and healthcare institutions were approached by hackers via Microsoft Teams in order to deceive them into allowing remote access via Quick Assist and install a brand-new malware known as A0Backdoor. By first bombarding the employee's inbox with spam and then contacting them over Teams while posing as the company's IT team and offering help with the unwanted communications, the attacker uses social engineering to acquire the employee's trust. The threat actor tells the user to launch a Quick Assist remote session in order to gain access to the target machine. This allows the malicious toolkit, which includes digitally signed MSI installers hosted in a personal Microsoft cloud storage account, to be deployed. Researchers at the cybersecurity firm BlueVoyant cl...
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
News

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

Using a Rust-based implant nicknamed RustyWater, the Iranian threat actor known as MuddyWater has been linked to a spear-phishing campaign that targets Middle Eastern financial, telecom, marine, and diplomatic organizations. According to a report released this week by CloudSEK resetter Prajwal Awasthi, the campaign delivers Rust-based implants with asynchronous C2, anti-analysis, registry persistence, and modular post-compromise capability augmentation using icon spoofing and malicious Word documents. The most recent development is indicative of the ongoing evolution of MuddyWater's tradecraft, which has steadily but gradually decreased its reliance on reputable remote access software as a post-exploitation tool in favor of a varied custom malware arsenal that includes tools like re...
27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials
News

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

Details of a "sustained and targeted" spear-phishing attack that published more than two dozen packages to the npm registry to enable credential theft have been made public by cybersecurity researchers. According to Socket, the activity, which included uploading 27 npm packages from six distinct npm aliases, has mostly targeted sales and commercial staff at critical infrastructure-adjacent firms in the United States and Allied countries. Researchers Nicholas Anderson and Kirill Boychenko reported that a five-month operation transformed 27 npm packages into robust hosting for browser-run lures that imitate Microsoft sign-in and document-sharing portals, targeting 25 companies in the manufacturing, industrial automation, plastics, and healthcare sectors for credential theft. The na...
Phishing emails increasingly use SVG attachments to evade detection
News

Phishing emails increasingly use SVG attachments to evade detection

Scalable Vector Graphics (SVG) attachments are being used more often by threat actors to distribute malware or show phishing forms without being discovered. JPG and PNG files, which are composed of grids of tiny squares called pixels, make up the majority of photos on the internet. The entire image is made up of pixels, each of which has a distinct color value. Scalable Vector Graphics, or SVG, uses lines, shapes, and text that are described in textual mathematical formulas in the code to make graphics rather than pixels read more about Phishing emails increasingly use SVG attachments to evade detection. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
Ukraine Warns of New Phishing Campaign Targeting Government Computers
News

Ukraine Warns of New Phishing Campaign Targeting Government Computers

The Computer Emergency Response Team of Ukraine (CERT-UA) has issued a warning regarding a recent phishing effort that disseminates malware with the ability to access remote desktops by impersonating the Security Service of Ukraine. Under the code UAC-0198, the organization is keeping tabs on the action. Since July 2024, an estimated 100 or more computers—including those connected to the nation's federal agencies—have become infested. Attack chains use a large-scale email distribution method to send a ZIP archive file that contains an MSI installer file, which when opened, releases malware known as ANONVNC. ANONVNC enables covert illegal access to the compromised computers and is based on the open-source remote management application MeshAgent read more about Ukraine Warns of New...
New Phishing Scam Uses Google Drawings and WhatsApp Shortened Links
News

New Phishing Scam Uses Google Drawings and WhatsApp Shortened Links

Researchers studying cybersecurity have uncovered a brand-new phishing effort that uses Google Drawings and shortened URLs created by WhatsApp to avoid detection and fool people into clicking on false links intended to steal personal data. Menlo Security researcher Ashwin Vamshi claimed that the attackers used a collection of well-known computer websites to create the threat. These included Google and WhatsApp, which hosted the attack pieces, as well as an Amazon clone that collected the victim's data. "This attack is a great example of a Living Off Trusted Sites (LoTS) threat." The assault begins with a phishing email that sends recipients to a picture that looks to be a link for verifying their Amazon account read more about New Phishing Scam Uses Google Drawings and WhatsApp Shor...
Millions of Docker repos found pushing malware and phishing sites
News

Millions of Docker repos found pushing malware and phishing sites

Since early 2021, three extensive attacks have targeted users of Docker Hub, infecting millions of repositories with malware and phishing websites. About 20% of the 15 million repositories hosted by Docker Hub had malicious information, ranging from spam to harmful malware and phishing websites, as discovered by JFrog security researchers. The researchers linked over 2.81 million repositories to three significant harmful campaigns and found nearly 4.6 million repositories without Docker images, which could not be used with a Kubernetes cluster or a Docker engine. Different strategies were employed by each of these efforts to produce and disseminate the malicious repositories. While the "Website SEO" campaign established a few phony repositories per day and employed a single user ...