Phishing
Curated coverage and analysis in this editorial area.

Mustang Panda Turns Zoho WorkDrive Into Covert C2 Channel Against Indian Government
The Mustang Panda APT group ran two espionage campaigns in June 2026 targeting the Indian government and hydroelectric infrastructure,…

Gamaredon 2025: 35 Spear-Phishing Campaigns and 6 PowerShell Tools Target Ukraine
The Gamaredon APT group, attributed by Ukraine's SSU to the FSB's 18th Center for Information Security, launched 35 distinct spear-phi…

SBU and FBI Expose Russian Social-Engineering Campaign Targeting Signal and WhatsApp Accounts
Ukraine's SBU and the FBI disclosed a long-running Russian operation that uses morning-timed SMS phishing to steal verification codes…

Shopify's Shop App Abused for Callback Phishing, 50 Million Users at Risk
Fake invoices with phone numbers are being injected into the Shopify Shop app. Researchers say the insertion mechanism remains unknown…

'Snoopy' Sentenced: 18 Months for the Massive DraftKings Hack
Nathan Austad, known as 'Snoopy,' received an 18-month federal prison sentence for orchestrating the November 2022 credential-stuffing…

Mistic: KongTuke's In-Memory Backdoor Challenges EDR Defenses
Operational since April 2026, the stealthy Mistic backdoor leverages DLL sideloading and in-memory BOF execution for long-term persist…

LastPass Breached via Klue Supply-Chain Attack: Customer Data Stolen, Vaults Intact
LastPass confirms a supply-chain breach through market-intelligence vendor Klue: stolen OAuth tokens granted access to LastPass's Sale…

London Hydro Breach Exposes 160k Customers, Fuels Targeted Phishing Risk
London Hydro disclosed a data breach on June 20. Customer account data was exposed — no payment cards — but the details are ideal for…

Xsolis Phishing Breach Exposes 1.4 Million PHI Records
Xsolis took five months to disclose the full scope of a January 2026 phishing attack. The HHS breach tracker revealed 1,396,519 affect…

OXLOADER: Malicious Google Ads Deliver Infostealer
Elastic Security Labs uncovers OXLOADER, a previously undocumented Windows loader distributed via malicious Google Ads impersonating N…

WhatsApp Weaponized: VBS and RMM Delivered via DMs from Compromised Contacts
An active campaign since June 2026 uses WhatsApp Desktop to distribute malicious VBScript files, install legitimate RMM software, and…

Tax Scam Impersonates the State: Adaptive Phishing Targets Crypto and Bank Accounts
CERT-AGID has detected active phishing campaigns abusing the name, logo, and branding of Italy's Agenzia delle Entrate to trick victim…