Tagged: Social Engineering
Adversaries have intensified their offensives against Facebook users by deploying one of the most inconspicuous and treacherous phishing methodologies of recent years. Cybersecurity specialists at Trellix have observed a surge in campaigns utilizing “Browser-in-the-Browser”...
Fraudulent investment stratagems are increasingly assuming a hyper-realistic façade, meticulously augmented by the advancements of artificial intelligence. Researchers at Check Point have delineated a sophisticated new campaign wherein adversaries construct an entirely fabricated milieu,...
A sophisticated malware campaign has surfaced in Brazil, leveraging the ubiquity of WhatsApp to propagate the Astaroth banking trojan. This delivery vector has proven exceptionally potent given the application’s cultural and commercial dominance in...
Cyber adversaries have conceived an ingenious method to circumvent the security protocols utilized by email services to intercept malicious QR codes. Rather than employing conventional image files, they have begun disseminating QR codes constructed...
Notifications regarding Booking.com cancellations involving substantial financial transactions appear as mere routine for hospitality providers. Yet, such correspondence serves as the harbinger for a sophisticated malicious campaign tracked by Securonix researchers under the moniker...
Coinbase has reported the first arrests in its investigation into the sale of customer data: police in Hyderabad, India, have detained a former exchange support employee suspected of accepting bribes and handing customer records...
Fraudulent job advertisements promising easy income and remote work continue to flood social media platforms, particularly across the Middle East and North Africa. Disguised as no-experience side gigs, these schemes are designed to harvest...
Within cybercriminal circles, interest in recruiting insiders from within companies is surging. Rather than mounting complex external intrusions, attackers are increasingly betting on internal sources—employees willing, for a price, to grant access to corporate...
Researchers at Gen have reported a new WhatsApp account-takeover technique dubbed GhostPairing. The attack appears mundane and arouses little suspicion, yet it ultimately grants attackers full access to a victim’s chats, media files, and...
A scheme is gaining momentum worldwide in which doxers impersonate police officers and use so-called “emergency requests” to coerce major companies into disclosing private personal data within minutes. On September 4, for example, an...
A new technique dubbed “ConsentFix” expands upon the already known ClickFix social engineering attack, enabling the hijacking of Microsoft accounts without passwords or multi-factor authentication. To achieve this, attackers exploit the legitimate Azure CLI...
Researcher ZachXBT has stated that a British national implicated in the major $243 million cryptocurrency breach involving lender Genesis may have been detained in Dubai. According to him, the individual in question is known...