Phishing
Curated coverage and analysis in this editorial area.

Android Malware Impersonates Indeed: Spyware and Anti-Uninstall via Accessibility
Malwarebytes analyzed fake Android apps impersonating Indeed for job interviews. The Trojan droppers install spyware, seize device con…

InstallFix Campaign Clones Claude Code to Spread Malware Without Exploits
Cybercriminals are using malvertising and cloned sites to distribute stealers and backdoors. The attack exploits no software vulnerabi…

McKesson in ShinyHunters' Crosshairs: 284 Million Records and a $55 Million Ransom
McKesson disclosed a security incident involving unauthorized access to third-party applications. The ShinyHunters group claims to hav…

BlueDelta Refines HEADLACE: HOOKEDGE Backdoor Abuses Legitimate Webhook Services
The BlueDelta group has used macro-laced Word documents to distribute HOOKEDGE, a batch-script backdoor that leverages webhook.site fo…

Bug in JavaScript Obfuscator Exposes Polymorphic Phishing Campaign
A server-side scope error in an obfuscator triggered infinite loops in 3.6% of variants, revealing a polymorphic evasion mechanism tha…

Mirage2FA: AiTM Phishing Kit Hits 3,500 Organizations, Bypasses MFA on Microsoft 365
The Mirage2FA phishing-as-a-service kit, operated by LinX Coders, has targeted over 3,500 organizations using Adversary-in-the-Middle…

DOUBLECUP: The Fake Steganography That Exposes Criminal Payloads to a Simple grep
The DOUBLECUP loader promises advanced steganography but hides PowerShell code in plaintext after the PNG file. Extractable with FINDS…

Windows: Localized Filename Bug Steals NTLM Credentials with a Single Click
CVE-2026-50508: A flaw in Windows localized filenames enables NTLM hash theft simply by opening a file or visiting a web page. Microso…

SilkParasite Exposes the Line Between AI-Assisted and AI-Generated Malware
Bitdefender uncovered SilkParasite, a cyber-espionage campaign using seven RAT families and AI-assisted development to target governme…

SynkLoader: The 'Kitchen Sink' Malware Attacking via Microsoft Teams
Expel researchers have uncovered SynkLoader, a modular, multi-language malware family that uses Microsoft Teams phishing to breach cor…

North Korea’s Famous Chollima Behind 47% of State-Backed Tech Attacks
The North Korean group Famous Chollima carried out 47% of all state-sponsored attacks against the technology sector in one year, using…

UNC6671: Personal Phones Become the Gateway to Steal SaaS Data
The UNC6671 group uses vishing on personal smartphones to bypass MFA and steal SaaS sessions. Google has tracked over $10 million in e…