home.social

#credential-harvesting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #credential-harvesting, aggregated by home.social.

fetched live
  1. Web3 Enables Sophisticated Cloud Supply Chain Attacks

    Malware authors are now using blockchain technology to launch devastating cloud supply chain attacks, as seen in the ChainDrop attack that infected over 400 npm packages. This sneaky tactic uses a custom runtime to launch a credential harvester, allowing attackers to capture sensitive cloud provider IAM keys and more.

    osintsights.com/web3-enables-s

    #Web3 #CloudSupplyChain #Npm #MalwareOperations #CredentialHarvesting

  2. FBI Warns of Ongoing FortiBleed Attacks Targeting Fortinet VPN Admins

    Tens of thousands of Fortinet FortiGate firewalls and SSL VPN gateways are under active attack by hackers leveraging a massive June credential leak, putting countless networks at risk of disruption. The breach, known as FortiBleed, exposed a staggering 73,932 firewall URLs across 194 countries, giving attackers a…

    osintsights.com/fbi-warns-of-o

    #Fortibleed #Fortinet #VpnAttacks #CredentialHarvesting #FirewallVulnerabilities

  3. FBI Warns of Ongoing FortiBleed Threat Targeting Fortinet Devices

    The FortiBleed threat is still on the loose, putting 86,644 vulnerable Fortinet devices across 194 countries at risk of being compromised, with attackers exploiting reused credentials and weak password storage to gain control.

    osintsights.com/fbi-warns-of-o

    #Fortibleed #Fortinet #EmergingThreats #CredentialHarvesting #VpnExploitation

  4. Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access

    Attackers who gain access to AWS credentials perform validation to determine their usefulness, particularly for Amazon Bedrock access. Multiple credential harvesting platforms, including KMON_NOC, have been identified that specifically test stolen AWS keys for LLM capabilities. These platforms validate credentials using GetCallerIdentity, then test Bedrock access through ListFoundationModels and Converse API calls. The validation process helps attackers assess credential value for resale in token-jacking markets, where stolen AI model access is sold below retail price. Scripts analyzed on VirusTotal demonstrate systematic testing across multiple regions, targeting Anthropic Claude models specifically, and enumerating promotional credits to assess financial value. This represents an evolution in credential validation similar to historical patterns observed with AWS SES/SNS services.

    Pulse ID: 6ac52c8896a61ee777d4aee5
    Pulse Link: otx.alienvault.com/pulse/6ac52
    Pulse Author: AlienVault
    Created: 2026-10-06 17:14:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amazon #AWS #CredentialHarvesting #VirusTotal #OTX #AlienVault

  5. Iranian State-Aligned Threat Actor Masquerading as Dubai Airports IT Department Delivering Trojanized Coding Challenges - Blinder Tunnel Campaign Targeting Iraqi Critical Infrastructure

    An Iranian state-aligned threat actor designated as CL-STA-1178 has been impersonating the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. The Blinder Tunnel campaign, active since November 2025 with attacks intensifying in March 2026, primarily targeted Iraqi critical infrastructure. The operation employs a three-step attack chain exploiting legitimate Windows developer files, AppDomainManager hijacking, and DLL sideloading to deploy ShelbyLoader V2 malware. Attackers abuse GitHub API infrastructure for command-and-control communications, utilizing repositories for decryption keys, payload downloads, and GitHub issues as fallback mechanisms. The campaign incorporates Peaky Blinders television show themes in its infrastructure naming and embeds the show's theme song in malware. Operational security failures exposed connections to a separate credential harvesting operation targeting Israeli entities using conflict-themed Google Drive lures during May-June 2026.

    Pulse ID: 6ac6152430b84019d1fded71
    Pulse Link: otx.alienvault.com/pulse/6ac61
    Pulse Author: AlienVault
    Created: 2026-10-07 09:47:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #Deliver #Deploy #GitHub #OTX #AlienVault

  6. FBI Warns of Ongoing FortiBleed Threat

    The FBI and Secret Service are warning organizations that the FortiBleed threat is still active and can have a devastating impact, locking you out of your own systems if attackers disable accounts or change passwords. This is more than just a simple credential theft - it's a serious security risk that requires immediate attention.

    osintsights.com/fbi-warns-of-o

    #Fortibleed #VpnGateway #Firewall #CredentialHarvesting #AdministrativeAccess

  7. Gentlemen Ransomware Campaign Abuses MCP for Command Execution

    Gentlemen ransomware affiliate Azazel abused Model Context Protocol
    (MCP) tooling as a command and control channel during live intrusions. The
    campaign targeted GitLab secrets, credentials and cloud infrastructure, using
    MCP-based command execution, credential harvesting, data exfiltration and
    destructive actions across compromised environments.

    Pulse ID: 6ac56b9663bd025854777de2
    Pulse Link: otx.alienvault.com/pulse/6ac56
    Pulse Author: cryptocti
    Created: 2026-10-06 21:43:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Gentlemen #RansomWare #Cloud #CredentialHarvesting #OTX #cryptocti

  8. Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel

    Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users. The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code […] The post Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel appeared first on Cyber Security News .

    Pulse ID: 6abfc5f68ae4b5eaef02990e
    Pulse Link: otx.alienvault.com/pulse/6abfc
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 14:55:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #SQL #Microsoft #CredentialHarvesting #OTX #CyberHunter_NL

  9. Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers

    A threat actor compromised three web servers hosting recreation management software for municipalities and parks organizations by exploiting a file upload vulnerability. After multiple failed exploitation attempts, the attacker registered legitimate accounts and abused the member file upload function to deploy webshells. The attacker enumerated systems, extracted database credentials, and targeted payment card data from Fortis webhook logs. User-agent strings indicate Chinese origin, with suspected AI-generated scripts throughout the operation. The adversary adapted tactics across compromises, employing timestomping and file masquerading for defense evasion. When one server returned to production prematurely, the attacker injected a trojanized jQuery file into authentication pages, establishing WebRTC and WebSocket channels for credential harvesting via Cloudflare Workers infrastructure.

    Pulse ID: 6abf5aa04b47ef1458d7472a
    Pulse Link: otx.alienvault.com/pulse/6abf5
    Pulse Author: AlienVault
    Created: 2026-10-02 07:17:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CredentialHarvesting #Deploy #OTX #AlienVault

  10. Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline

    A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...

    Pulse ID: 6aba46a30e26418fb09c6000
    Pulse Link: otx.alienvault.com/pulse/6aba4
    Pulse Author: AlienVault
    Created: 2026-09-28 10:51:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault

  11. The Closed Quorum: Inside the first reported autonomous AI C2 implant

    CLOSEDQUORUM is a Windows malware binary representing the first documented implant utilizing autonomous AI-driven command and control. Discovered through Cisco Talos' CAIRN project, it delegates tactical decisions to a panel of commercial large language models including DeepSeek, Qwen, Mistral, and Google Gemini. The system operates through plurality voting among AI models to select actions for credential harvesting and crypto wallet theft, eliminating the need for continuous human operator involvement. The 16.4MB Go-compiled executable employs structured JSON schema to constrain LLM responses to executable attack choices. While containing placeholder credentials in public distribution, development builds demonstrate compile-time injection of operator-specific API keys and Discord webhooks. This architecture represents a significant shift toward effort displacement in cyber operations, where entire attack phases execute autonomously without human bottlenecks, though introducing new dependencies on commerci...

