Phishing
Curated coverage and analysis in this editorial area.

Chinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America
Proofpoint has identified UNK_MassTraction, a suspected Chinese cluster, exploiting two Roundcube N-day vulnerabilities to compromise…

AssuranceAmerica: 7 Million Driver's Licenses Exposed, No Credit Monitoring Offered
A single compromised employee account opened access to nearly 7 million driver's license numbers. AssuranceAmerica is not offering cre…

Verified X Ads Spread Mac Malware and Steal Microsoft 365 Accounts
Active campaigns exploit X's blue verification badge to distribute Mac malware via ClickFix and steal Microsoft 365 OAuth tokens using…

RedWing: Android Banking Malware Turns into a Telegram Rental Service
Zimperium zLabs uncovered RedWing, a Malware-as-a-Service platform that commercializes Android banking fraud with Telegram bots and su…

China-Linked Exploit Chain Targets US and Canadian Universities via Roundcube
A suspected Chinese espionage cluster has compromised fewer than ten US and Canadian universities using a two-vulnerability chain in R…

Vishing 2.0 Hits Teams: Fake IT Support Calls Deploy EtherRAT
Palo Alto Networks Unit 42 uncovered a campaign that abuses Microsoft Teams voice calls to impersonate corporate IT support and trick…

Avalon: The Malware Framework Merging AI and Multi-Evasion to Strike
The Avalon framework combines credential harvesting, multi-EDR evasion, and the CrownX ransomware into a single attack chain. Blackpoi…

Interpol Ransomware: Small Businesses Targeted via Social Engineering
Threat actors are impersonating Interpol in a ransomware campaign hitting small businesses across pharmaceutical, food, agriculture, t…

VEIL#DROP: How Blogger Became an Infostealer Armorer
Securonix uncovers VEIL#DROP, a multi-stage malware chain that weaponizes Google Blogger to deliver the PureLogs Stealer filelessly, b…

ClickFix Evolves Into a Platform: Analysis of 3,000 Payloads Reveals API-Driven Delivery
A researcher analyzed 3,000 live ClickFix payloads, uncovering an API-driven architecture, rotating cryptographic wrappers, and adopti…

Phantom Squatting: When AI Generates Your Next Supply-Chain Threat
Unit 42 documents a novel attack vector: adversaries proactively register domains hallucinated by LLMs to intercept traffic from AI-in…

Health Card Phishing: €6.39 to Steal Your Identity
CERT-AGID exposes the funnel of an active phishing campaign impersonating the Italian Ministry of Health, using a fake mandatory healt…