Security News

FatalRAT Phishing Attacks Target APAC Industries Using Chinese Cloud Services
2025-02-25 05:51

Various industrial organizations in the Asia-Pacific (APAC) region have been targeted as part of phishing attacks designed to deliver a known malware called FatalRAT. "The threat was orchestrated...

Beware: PayPal "New Address" feature abused to send phishing emails
2025-02-22 21:01

An ongoing PayPal email scam exploits the platform's address settings to send fake purchase notifications, tricking users into granting remote access to scammers [...]

Darcula allows tech-illiterate crooks to create, deploy DIY phishing kits targeting any brand
2025-02-20 11:34

A new, improved version of Darcula, a cat-themed phishing-as-a-service (PhaaS) platform aimed at serving Chinese-speaking criminals, will be released this month and will allow malicious users to...

Darcula PhaaS can now auto-generate phishing kits for any brand
2025-02-20 11:00

The Darcula phishing-as-a-service (PhaaS) platform is preparing to release its third major version, with one of the highlighted features, the ability to create do-it-yourself phishing kits to...

Phishing attack hides JavaScript using invisible Unicode trick
2025-02-19 20:14

A new JavaScript obfuscation method utilizing invisible Unicode characters to represent binary values is being actively abused in phishing attacks targeting affiliates of an American political...

Device Code Phishing
2025-02-19 15:07

This isn’t new, but it’s increasingly popular: The technique is known as device code phishing. It exploits “device code flow,” a form of authentication formalized in the industry-wide OAuth...

Darktrace: 96% of Phishing Attacks in 2024 Exploited Trusted Domains Including SharePoint & Zoom Docs
2025-02-19 14:00

The cyber security firm reported in its latest annual report that their researchers found more than 30.4 million phishing emails last year.

Russian phishing campaigns exploit Signal's device-linking feature
2025-02-19 11:59

Russian threat actors have been launching phishing campaigns that exploit the legitimate "Linked Devices" feature in the Signal messaging app to gain unauthorized access to accounts of interest. [...]

Microsoft: Hackers steal emails in device code phishing attacks
2025-02-15 15:22

An active campaign from a threat actor potentially linked to Russia is targeting Microsoft 365 accounts of individuals at organizations of interest using device code phishing. [...]

Microsoft: Russian-Linked Hackers Using 'Device Code Phishing' to Hijack Accounts
2025-02-14 10:27

Microsoft is calling attention to an emerging threat cluster it calls Storm-2372 that has been attributed to a new set of cyber attacks aimed at a variety of sectors since August 2024. The attacks...