    Pulse ID: 6ab2681b40bfd39454369b4f
    Pulse Link: otx.alienvault.com/pulse/6ab26
    Pulse Author: AlienVault
    Created: 2026-09-22 11:35:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cisco #CredentialHarvesting #Discord #Google #OTX #AlienVault

  12. AI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distribution

    This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations.

    Pulse ID: 6ab22dd5026bef69ef5a17fd
    Pulse Link: otx.alienvault.com/pulse/6ab22
    Pulse Author: AlienVault
    Created: 2026-09-22 07:27:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #CredentialHarvesting #SocialEngineering #SupplyChain #OTX #AlienVault

  13. North Korea Exploits Job Seekers to Infect 30,000 Devices

    North Korean hackers have compromised over 30,000 devices by posing as recruiters, targeting unsuspecting job seekers with a clever ruse that steals sensitive information and cryptocurrency. By exploiting stolen IDs, these cybercriminals can impersonate victims and generate foreign currency, ultimately funding the regime.

    osintsights.com/north-korea-ex

    #NorthKorea #Waterplum #JobScams #CredentialHarvesting #CryptocurrencyTheft

  14. Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

    In August 2026, the Pakistan-nexus threat actor APT36 launched Operation RapidRust, targeting government and defense organizations in India and Afghanistan with an updated arsenal of custom tools. The campaign introduced RUSTYSHADE, a Rust-based backdoor leveraging private GitHub repositories for command-and-control with AES-256-GCM encryption. Additional tools included RUSTYMOVE for USB-based lateral movement to air-gapped networks, PSNATCH and BASHNATCH for file exfiltration from Windows and Linux systems respectively. The attackers registered typosquatted domains impersonating Indian news outlets to stage malicious PowerShell scripts. Post-compromise activities revealed systematic network reconnaissance, credential harvesting, and lateral movement attempts, with operations conducted exclusively on weekdays between 4:00-11:00 UTC, demonstrating disciplined operational security and sustained targeting of South Asian government infrastructure.

    Pulse ID: 6aaaca963a639dd0475e8462
    Pulse Link: otx.alienvault.com/pulse/6aaac
    Pulse Author: AlienVault
    Created: 2026-09-16 16:57:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #BackDoor #CredentialHarvesting #GitHub #OTX #AlienVault

  15. Thai Broadband Provider Targeted via FortiGate SSL-VPN and MeshCentral Persistence

    An exposed directory on a Thai server revealed an active intrusion campaign targeting 3BB (Triple T Broadband), one of Thailand's largest broadband providers. The attacker exploited CVE-2024-21762 in a FortiGate 60F SSL-VPN appliance to gain initial access, then deployed MeshCentral remote management software for persistent command-and-control. The operation involved extensive reconnaissance, credential harvesting targeting RADIUS authentication databases, privilege escalation using PwnKit and Dirty COW exploits, lateral movement via SSH brute-forcing across 55+ internal hosts, and anti-forensic cleanup procedures. Multiple devices were already enrolled under attacker control at discovery, with additional targeting of Jasmine International infrastructure. The attacker's toolkit included web application exploitation scripts, database credential extraction tools, and persistence mechanisms designed to maintain long-term access to subscriber authentication systems.

    Pulse ID: 6aa84f430eb4651668636168
    Pulse Link: otx.alienvault.com/pulse/6aa84
    Pulse Author: AlienVault
    Created: 2026-09-14 19:47:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #SSL #VPN #CVE202421762 #CredentialHarvesting #OTX #AlienVault

  16. The Death of Trust: Why Adversary-in-the-Middle and QR Attacks Are Gutting Corporate Defenses

    1,408 words, 7 minutes read time.

    We have built our enterprise security perimeters on a foundation of sand, and the storm has finally arrived. For years, security leadership assured stakeholders that multi-factor authentication was the ultimate shield against unauthorized entry. That comfort was a lie, born of complacency and soft thinking. Threat actors have evolved past simple credential harvesting; they are actively deploying Adversary-in-the-Middle (AiTM) phishing frameworks and zero-visibility QR code vectors that bypass legacy defenses without breaking a single line of code. We watched the systems fail because we relied on passive compliance rather than uncompromising operational discipline.

    The modern attack landscape does not care about our corporate policy manuals or annual security awareness videos. According to data tracked by Microsoft Threat Intelligence and the Cybersecurity and Infrastructure Security Agency (CISA), targeted organizations face an unprecedented surge in AiTM token hijacking and image-embedded QR phishing campaigns designed specifically to bypass secure email gateways. Threat actors set up reverse-proxy infrastructure that sits directly between our users and legitimate authentication endpoints. When our workforce logs in, the attacker proxies the request, steals the authenticated session cookie in real time, and walks straight through the front door.

    We must strip away the illusion that traditional defensive controls are keeping us safe. The rise of hybrid voice-and-email callback attacks and CAPTCHA-gated phishing infrastructure proves that attackers are exploiting the exact gaps we left open through institutional laziness. This deep-dive analysis confronts the mechanical realities of modern social engineering, dissects the failure of static multi-factor authentication, and lays out the hard architecture required to survive.

    The Mechanics of Session Hijacking: How Reverse Proxies Bypass Legacy MFA

    We need to understand the structural failure occurring at the authentication layer. Legacy multi-factor authentication relies on push notifications, SMS codes, or time-based one-time passwords (TOTP) to verify identity. Threat actors bypass these controls entirely by utilizing advanced AiTM phishing proxies like EvilGinx. The attack vector does not attempt to break encryption algorithms or crack complex passwords; it simply manipulates the human operating the endpoint into handing over full access.

    The process is surgically precise and brutally efficient. An employee receives a high-urgency communication, often mimicking internal human resources or critical SaaS infrastructure. The link inside routes the target to an attacker-controlled proxy server that dynamically mirrors the organization’s real login portal in real time. As the employee inputs their primary credentials and completes the secondary MFA challenge, the proxy server relays those packets directly to the legitimate service provider.

    Once the service provider authenticates the session, it issues a session token or authentication cookie back to the user. Because that traffic flows directly through the adversary’s proxy, the attacker captures the live session token instantaneously. The attacker then injects that session token into their own browser, instantly hijacking the active, fully authenticated corporate session without ever needing to know the user’s password or possess their physical MFA token. We must realize that the authentication process completed successfully in the eyes of the server, yet the enterprise was compromised entirely.

    Blind Spots in the Perimeter: The Rise of Image-Based Quishing and TOAD Attacks

    We have allowed our perimeter defenses to become completely blind to non-traditional attack vectors. Standard secure email gateways spend massive compute resources scanning incoming plain-text URLs and parsing standard attachments for known malicious signatures. Cybercriminals recognize this dependency and have adapted by shifting their payloads into optical and multi-channel vectors that bypass automated text-scanning engines entirely.

    QR code phishing, known colloquially as quishing, represents a massive operational vulnerability across corporate environments. Attackers embed malicious authentication URLs inside image-based QR codes wrapped within benign PDF documents or inline email bodies. Traditional email filters read the image as harmless static graphic data, allowing the message to land directly in the victim’s inbox. The target is instructed to scan the code using a personal mobile device to complete an mandatory system update or open a secure document.

