#phishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #phishing, aggregated by home.social.
-
Do I known anyone that's used #SublimeSecurity for enhanced email scanning security? I am looking to get ahead of some of the improved #phishing that's become common, addressing a number of long running issues with Microsoft security offerings.
I'm looking for your experiences with the product,setup,support, or what you be heard from others using it. :boost_please:
https://sublime.security -
New. This is part of a series, marketing included.
Group-IB: One Adversary: The Fifteen-Minute Problem https://www.group-ib.com/blog/15-minute-problem/ #infosec #fraud #phishing
-
New. This is part of a series, marketing included.
Group-IB: One Adversary: The Fifteen-Minute Problem https://www.group-ib.com/blog/15-minute-problem/ #infosec #fraud #phishing
-
#^Halucinované odkazy z AI otevírají kyberzločincům nové možnosti
Kyberzločinci využívají halucinace jazykových modelů, které vytvářejí věrohodně znějící, ale neexistující webové adresy či názvy softwarových balíčků. Opakovaně doporučované falešné domény pak registrují a mění je na stránky s malwarem, phishingem nebo podvrženým softwarem. Studie Palo Alto Networks našla mezi miliony AI vygenerovaných adres přes 13 tisíc již registrovaných škodlivých domén a další statisíce volných názvů. Tento postup, označovaný jako slop squatting, ohrožuje zejména programátory, zatímco takzvaný phantom squatting může zasáhnout běžné uživatele hledající banky, obchody či rady. Odborníci doporučují výstupy AI vždy ověřovat a rozvíjet odolnější přihlašování, například prostřednictvím standardu WebAuthn.
#kyberbezpecnost #umelainteligence #phishing -
How Scammers Built an Investment Scam Network Using Maliciously Registered Domain Names
Andy Malis shares an investigation by Whalebone into a scam that used fake news stories to draw victims to a fake investment platform. He explains how the scammers used maliciously registered and deceptively composed domain names and both brand and personality impersonation to make the scam convincing and safe.
This is that one occasion where you should pay attention to a "fake news" claim.
https://interisle.substack.com/p/how-scammers-built-an-investment
-
How Scammers Built an Investment Scam Network Using Maliciously Registered Domain Names
Andy Malis shares an investigation by Whalebone into a scam that used fake news stories to draw victims to a fake investment platform. He explains how the scammers used maliciously registered and deceptively composed domain names and both brand and personality impersonation to make the scam convincing and safe.
This is that one occasion where you should pay attention to a "fake news" claim.
https://interisle.substack.com/p/how-scammers-built-an-investment
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
Recent Attack Activity Analysis Using North Korea-Related Lures
APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.
Pulse ID: 6a7dc1fd395815126acd4647
Pulse Link: https://otx.alienvault.com/pulse/6a7dc1fd395815126acd4647
Pulse Author: AlienVault
Created: 2026-08-13 13:09:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault
-
Booking.com-Phishing kurz vor dem Urlaub
-
Booking.com-Phishing kurz vor dem Urlaub
-
Inside Multi-Stage Phishing Redirection Chains
Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.
Pulse ID: 6a7ce26b7815e336e5eee192
Pulse Link: https://otx.alienvault.com/pulse/6a7ce26b7815e336e5eee192
Pulse Author: AlienVault
Created: 2026-08-12 21:15:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #Cloud #CyberSecurity #EDR #HTML #InfoSec #OTX #OpenThreatExchange #Phishing #Rust #bot #AlienVault
-
Inside Multi-Stage Phishing Redirection Chains
Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.
Pulse ID: 6a7ce26b7815e336e5eee192
Pulse Link: https://otx.alienvault.com/pulse/6a7ce26b7815e336e5eee192
Pulse Author: AlienVault
Created: 2026-08-12 21:15:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #Cloud #CyberSecurity #EDR #HTML #InfoSec #OTX #OpenThreatExchange #Phishing #Rust #bot #AlienVault
-
#Phishing: Vermeintlich "wichtige Information" im Namen der #DKB: https://verbraucherzentrale.de/phishing
-
#Phishing: Vermeintlich "wichtige Information" im Namen der #DKB: https://verbraucherzentrale.de/phishing