home.social

#spearphishing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.

fetched live
  1. Iranian Hackers Deploy Cross-Platform Malware via Coding Tests

    Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote…

    osintsights.com/iranian-hacker

    #IranianHackers #Noderabbit #CrossplatformMalware #Spearphishing #Linkedin

  2. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  3. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  4. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  5. Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...

    Indicators extracted from public reporting. Source: reddit.com/r/netsec/comments/1

    Pulse ID: 6a85e02d9151a30aa821db6a
    Pulse Link: otx.alienvault.com/pulse/6a85e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 16:56:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL

  6. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  7. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  8. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  9. Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan

    Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise.

    insicurezzadigitale.com/operat

  10. Фейковый грант от NED: анатомия таргетированного фишинга

    18 февраля 2026 года сотрудник НКО получил таргетированное фишинговое письмо якобы от National Endowment for Democracy — американского фонда поддержки демократии. Обращение по полному имени, ссылка на «предыдущую заявку на грант» (которой никогда не было), и упоминание документа, которого физически нет в письме — классическая техника «фантомного вложения», при которой первое письмо устанавливает доверие, а вредоносный файл приходит уже в ответ на реакцию жертвы. В этой статье — разбор атаки по заголовкам, инфраструктуре и социальной инженерии. Материал будет полезен аналитикам SOC и сотрудникам НКО: в конце — IOC, kill chain и рекомендации для администраторов почты.

    habr.com/ru/articles/1004156/

    #информационная_безопасность #фишинг #spearphishing #threat_intelligence #социальная_инженерия #email_security

  11. Фишинг под видом Meta: SPF pass, DKIM pass, входящие Gmail

    2 марта 2026 года я получил на анализ фишинговое письмо. Отправитель - «M e t a», тема - «[Требуется действие] Завершите проверку, чтобы восстановить показ объявлений». SPF pass, DKIM pass, ARC pass - письмо прошло все проверки и лежало во входящих Gmail. Ключ - цепочка Resend.com → Amazon SES → Gmail, где каждый элемент легитимен. Разбираю, как атакующие этого добились и почему это работает.

    habr.com/ru/articles/1005750/

    #информационная_безопасность #фишинг #spearphishing #threat_intelligence #социальная_инженерия #email_security

  12. Krasser Scheiß: Pine64 (ein Lieferant von uns) hat mich grad darüber informiert, dass anscheinend eine #spearPhishing attacke auf uns vorbereitet worden ist (zumindest stellt es sich mir so dar).

    "Tom Milton" hat sich bei dem Lieferanten als neuer "Lead Accountant" vorgestellt.

    ich gehe davon aus, dass der liebe Tom dann gefälschte Rechnungen an uns geschickt hätte....

    Was denkt ihr?

    #hacking #phishing #krasserScheiß #security

  13. A five-month spearphishing operation discovered by Socket has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.

    Read More: security.land/npm-registry-wea

    #SecurityLand #Cybersecurity #Research #NPM #Phishing #CriticalInfrastructure #AiTM #Spearphishing #Dev

  14. There's a new look to modern day #ransomware attacks (no) thanks to the Ransomware-as-a-Service (#RaaS) ecosystem. As attackers continue to automate spear #phishing and other processes, identifying and mitigating these email threats becomes both more important and more challenging. 😓 So, let's talk about how your team can improve their risk mitigation strategies.

    In this article we review:
    🎣 Phishing, spear phishing, and whaling
    📧 Why ransomware email threats are so successful
    🛡️ Best practices for mitigating these threats

    Dig into the details of implementing email security, centralizing security data, integrating threat intelligence, identifying very attacked persons (VAPs), and more.

    graylog.org/post/understanding #SpearPhishing #ThreatIntel #SIEM #CyberSecurity

  15. 🚨 The OpenAI/Mixpanel breach is not just a "vendor issue"—it's a systemic failure. We analyzed 3 years of security incidents at OpenAI and compared them to the fortified architectures of Google Gemini and Anthropic Claude.

    #SecurityLand #ExpertDecode #AI #SecurityBreach #Cyberattack #OpenAI #ChatGPT #Claude #Gemini #SpearPhishing #Business #Enterprise #Mixpanel

    Read More: security.land/openai-mixpanel-