    This action immediately forces the target off our managed corporate network and onto an unmonitored mobile device that lacks endpoint detection and response (EDR) agents. From there, the mobile browser connects to the AiTM proxy framework, and the session is compromised out of sight of internal security operations. Simultaneously, Telephone-Oriented Attack Delivery (TOAD) campaigns combine fake subscription invoices with live callback centers. When employees call the listed support number, live operators leverage high-urgency social engineering to guide targets through manual credential entry or remote control software installation. The system fails because we trained our people to look for suspicious links while leaving them exposed to visual and verbal exploitation.

    Engineering Absolute Resistance: Deploying FIDO2 and Zero-Trust Architecture

    We cannot solve an architectural flaw with soft solutions like additional compliance training or stern warning banners. Human error under psychological manipulation is an inevitable reality; therefore, our technical controls must enforce absolute resistance at the protocol level. We must eliminate push-based and TOTP-based authentication schemes in favor of hardware-bound, phishing-resistant credentials based on FIDO2 and WebAuthn standards.

    FIDO2 architecture neutralizes AiTM reverse-proxy attacks through cryptographic origin binding. When an employee authenticates using a FIDO2 security key or platform authenticator, the web browser cryptographically binds the authentication request to the specific domain origin shown in the browser address bar. If an attacker routes the employee to a spoofed proxy domain, the browser detects the domain mismatch and refuses to sign the authentication challenge. The proxy captured nothing because no valid token was ever generated.

    Beyond hardware-bound authentication, we must enforce strict Zero-Trust network access and continuous conditional access policies. Authentication must never be treated as a single, static event that grants permanent access for the duration of a session token. System infrastructure must continuously evaluate device health, geographic velocity, IP reputation, and behavioral anomalies throughout the entire life of the connection. If a session token suddenly presents from an unrecognized IP address or an unmanaged device, that session must be revoked immediately, and step-up authentication must be enforced.

    Summary of Core Defenses

    • Hardware-bound FIDO2 and WebAuthn protocols eliminate AiTM session hijacking by cryptographically binding authentication challenges to verified domain origins.
    • Optical payload inspection and mobile device management controls counter image-based quishing vectors that bypass traditional secure email gateways.
    • Continuous conditional access policies validate device compliance, network context, and session integrity in real time to neutralize stolen session tokens.

    The era of trusting simple passwords paired with basic multi-factor push notifications is dead. Attackers have weaponized automated proxies and optical vectors to turn our own authentication mechanisms against us. Survival requires dropping the comfortable illusion of legacy security, taking absolute accountability for our technical debt, and building an unyielding architecture that stops threat actors cold before the system burns.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #adversaryInTheMiddle #AiTMPhishing #antiPhishingDefense #BYODVulnerabilities #conditionalAccessPolicies #continuousAuthentication #credentialHarvesting #cyberIncidentResponse #cybersecurityDefenses #domainOriginCryptographicCheck #EDRBypass #emailSecurityGateway #endpointProtection #enterpriseSecurity #EvilGinx #FIDO2 #hardwareBoundAuthentication #IAMSecurity #identityAccessManagement #identitySecurity #identitySecurityProtocols #MFABypass #mobileSecurityRisks #modernPhishingCampaigns #MultiFactorAuthenticationFailure #networkPerimeterSecurity #opticalPayloadThreats #originBinding #passTheCookie #phishingFrameworks #phishingProxies #phishingResistantMFA #QRCodePhishing #quishing #reverseProxyAttacks #secureEmailGatewayBypass #sessionCookieHijacking #sessionHijackingPrevention #sessionTokenTheft #socialEngineeringVectors #telephoneOrientedAttackDelivery #threatIntelligence #TOADAttacks #tokenHijacking #WebAuthn #zeroTrustArchitecture #zeroTrustNetworkAccess
  17. Anthropic Exposes AI Abuse by Hackers Linked to Russia, China

    Anthropic uncovered a massive AI-powered operation by hackers linked to Russia and China, who used a sophisticated pipeline to download and scan 1.8 million Android apps for sensitive secrets. This alarming breach highlights the growing threat of AI abuse in cyber attacks.

    osintsights.com/anthropic-expo

    #AiAbuseDetection #Russia #China #Shinyhunters #CredentialHarvesting

  18. Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

    Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. Customers are strongly advised to apply available hotfixes immediately.

    Pulse ID: 6aa1c2281252d98a241ae632
    Pulse Link: otx.alienvault.com/pulse/6aa1c
    Pulse Author: AlienVault
    Created: 2026-09-09 20:31:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cisco #CredentialHarvesting #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Russia #Sandworm #Talos #Vulnerability #Worm #bot #AlienVault

  19. Threat Actors Exploit AI for Large-Scale Credential Harvesting

    Threat actors are supercharging their attacks with AI, using it to scale up credential harvesting and launch more sophisticated campaigns. Google Threat Intelligence Group reports that financially motivated and espionage-focused attackers are increasingly turning to AI to target high-value sectors like healthcare,…

    osintsights.com/threat-actors-

    #Ai #CredentialHarvesting #GoogleThreatIntelligenceGroup #Healthcare #ArtificialIntelligence

  20. Attackers Exploit PaperCut Flaws to Harvest Education Sector Credentials

    Stolen logins from the education sector could give attackers a master key to unlock other critical systems, sparking serious concerns about widespread security breaches. Threat actors are exploiting PaperCut flaws to harvest credentials, creating a privileged pathway for further malicious activity.

    osintsights.com/attackers-expl

    #Papercut #Cve202681578 #Cve202682078 #EducationSector #CredentialHarvesting

  21. Shai-Hulud Infostealer Worm Targets 469 Credential Locations, Threatens Software Supply Chains

    A recent Shai-Hulud infostealer worm variant has significantly upped the ante, now scanning 469 credential locations - a massive jump from 189 in earlier variants - to harvest sensitive access credentials and threaten software supply chains. This strategic shift allows attackers to exploit…

    osintsights.com/shai-hulud-inf

    #InfostealerWorm #Shaihulud #SupplyChain #CredentialHarvesting #MalwareOperations

  22. Hackers Exploit Public Wi-Fi DNS to Harvest Credentials

    Beware of hackers lurking on public Wi-Fi networks at hotels, conference centers, and other hotspots, who are using a sneaky trick to steal your login credentials by hijacking the network's DNS settings. By changing just one setting, they can redirect you to fake login pages that look legit - and that's all they need to get…

    osintsights.com/hackers-exploi

    #PublicWifiHacking #CredentialHarvesting #DnsManipulation #EmergingThreats #WifiSecurity

  23. Infostealers Harvest 1.7 Billion Credentials in Six Months

    Cybercriminals have supercharged their credential-harvesting capabilities, with infostealer malware infecting 7.4 million devices and snagging a staggering 1.7 billion credentials in just six short months. This automated threat landscape redefines the speed and scale of a breach.

    osintsights.com/infostealers-h

    #InfostealerMalware #CredentialHarvesting #EmergingThreats #IdentityfocusedCybercrime #MalwareOperations

  24. Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam

    A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts.

