❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 24 July 2026Hacking and InfoSec

Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos

By: Divya
24 July 2026 at 08:57

An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and […]

The post Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload

24 July 2026 at 03:00

A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of the Brazilian-origin banking trojan, first documented in 2019, which has consistently focused on Portuguese-speaking victims rather than domestic Brazilian targets. In the latest campaign, attackers leverage convincing financial-themed phishing emails masquerading as routine […]

The post Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayHacking and InfoSec

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

23 July 2026 at 12:00

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called β€œJalisco,” is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

22 July 2026 at 16:00

Threat actors are using a new technique called β€œphantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42.

Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.

Warning: ARToken Phishing Kit Automates BEC Attacks

22 July 2026 at 12:00

Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called β€œARToken” that’s built on the EvilTokens phishing platform. ARToken focuses on targeted social engineering attacks, allowing operators to customize phishing attempts for each victim.

Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers

By: Divya
22 July 2026 at 02:41

Authorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns. The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted […]

The post Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials

21 July 2026 at 04:40

Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft that significantly complicate detection and response. APT42, also tracked as TA453 in some reporting, is […]

The post Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks

16 July 2026 at 02:36

Kratos, a subscription-based phishing-as-a-service platform, is targeting Microsoft 365 users in the United States, Europe, and other regions through campaigns designed to blend into ordinary document-sharing workflows. The operation abuses trusted services, including Microsoft SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and systeme.io, to deliver links that ultimately redirect recipients to credential-harvesting pages. Only 156 sessions […]

The post Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Report: Social Engineering Remains a Central Part of AI-assisted Attacks

15 July 2026 at 09:00

Threat actors continue to rely on social engineering as AI is incorporated into their attacks, according to ESET’s Threat Report for the first half of 2026.

ESET’s Director of Threat Prevention Labs, JiΕ™Γ­ KropÑč, stated, β€œRather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviors. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface.”

Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads

14 July 2026 at 08:13

Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investigation links these operations into five interconnected schemes targeting dozens of Turkish banking brands. Group-IB recorded more than 6,600 scam […]

The post Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs

10 July 2026 at 09:00

An initial access broker associated with the Payouts King ransomware group is using Microsoft Teams phishing to deploy a malicious Microsoft Edge web browser extension, according to researchers at Zscaler. Once the hackers have a foothold within an organization, they sell the access to the ransomware gang to conduct follow-on attacks.

Invoice Phishing Attacks Are Abusing the Shop App

9 July 2026 at 16:00

Threat actors are abusing Shop, a legitimate app developed by Shopify, to launch phishing attacks, according to researchers at Gen Digital. Shop is used for making purchases and tracking orders, but threat actors are exploiting the platform to generate in-app notifications for phony invoices.

SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions

9 July 2026 at 03:15

Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with […]

The post SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants

8 July 2026 at 02:18

A targeted phishing campaign impersonating the Indian Income Tax Department has been observed delivering a sophisticated, six-stage infection chain that culminates in two in-memory remote-access implants: a Gh0st RAT derivative and a Quasar/AsyncRAT-family .NET payload. Victims are funneled to fake government pages that mimic Ministry of Finance and Income Tax branding and are pressured with […]

The post Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