-
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardmen…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Kaspersky details how the newly named Armored Likho APT uses BusySnake Stealer, AI-generated loaders, and phishing to target government and energy organizations.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A targeted phishing campaign impersonating the Indian Income Tax Department has been observed delivering a sophisticated, six-stage infection chain that culminates in two in-memory remote-access implants: a Gh0st RAT derivative and a Quasar/AsyncRAT-fa…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A targeted spear-phishing campaign that configures AnyDesk for silent, persistent remote access and exfiltrates its configuration using the Blat SMTP utility. The campaign uses an aerospace-themed invoice lure that impersonates the Russian research ins…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated interview-themed phishing campaign that impersonates major global brands to harvest Gmail credentials. Attackers pose as recruiters offering marketing roles at well-known companies, leveraging personalized targeting and a layered redire…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated email phishing campaign exploiting the global excitement around the 2026 FIFA World Cup is deceiving fans with counterfeit reward pages designed to harvest credit card information rather than deliver promised prizes. The scam initiates …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated phishing campaign that uses a fake invoice PDF to mask the delivery of multiple remote access trojans primarily AsyncRAT, but also VenomRAT and XWorm via layered shortcuts. TryCloudflare quick tunnels, and disguised Python packages. The…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A routine threat-feed alert for a RedLine Stealer command-and-control (C2) IP morphed into a full-scale pivot investigation that exposed a tailored maritime spear‑phishing and business email compromise (BEC) ecosystem. The starting signal a UniqueSigna…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An emergent supply-chain attack vector they term “phantom squatting,” in which large language models (LLMs) routinely hallucinate plausible but nonexistent domains for legitimate brands and adversaries then preemptively register those domai…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
EvilTokens phishing hides takeover clues until browser execution leaving SOC teams needing deeper visibility to validate threats faster and reduce account risk.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