    Pulse ID: 6a74c5ff523b6fcb70f5711d
    Pulse Link: otx.alienvault.com/pulse/6a74c
    Pulse Author: AlienVault
    Created: 2026-08-06 17:35:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BitCoin #Browser #CAPTCHA #CredentialHarvesting #CyberSecurity #Email #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #Russia #SocialEngineering #Troll #Word #bot #cryptocurrency #AlienVault

  25. OctLurk and SilkLurk: new Backdoors in Central Asia

    Two newly identified backdoors, OctLurk and SilkLurk, have been targeting government organizations across Central Asia since January 2025. Victims span Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, affecting healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and educational institutions. Both backdoors employ heavily obfuscated loaders customized per victim, using machine-specific data for decryption. They deploy multiple plugins for command execution, file manipulation, credential harvesting, keylogging, network scanning, and remote access. The attackers also utilized LurkProxy for network traffic proxying and deployed additional tools including PlugX, Impacket, FSCAN, and Pandora FMS agents. Analysis indicates both backdoors are operated by the same Chinese-speaking threat actor, though attribution to a specific known group remains unconfirmed. The campaigns demonstrate sophisticated persistence mechanisms and ext...

    Pulse ID: 6a6b4b97df5f9df74333adfa
    Pulse Link: otx.alienvault.com/pulse/6a6b4
    Pulse Author: AlienVault
    Created: 2026-07-30 13:03:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #CentralAsia #Chinese #CredentialHarvesting #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Mac #OTX #Office #OpenThreatExchange #PlugX #Proxy #RAT #RCE #SMS #Syria #bot #AlienVault

  26. Cybersecurity Experts Warn of Global Hotel Wi-Fi Credential Harvesting Campaign

    Beware of hackers lurking on hotel Wi-Fi networks, as a global campaign is underway to steal sensitive credentials from unsuspecting travelers and businesses. Cyber attackers are exploiting weak spots in hotel routers and Wi-Fi systems to gain control and manipulate DNS settings.

    osintsights.com/cybersecurity-

    #WifiHacking #CredentialHarvesting #HotelWifi #DnsPoisoning #CaptiveWifi

  27. FortiBleed Exposes Link to Ransomware Ops

    A shocking new report reveals that the notorious FortiBleed vulnerability has a direct link to ransomware operations, with a key player found negotiating with both groups. This alarming connection has led to at least 12 ransomware deployments and hundreds of encrypted endpoints.

    osintsights.com/fortibleed-exp

    #Fortibleed #RansomwareOperations #CredentialHarvesting #MassCredentialTheft #RansomwareDeployment

  28. FortiBleed Exposes 110 Million Credentials in Global Firewall Hack

    A recent global firewall hack, dubbed FortiBleed, has exposed a staggering 110 million credentials, putting countless individuals and organizations at risk. This massive breach was made possible by a sophisticated five-stage pipeline that allowed hackers to capture sensitive information, including cleartext and hashed credentials, from…

    osintsights.com/fortibleed-exp

    #Fortibleed #CredentialHarvesting #FirewallHack #Golang #Ssh

  29. Threat Actors Monetize Stolen Credentials with Searchable Underground Services

    Cybercriminals are cashing in on stolen credentials with a new breed of underground services that allow buyers to search and purchase specific, verified login details. This emerging market acts as a middleman between hackers who steal sensitive info and those who want to use it to take over…

    osintsights.com/threat-actors-

    #StolenCredentialMarket #UndergroundEconomy #Infostealer #AccountTakeover #CredentialHarvesting

  30. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  31. North Korean Hackers Exploit Coding Lures to Steal Crypto Credentials

    In a sneaky move, North Korean hackers sent over 250 emails with innocent-looking coding tasks to nearly 100 US-based organizations, tricking them into handing over cryptocurrency credentials. The clever phishing scam, tracked as UNK_DeadDrop, targeted tech, education, and finance firms, with a special focus on cryptocurrency…

    osintsights.com/north-korean-h

    #NorthKorea #CryptocurrencyTheft #CredentialHarvesting #Phishing #Github

  32. Hackers Exploit Active Directory Flaw to Harvest Passwords

    Storing passwords in Active Directory description fields is a rookie mistake that hackers are eager to exploit, and one hacker did just that with alarming ease. It was disturbingly simple for them to get their hands on sensitive information.

    osintsights.com/hackers-exploi

    #ActiveDirectoryFlaw #CredentialHarvesting #PasswordExposure #IdentityTheft #EmergingThreats

  33. Miasma Supply Chain Attack Targets Red Hat npm Packages

    A new supply-chain campaign, codenamed Miasma, has compromised multiple Red Hat npm packages to steal sensitive credentials and deliver a self-propagating worm, putting developer machines at risk. This sneaky attack uses clever tactics like install-time execution and encrypted exfiltration to harvest secrets and spread its reach.

    osintsights.com/miasma-supply-

    #SupplyChainAttack #Npm #RedHat #CredentialHarvesting #CicdTargeting

  34. A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure

    JINX-0164, a financially motivated threat actor active since mid-2025, has been conducting sophisticated campaigns against cryptocurrency organizations. The actor employs LinkedIn-based social engineering, posing as recruiters or business partners to deliver custom macOS malware including AUDIOFIX (a Python-based infostealer and RAT) and MINIRAT (a lightweight Go backdoor). Their operations focus on compromising developer endpoints to steal cryptocurrency wallet credentials, cloud secrets, and GitHub tokens. The attackers then pivot to CI/CD infrastructure, injecting malicious code into repositories to enable lateral movement. In April 2026, they executed a supply chain attack by trojanizing the npm package @velora-dex/sdk. The group masks activity using VPN services and demonstrates advanced capabilities including credential harvesting from password managers, browser extensions, and development tools.

    Pulse ID: 6a181e409d755171f4ac356c
    Pulse Link: otx.alienvault.com/pulse/6a181
    Pulse Author: AlienVault
    Created: 2026-05-28 10:51:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Cloud #CredentialHarvesting #CyberSecurity #Endpoint #GitHub #InfoSec #InfoStealer #LinkedIn #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #Password #Python #RAT #SocialEngineering #SupplyChain #Trojan #VPN #Word #bot #cryptocurrency #AlienVault

  35. Hook, Line, and Sinker: Why People Still Fall for “Official” Emails

    3,206 words, 17 minutes read time.

    The digital landscape is a cold, relentless stretch of asphalt where the rain never stops and the shadows are always reaching for your throat. It is an environment built on the fundamental architecture of trust, yet it is that very trust that serves as the primary vector for the modern grift. When we look at the evolution of the phishing landscape, we aren’t just looking at a series of technical failures or a lack of robust filtering; we are looking at the exploitation of the human operating system. Most analysts want to talk about SPF, DKIM, and DMARC as if they are the ultimate shields against the storm, but they often ignore the fact that the most sophisticated code in the world cannot patch a moment of panic. The “Official” email is the modern equivalent of a knock at the door at three in the morning; it carries an inherent authority that bypasses the logical gates of the brain and targets the raw, unrefined nerves of social obligation and fear of consequence.

