Showing posts with label Phishing Attack. Show all posts
Showing posts with label Phishing Attack. Show all posts

Hacker Steals $24.5 Million in Major Resolv DeFi Platform Breach

 



AI-Powered Phishing Surge Exploits Microsoft Authentication, Targets Thousands

In a concerning shift in cyberattack tactics, security researchers have uncovered a large-scale phishing campaign leveraging artificial intelligence to generate highly customized lures. The campaign, which intensified sharply in early March, is being described as one of the most aggressive and effective phishing operations seen in recent times.

Hackers Abuse Cloudflare and Zendesk Pages in Sophisticated Phishing Campaign

 


Hackers Exploit Cloudflare and Zendesk Pages in Sophisticated Phishing Campaign to Steal User Credentials

A new wave of phishing attacks is exploiting the credibility of trusted cloud platforms like Cloudflare Pages and Zendesk to execute large-scale credential theft operations. Security researchers have uncovered an elaborate infrastructure of malicious domains designed to impersonate legitimate customer support portals, revealing an alarming escalation in the use of reputable cloud services for social engineering.

Scam Alert: Toll Payment Texts Used in New Wave of Phishing Attacks

 


Toll Payment Text Scam Surges Again — What You Need to Know

A new wave of phishing scams is hitting mobile users across the U.S., as fraudsters impersonating toll authorities like E-ZPass, The Toll Roads, and FasTrak flood phones with fake payment texts. These scam messages are designed to trick you into handing over sensitive personal and financial details — and they're getting more sophisticated.

AWS Takes Down Russian APT29 Domains


 

AWS Seizes Domains Used by Russian Threat Group APT29 in Credential-Stealing Campaign

Amazon Web Services (AWS) has disrupted a phishing operation by seizing several domains used by APT29, a Russian state-linked threat group, in a campaign aimed at stealing credentials from what AWS described as "Russian adversaries." The malicious effort by APT29—also known as Midnight Blizzard, Cozy Bear, and Nobelium—targeted government agencies, enterprises, and military organizations with phishing emails written in Ukrainian, marking a broader reach than typical APT29 operations.

ESET Antivirus Breach: Israeli Partner Compromised in Major Cybersecurity Incident

 



Hackers Breach ESET’s Israel Partner, Sending Phishing Emails with Data Wipers

In a recent cybersecurity breach, hackers infiltrated the email server of Comsecure, ESET’s exclusive distributor in Israel, to launch a phishing campaign aimed at Israeli businesses. Disguised as legitimate antivirus software, the attackers used data wipers, malicious software designed to erase files and corrupt systems, posing a destructive threat.

Evilginx Unveiled: The Rise of Phishing-as-a-Service and Its Implications


Evilginx is an advanced phishing framework that has significantly altered the landscape of cyber threats. Originally designed for educational and research purposes, Evilginx allows security professionals to demonstrate the vulnerabilities in web authentication mechanisms. However, like many powerful tools, it has also been exploited for malicious purposes.

Evilginx operates as a man-in-the-middle (MitM) attack proxy, enabling attackers to intercept and capture login credentials and session cookies in real-time. This sophisticated phishing technique can deceive even the most vigilant users, making it a formidable tool in the hands of cybercriminals.

Phishing is an emerging and evolving threat


Phishing is an emerging threat that has become increasingly prevalent in recent years. The term "phishing" is used to describe a type of cyber attack in which criminals use social engineering techniques to trick individuals into providing sensitive information, such as login credentials or financial information. The information is then used for various criminal activities, including identity theft and financial fraud.

CISA published new infographic to increase awareness against the Phishing attack


Phishing is a constant and evolving threat to organizations and individuals and threat actors discover new tactics to increase their chances of success. It is important that organization or individuals follow certin SOP's to avoid falling in this so as to increase awareness CISA published a Phishing Infographic to help protect both organizations and individuals from successful phishing operations. 

OPERA1ER APT Active Cybercriminal Group Targeting Africa .


Recently Group-IB discover APT OPERA1ER Cybercriminal which operate from Africa and active from 5 years.

Group-IB Threat Intelligence team investigate targeted attack on financial Organizations in Africa including more than 30 attack and over 30 million USD estimated damage by this cyber criminal group in his five years of operation.

Group-IB attributed this to threat actor codename OPERA1ER (Other name DESKTOP GROUP ,Common Raven, NXSMS)

FIFA World Cup Qatar: Scammers exploit the global user interest, FIFA fans at risk!


22nd FIFA World Cup taken place at Qatar from November 20 to December 18 and nearly one billion people expected to watch this game. Cybercriminals never want to let this opportunity slip so we can see high number of credit card fraud, DDOS attack, APT campaign, Phishing, Identity theft by scammers and other cybercriminal during the event.


Cloudsek and Group-IB bot investigated this case and presented report on how scammers and other cybercriminal using this chance to get Financial gain from the gigantic fan base.

New 4 Phase phishing attack activly target cryptocurrency wallet users of Coinbase, MetaMask and Kucoin 2FA Bypass

Image Source: PIXM
 
Pixm cybersecurity company is tracking group which is currently active in the wild . This group targeting the users of cryptocurrency exchanges and wallets.According to pixm's Research team initially Group target only Coinbase users and over the last month the group increase their capabilities to cover more cryptocurrency exchange and wallets.

CYJAX uncover a sophisticated state sponsored larger scale phishing campaign


"Cyjax has investigated a sophisticated, large-scale phishing campaign that exploits the reputation of
international, trusted brands. It targets businesses in multiple verticals including retail, banking, travel,
and energy. Promised financial or physical incentives are used to trick victims into further spreading the
campaign via WhatsApp. Once victims are psychologically invested in the phish, they are redirected through

State-Sponsored Russian Cyber Campaign Targets Zimbra Email Users

  Russian State-Sponsored Threat Actors Exploit Zimbra Webmail in Sophisticated Phishing Campaign Cybersecurity agencies have issued a high-...