    Analyzing the recent waves of business email compromise and high-stakes credential harvesting, I see a clear pattern that suggests we are losing the war of attrition because we refuse to acknowledge the psychological heavy lifting being done by the adversary. The craft has moved far beyond the broken syntax and desperate pleas of a decade ago, evolving into a surgical instrument that mirrors the exact cadence of corporate bureaucracy. These attackers are not just hackers anymore; they are student of institutional behavior who understand that a well-placed “Urgent Action Required” notice from a spoofed human resources alias is more effective than any brute-force attack. By the time the target realizes the landing page is a mirror of a Microsoft 365 login, the credentials have already been spirited away into a database in a jurisdiction where the law doesn’t have a name.

    The Psychological Mechanics of the Digital Ambush

    The success of a phishing campaign relies on the deliberate manipulation of cognitive load and the exploitation of ingrained social hierarchies. When an individual receives an email that appears to originate from a high-level executive or a government entity like the Internal Revenue Service, the brain undergoes a shift from analytical processing to a reactive survival mode. This is not a matter of intelligence or technical savvy, as even seasoned administrators have been known to trip over a well-constructed lure when the timing is right. The adversary waits for the moment of highest friction—the end of a quarter, the middle of a migration, or the chaos of a public holiday—to drop a message that demands immediate attention. This creates a sense of urgency that effectively narrows the victim’s field of vision, making them ignore the subtle discrepancies in the sender’s address or the slightly off-kilter phrasing of the call to action.

    Furthermore, the concept of social proof is weaponized within these emails to provide a false sense of security that lulls the victim into a state of compliance. Many of these “official” messages are designed to look like a small part of a larger, ongoing process, such as a mandatory security update or a routine document review. By framing the malicious link as a necessary step in a boring, everyday task, the attacker sidesteps the natural skepticism that usually accompanies an unexpected request. Consequently, the victim views the interaction not as a potential threat, but as a minor hurdle to be cleared so they can return to their actual work. This mundane nature of the attack is its greatest strength, allowing it to slip through the cracks of human intuition while the technical defenses are busy looking for more overt signs of intrusion.

    Why Technical Defense Perimeters Often Fail the Human Test

    We have spent billions of dollars on secure email gateways and advanced threat protection, yet the “official” email remains the most successful entry point for ransomware and data exfiltration. This failure is rooted in the inherent tension between usability and security, where the need for seamless communication often creates gaps that an attacker can drive a truck through. A secure email gateway is essentially a filter designed to catch known bad patterns, but the modern phisher is an expert at staying just beneath the threshold of detection. They use legitimate infrastructure, such as compromised Small Business Server accounts or reputable cloud hosting providers, to launch their campaigns. When a malicious email originates from a trusted IP address with valid cryptographic signatures, the technical gates swing wide open, leaving only the human at the keyboard to make the final call.

    In addition to the subversion of trust, the rapid pace of digital transformation has outstripped the ability of the average user to verify the authenticity of their communications. As organizations move their operations to various third-party SaaS platforms, the number of “official” domains that a user interacts with on a daily basis has skyrocketed. It is no longer enough to look for a single corporate domain; employees are now expected to recognize notifications from payroll systems, project management tools, and cloud storage providers, all of which use different naming conventions and email templates. This fragmentation creates a smokescreen for the attacker, who can easily hide a malicious domain amidst the noise of a dozen legitimate ones. As a result, the mental fatigue of constantly verifying these sources leads to a state of “security nihilism,” where the user eventually stops checking altogether and simply clicks through to stay productive.

    The anatomy of a modern credential harvest is a masterclass in deceptive minimalism, designed to exploit the very tools we use to stay organized and secure. Looking at the mechanics of the “Official” document lure, I see a devastatingly effective strategy that leverages the ubiquity of shared drives and collaborative platforms like SharePoint or DocuSign. The attacker doesn’t need to attach a piece of malware that might trigger an endpoint detection system; they simply provide a link to a legitimate-looking landing page that asks for a login to “view the protected file.” This transition from a trusted email environment to a browser-based authentication prompt is where the logic breaks down for most users. Because the initial email looked like a standard notification—complete with the correct legal disclaimers and corporate branding—the user’s brain has already cleared the transaction for takeoff. By the time they land on the spoofed login page, they aren’t looking for a scam; they are looking for their document, and they will hand over their credentials to get it.

    The danger is compounded by the rise of “Living off the Land” techniques in the phishing world, where attackers use the victim’s own tools against them. When an adversary compromises a legitimate account within a supply chain, they can send “official” emails from a truly valid source to that person’s entire contact list. This lateral movement within a trusted ecosystem is the nightmare scenario for any security operations center because the traditional red flags simply do not exist. There is no mismatched “From” header to inspect, and the link often points to a real file hosted on a real corporate server that happens to contain a malicious redirect. In this context, the victim isn’t falling for a fake; they are being misled by a compromised reality. This level of deception makes it nearly impossible for the average employee to distinguish between a routine request and a high-stakes heist, especially when the message arrives in the middle of a high-pressure workday.

    The Institutional Cost of Authority-Based Exploitation

    When we break down the damage, we see that the financial toll of these “official” phishes is often eclipsed by the erosion of internal culture and institutional trust. Every time a successful campaign rips through a department, the aftermath involves a heavy-handed response from IT that usually includes more restrictive policies and mandatory, often condescending, training modules. This creates a friction-filled environment where employees start to view their own security team as an adversary or a hurdle to their productivity. Furthermore, the psychological impact on the individual who clicked the link can be profound, leading to a loss of confidence that hampers their work performance and makes them less likely to report future suspicious activity for fear of further embarrassment. Consequently, the organization becomes more brittle, hiding its vulnerabilities behind a facade of compliance while the actual risk remains unaddressed and festering in the shadows.

    Looking at the broader economic landscape, the industrialization of phishing kits has lowered the barrier to entry for low-level criminals, allowing them to masquerade as sophisticated entities with the click of a button. These kits come pre-loaded with high-fidelity templates for every major bank, government agency, and tech giant, ensuring that even a novice operator can launch an “official” campaign that looks professional. This democratization of high-end social engineering means that the volume of attacks is constantly increasing, creating a background radiation of fraud that everyone must navigate daily. The sheer frequency of these encounters leads to a desensitization of the workforce, where the warning signs that used to trigger an alarm are now ignored as part of the digital noise. This saturation of the communication channel is exactly what the adversary wants, as it ensures that eventually, someone, somewhere, will be tired or distracted enough to swallow the hook.

    The Illusion of Multi-Factor Authentication as a Total Shield

    One of the most dangerous myths in the current security climate is the idea that Multi-Factor Authentication is an unhackable barrier that renders phishing obsolete. While MFA is a critical layer of defense, the “official” email has evolved to bypass it through sophisticated techniques like adversary-in-the-middle attacks and session hijacking. In a standard MFA-bypass scenario, the malicious email leads the victim to a proxy server that mimics the real login page in real-time. As the victim enters their username, password, and the subsequent one-time code from their phone, the attacker’s server passes those credentials to the actual service and steals the resulting session cookie. To the user, the experience is seamless and appears entirely “official,” but behind the scenes, the attacker now has a persistent foothold that bypasses the need for a password entirely. This proves that even our most robust technical solutions can be undermined by a well-executed social engineering play that targets the moment of authentication.

    Moreover, the phenomenon of “MFA Fatigue” has become a potent weapon in the attacker’s arsenal, turning a security feature into a vulnerability. After sending a series of “official” emails claiming there is a problem with an account, the attacker will trigger a barrage of push notifications to the victim’s mobile device. The goal is to wear the person down until they hit “Approve” just to make the buzzing stop, assuming it’s a glitch in the “official” system. This exploit doesn’t require technical brilliance; it requires an understanding of human frustration and the tendency to take the path of least resistance. It demonstrates that as long as there is a human in the loop, the adversary will find a way to manipulate that person into opening the door, no matter how many locks we put on it. The “official” email is merely the first step in a psychological siege designed to break the victim’s resolve.

    The strategy of the modern phisher has moved beyond the simple theft of credentials and into the territory of high-stakes narrative control. When we analyze the rise of Business Email Compromise, it becomes clear that the “Official” email is often just the opening act in a long-form con that can last for weeks. The attacker doesn’t just want a password; they want to insert themselves into the financial workflow of an organization. By mimicking the tone, the signature blocks, and the specific jargon of a vendor or a high-level partner, the adversary creates a secondary reality where a change in banking details or a diverted wire transfer seems like a routine administrative adjustment. The horror of this approach lies in its banality. There are no flashing red lights or “Access Denied” screens; there is only a quiet, professional-looking email that follows every established rule of corporate etiquette while it drains the company’s accounts.

    Furthermore, the integration of generative AI into the attacker’s toolkit has eliminated the last remaining red flags that used to give these “Official” lures away. Gone are the days when a sharp-eyed employee could spot a phishing attempt by its poor grammar or awkward phrasing. Today’s lures are syntactically perfect, culturally nuanced, and tailored to the specific industry of the target. An attacker can now feed a few public interviews or LinkedIn posts from an executive into a model and generate an email that captures that individual’s unique “voice” with terrifying precision. This makes the “Official” email even more dangerous because it appeals to the victim’s sense of familiarity. Consequently, the gap between a legitimate internal communication and a fraudulent one has narrowed to the point of invisibility, leaving the human target to navigate a minefield where every step looks like solid ground.

    The Weaponization of Compliance and Legal Fear

    A significant portion of why people still fall for these lures is the strategic use of “regulatory theater” to induce a state of compliance-driven panic. Attackers have realized that the modern professional is terrified of three things: HR violations, tax audits, and data breaches. By framing a phishing lure as a “Mandatory Data Privacy Attestation” or an “Immediate Tax Compliance Notice,” the attacker leverages the weight of the law to bypass the user’s skepticism. These emails often include realistic references to actual legislation, such as GDPR or the CCPA, which adds a layer of superficial credibility that is hard to ignore. The victim isn’t just clicking a link; they are attempting to protect themselves or their company from a perceived legal threat. This flip of the script—making the scam look like a security measure—is a calculated move that turns a person’s best intentions into their greatest vulnerability.

    In addition to legal threats, the “Official” lure often exploits the internal power dynamics of the modern workplace. In a high-pressure environment where “performance” is everything, the fear of failing to respond to a superior is a powerful motivator. I see this play out in “Urgent Request” scenarios where the email appears to come from a CEO or a Board Member who is “stuck in a meeting” and needs a quick favor. The victim is often so focused on the social reward of being helpful or the fear of appearing incompetent that they fail to perform even basic due diligence. The adversary knows that in a hierarchy, authority flows downward with a force that can flatten common sense. By the time the employee thinks to call the executive to verify the request, the gift cards have been drained or the sensitive spreadsheet has been uploaded to a command-and-control server.

    Rebuilding the Perimeter on a Foundation of Radical Skepticism

    If we are going to survive in this environment, we have to move past the idea that we can train the human element out of the equation. The “Official” email works because it is designed to work on humans, and humans are fundamentally social, cooperative, and prone to pressure. The solution isn’t another hour of boring slide decks; it’s a fundamental shift toward an “Assume Breach” mentality at the individual level. This means moving away from a culture of blind trust and toward one of verified communication, where no request involving data or money is ever handled through a single, unverified channel. We need to normalize the “Double-Check”—the idea that calling a coworker to verify an unusual email is not a sign of paranoia, but a standard operating procedure. This cultural shift is far harder to implement than a new firewall, but it is the only thing that can stand against the psychological precision of the modern phisher.

    Moreover, organizations must stop relying on the visual “polish” of an email as a proxy for its legitimacy. We need to strip away the corporate logos and the fancy signatures in our minds and look at the raw intent of the message. If an email creates a sense of urgency, demands a bypass of standard procedures, or directs you to an external site to enter credentials, it should be treated as hostile until proven otherwise. The “Official” email is a mask, and the only way to beat it is to stop being impressed by the mask. We have to start valuing the friction in our systems—the extra steps, the out-of-band verifications, and the healthy skepticism—because that friction is the only thing that slows the attacker down long enough for us to see the hook beneath the bait. The rain is still falling on the digital asphalt, and the shadows are still reaching, but they only win when we let them lead us where they want us to go.

    The persistence of the “Official” email as a top-tier threat vector is ultimately a testament to the fact that technical solutions are being applied to a non-technical problem. We are trying to use cryptographic signatures and automated filters to solve for the human desire to be helpful, the fear of authority, and the exhaustion of the modern workday. It is a mismatch of resources that the adversary exploits with predatory efficiency. When I look at the wreckage left behind by these campaigns, it is rarely the result of a single catastrophic failure; rather, it is a series of small, logical concessions made by a tired person just trying to get through their inbox. The attacker doesn’t need to be a digital ghost or a coding prodigy; they just need to be a better actor than you are a skeptic. They understand that if they can control the narrative, they can control the network, and they use the “Official” branding as the stage on which they perform their heist.

    To break this cycle, we have to stop treating phishing as a “user error” and start treating it as an inevitable environmental hazard. This requires a defensive architecture that doesn’t just look for bad files, but looks for suspicious behaviors and anomalies in the flow of authority. If an executive who never handles wire transfers suddenly sends an “Official” urgent request for one, the system should be smart enough to flag the deviation, regardless of how clean the email headers look. We need to build systems that protect people from their own instinct to comply, creating hard stops and out-of-band verification requirements for any high-value transaction. The goal is to move the burden of defense off the shoulders of the individual and into the design of the workflow itself. Until we accept that the “Official” email is the most dangerous weapon in the digital world, we will continue to find ourselves staring at the empty accounts and compromised servers that are the hallmark of a successful hook, line, and sinker.

    Call to Action

    The time for treating phishing as a minor IT nuisance is over; it is a predatory psychological war, and you are currently the primary target. If you are a leader, you need to stop hiding behind automated filters and start building a culture where a healthy “no” is valued more than a rushed “yes.” Stop the assembly line long enough to verify the source, pick up the phone when an email feels even slightly off-kilter, and demand that your organization implements out-of-band verification for every high-stakes transaction. Don’t wait for the post-mortem report to realize your “official” communication was a ghost in the machine. Audit your workflows today, tighten your authentication protocols, and train your eyes to see the hook beneath the polish—because the next “urgent” email in your inbox isn’t looking to help you, it’s looking to gut you.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #adversaryInTheMiddle #AiTM #AuthorityBias #BEC #businessEmailCompromise #CEOFraud #CognitiveLoad #corporateEspionage #corporateSecurity #credentialHarvesting #cyberDefense #cyberResilience #cyberRiskManagement #cyberThreats #cybercrime #cybersecurityBlog #cybersecurityTraining #dataBreach #DigitalAmbush #DKIM #DMARC #DocuSignScams #emailSecurity #financialFraud #HumanError #identityTheft #incidentResponse #informationSecurity #IRSPhishing #LivingOffTheLand #MalwareFreeAttacks #MFABypass #MFAFatigue #Microsoft365Security #OfficialEmailScams #phishing #PsychologicalExploitation #RegulatoryPhishing #secureEmailGateway #securityAwareness #SecurityNihilism #sessionHijacking #SharePointPhishing #socialEngineering #spearPhishing #SPF #threatIntelligence #TrustArchitecture #UrgencyTactics #vendorImpersonation #zeroTrust
  36. Popular node-ipc npm Package Infected with Credential Stealer

    A supply chain attack has compromised the node-ipc npm package, with malicious versions 9.1.6, 9.2.3, and 12.0.1 containing obfuscated stealer and backdoor functionality. The attack vector involved takeover of a dormant maintainer account through an expired email domain. The malware fingerprints host environments, enumerates and reads local files including SSH keys, cloud credentials, database configurations, and various developer secrets. Collected data is compressed into a gzip archive and exfiltrated via DNS TXT queries to attacker-controlled infrastructure disguised as legitimate Azure domains. The payload targets over 100 file patterns across macOS and Linux systems, focusing on developer credentials from AWS, Azure, GCP, Kubernetes, Docker, npm, GitHub, and numerous other services. The malicious code executes during CommonJS module loading, forking a detached child process to perform credential harvesting while avoiding detection through obfuscation and DNS-based covert channels.

    Pulse ID: 6a0d970e99916e7e7e17c893
    Pulse Link: otx.alienvault.com/pulse/6a0d9
    Pulse Author: AlienVault
    Created: 2026-05-20 11:12:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #BackDoor #Cloud #CredentialHarvesting #CyberSecurity #DNS #Docker #Email #GitHub #InfoSec #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Troll #ZIP #bot #AlienVault

  37. Malware Worm Eliminates Rival, Seizes Control

    Meet the malware worm with a ruthless streak - it not only eliminates rival malware from infected systems, but also seizes control and claims the compromised credentials for itself. This cunning worm is taking over, leaving other malicious operators with nothing.

    osintsights.com/malware-worm-e

    #MalwareOperations #RivalMalwareElimination #CredentialHarvesting #Worm #EmergingThreats

  38. Python Backdoor Exploits Tunneling Service to Harvest Browser, Cloud Credentials

    Meet DEEP#DOOR, a sneaky Python-based backdoor framework that's harvesting browser and cloud credentials by exploiting a tunneling service, and learn how it infiltrates systems through a clever sequence of stealthy steps. This sophisticated threat starts with a simple batch script that disables Windows security…

    osintsights.com/python-backdoo

    #PythonBackdoor #Deepdoor #RemoteAccessTrojan #Rat #CredentialHarvesting

  39. macOS ClickFix Attacks Harvest Credentials via AppleScript Stealers

    macOS users beware: a sneaky ClickFix campaign is using AppleScript stealers to harvest credentials from 14 browsers, 16 cryptocurrency wallets, and over 200 extensions. This targeted attack has already made off with a staggering amount of sensitive info - and it's still on the loose.

    osintsights.com/macos-clickfix

    #Macos #Clickfix #Applescript #Infostealer #CredentialHarvesting

  40. Using KATA and KEDR to detect the AdaptixC2 agent

    AdaptixC2 is an emerging open-source post-exploitation framework rapidly adopted by threat actors in APT attacks and ransomware campaigns. Written in Go and C++, it supports Windows, macOS, and Linux with extensive modularity through Beacon Object Files (BOFs). The framework enables diverse command-and-control channels including HTTP/S, TCP, mTLS, DNS, DoH, and SMB with RC4 encryption throughout. It implements sophisticated evasion techniques targeting both network detection systems and endpoint defenses. Despite advanced obfuscation capabilities, network-level detection remains viable through analysis of distinctive communication patterns, header structures, and behavioral indicators. The framework supports credential harvesting via LSASS dumping, LAPS exploitation, and Kerberos attacks, alongside defense evasion through process injection and lateral movement via WinRM and PsExec. Combined NDR and EDR solutions provide effective multi-layered detection coverage against AdaptixC2 operations across network ...

    Pulse ID: 69e2824daddc65cc4bab207d
    Pulse Link: otx.alienvault.com/pulse/69e28
    Pulse Author: AlienVault
    Created: 2026-04-17 18:56:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberSecurity #DNS #EDR #Encryption #Endpoint #HTTP #InfoSec #Linux #Mac #MacOS #OTX #OpenThreatExchange #PsExec #RAT #RCE #RansomWare #SMB #TCP #TLS #Windows #bot #AlienVault

  41. Dissecting macOS intrusion from lure to compromise

    Microsoft Threat Intelligence uncovered a macOS-focused cyber campaign by North Korean threat actor Sapphire Sleet utilizing social engineering to compromise systems. The attack chain begins with a malicious AppleScript file disguised as a Zoom SDK update, which executes cascading payloads through curl-to-osascript chains. The campaign deploys multiple backdoors including com.apple.cli, services, icloudz, and com.google.chromes.updaters for persistence and command execution. Credential harvesting occurs through fake system dialogs that mimic legitimate macOS password prompts. The threat actor bypasses Transparency, Consent, and Control protections by directly manipulating the TCC database, enabling extensive data exfiltration targeting cryptocurrency wallets, browser credentials, Telegram sessions, SSH keys, and Apple Notes. Operations focus on cryptocurrency, finance, and blockchain organizations with the primary objective of stealing digital assets.

    Pulse ID: 69e1f157d8f8bb7547f8c23f
    Pulse Link: otx.alienvault.com/pulse/69e1f
    Pulse Author: AlienVault
    Created: 2026-04-17 08:37:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #BlockChain #Browser #Chrome #Cloud #CredentialHarvesting #CyberSecurity #Google #InfoSec #Korea #Mac #MacOS #Microsoft #Mimic #NorthKorea #OTX #OpenThreatExchange #Password #RAT #SSH #SocialEngineering #Telegram #Word #Zoom #bot #cryptocurrency #AlienVault

  42. Feds Disrupt Russia-Backed Espionage Network Infecting 18,000 Devices

    Federal authorities have successfully disrupted a massive Russia-backed espionage operation that had infiltrated nearly 18,000 devices, stealing sensitive account credentials and tokens by hijacking internet traffic. This significant takedown thwarts the efforts of Forest Blizzard, a notorious threat group linked to Russia's GRU.

    osintsights.com/feds-disrupt-r

    #Russia #ForestBlizzard #Gru #EspionageNetwork #CredentialHarvesting

  43. Autonome APTs: Die Claude-basierte Operation wird nicht die letzte sein

    Die Aufdeckung einer neuen KI-gestützten APT wird oft als Beleg gesehen, dass Sicherheitssysteme funktionieren. Tatsächlich zeigt der Fall jedoch das Gegenteil: Er macht sichtbar, was bislang unentdeckt im Untergrund reifte.

    all-about-security.de/autonome

    #claude #apt #ki #autonomeAPTs #CredentialHarvesting #backdoor #CyberKillChain #cybersecurity

  44. DCRAT Impersonating the Colombian Government

    A new email attack distributing DCRAT, a Remote Access Trojan, has been uncovered. The threat actor impersonates a Colombian government entity to target organizations in Colombia. The attack employs multiple evasion techniques, including password-protected archives, obfuscation, steganography, base64 encoding, and multiple file drops. DCRAT features a modular architecture, comprehensive surveillance capabilities, information theft functions, system manipulation tools, file and process management, and browser credential harvesting. The attack chain involves a phishing email with a ZIP attachment containing a bat file, which drops an obfuscated vbs file. This file eventually runs a base64-encoded script that downloads and executes the final payload. The RAT employs various persistence mechanisms and anti-analysis techniques. It attempts to bypass Windows Antimalware Scan Interface (AMSI) and continuously tries to connect to its command-and-control server.

    Pulse ID: 68654eff7ba38f77505ba8c5
    Pulse Link: otx.alienvault.com/pulse/68654
    Pulse Author: AlienVault
    Created: 2025-07-02 15:23:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CredentialHarvesting #CyberSecurity #DCRat #Email #Government #InfoSec #InformationTheft #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #RemoteAccessTrojan #SMS #Steganography #Trojan #VBS #Windows #Word #ZIP #bot #AlienVault

  45. Cyber Attacks on Government Agencies: Detect and Investigate

    This analysis examines cyber threats targeting government institutions worldwide, focusing on three case studies: a phishing email targeting the South Carolina Department of Employment and Workforce, a fraudulent domain mimicking the U.S. Social Security Administration, and a malicious PDF posing as a South African Judiciary notice. The study demonstrates how ANY.RUN's solutions, including Threat Intelligence Lookup, Interactive Sandbox, and YARA Search, can be utilized to detect, analyze, and mitigate these threats. Key findings include the use of FormBook stealer, remote access tools, and credential harvesting techniques. The analysis provides actionable insights for government cybersecurity teams to enhance their defensive strategies and response capabilities.

    Pulse ID: 68409d6271a2178e01aa5e79
    Pulse Link: otx.alienvault.com/pulse/68409
    Pulse Author: AlienVault
    Created: 2025-06-04 19:24:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ANYRUN #Africa #CredentialHarvesting #CyberAttack #CyberAttacks #CyberSecurity #Email #FormBook #Government #InfoSec #Mimic #OTX #OpenThreatExchange #PDF #Phishing #RAT #RCE #bot #AlienVault

  46. TA406 Pivots to the Front

    In February 2025, TA406, a North Korean state-sponsored actor, began targeting Ukrainian government entities with phishing campaigns aimed at gathering intelligence on the Russian invasion. The group utilized freemail senders impersonating think tank members to deliver both credential harvesting attempts and malware. Their tactics included using HTML and CHM files with embedded PowerShell for malware deployment, as well as fake Microsoft security alerts for credential theft. The malware conducted extensive reconnaissance on target hosts, gathering system information and checking for anti-virus tools. TA406's focus appears to be on collecting strategic, political intelligence to assess the ongoing conflict and potential risks to North Korean forces in the region.

    Pulse ID: 6823b32f1fad0a568539c4c1
    Pulse Link: otx.alienvault.com/pulse/6823b
    Pulse Author: AlienVault
    Created: 2025-05-13 21:01:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberSecurity #Email #Government #HTML #ICS #InfoSec #Korea #Malware #Microsoft #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RCE #Russia #UK #Ukr #Ukrainian #bot #AlienVault

  47. Legitimate employee tracking software is being twisted into a spyware tool by cybercriminals. Imagine keystrokes and screenshots fueling elaborate ransomware attacks—how safe is your data?

    thedefendopsdiaries.com/the-mi

    #ransomware
    #kickidler
    #cybersecurity
    #infosec
    #credentialharvesting

  48. New RansomHub attack uses TDSKiller and LaZagne, disables EDR

    A recent analysis by the ThreatDown MDR team has uncovered a novel attack method employed by the RansomHub ransomware gang. The attackers are utilizing two tools: TDSSKiller, a legitimate Kaspersky rootkit removal utility, to disable endpoint detection and response (EDR) systems, and LaZagne, a credential harvesting tool. This marks the first instance of RansomHub incorporating these tools into their arsenal. The attack begins with network reconnaissance and admin group enumeration, followed by the deployment of TDSSKiller to disable security services like Malwarebytes Anti-Malware Service. Subsequently, LaZagne is used to extract stored credentials from various applications, facilitating lateral movement within the compromised network. The campaign is currently active, prompting the implementation of new detection rules and recommendations for enhanced security measures.

    Pulse ID: 66e1fea1c13efefb5eaa6141
    Pulse Link: otx.alienvault.com/pulse/66e1f
    Pulse Author: AlienVault
    Created: 2024-09-11 20:33:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberSecurity #EDR #Endpoint #EndpointDetectionandResponse #InfoSec #Kaspersky #MalWareBytes #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rootkit #bot #AlienVault

  49. Ongoing Social Engineering Campaign Refreshes Payloads

    Rapid7 observed a shift in tools utilized by threat actors in an ongoing social engineering campaign. The initial lure involves an email bombing followed by calls to users offering fake solutions. Once connected remotely, threat actors deploy payloads for credential harvesting, establishing command and control, and lateral movement. Notable changes include the use of AntiSpam.exe for credential harvesting and various executables and PowerShell scripts serving as droppers, beacons, and socks proxies. The campaign also attempts to exploit CVE-2022-26923 for privilege escalation.

    Pulse ID: 66c4561642cac3de1ea6abed
    Pulse Link: otx.alienvault.com/pulse/66c45
    Pulse Author: AlienVault
    Created: 2024-08-20 08:38:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #PowerShell #Rapid7 #SocialEngineering #Spam #bot #AlienVault

  50. TinyTurla-NG: In-depth tooling and command and control analysis

    Cisco Talos, in cooperation with CERT.NGO, has discovered new malicious components used by the Turla APT group. The investigation revealed details of the command and control scripts, including handling of requests and a web shell component. Three distinct PowerShell command sets were issued to the TinyTurla-NG backdoor to enumerate, stage, and exfiltrate files. Talos also uncovered the use of a modified Chisel tunneling tool, a privilege elevation tool, and credential harvesting scripts deployed via TinyTurla-NG.

    Pulse ID: 65d85c311941b7fae14734b9
    Pulse Link: otx.alienvault.com/pulse/65d85
    Pulse Author: AlienVault
    Created: 2024-02-23 08:49:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #BackDoor #RAT #Cisco #Talos #Turla #CredentialHarvesting #PowerShell #TinyTurla #AlienVault

Share on Mastodon

Enter the server where you have an account.