❌

Reading view

There are new articles available, click to refresh the page.

Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos

An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and […]

The post Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload

A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of the Brazilian-origin banking trojan, first documented in 2019, which has consistently focused on Portuguese-speaking victims rather than domestic Brazilian targets. In the latest campaign, attackers leverage convincing financial-themed phishing emails masquerading as routine […]

The post Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers

Authorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns. The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted […]

The post Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials

Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft that significantly complicate detection and response. APT42, also tracked as TA453 in some reporting, is […]

The post Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks

Kratos, a subscription-based phishing-as-a-service platform, is targeting Microsoft 365 users in the United States, Europe, and other regions through campaigns designed to blend into ordinary document-sharing workflows. The operation abuses trusted services, including Microsoft SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and systeme.io, to deliver links that ultimately redirect recipients to credential-harvesting pages. Only 156 sessions […]

The post Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads

Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investigation links these operations into five interconnected schemes targeting dozens of Turkish banking brands. Group-IB recorded more than 6,600 scam […]

The post Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions

Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with […]

The post SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants

A targeted phishing campaign impersonating the Indian Income Tax Department has been observed delivering a sophisticated, six-stage infection chain that culminates in two in-memory remote-access implants: a Gh0st RAT derivative and a Quasar/AsyncRAT-family .NET payload. Victims are funneled to fake government pages that mimic Ministry of Finance and Income Tax branding and are pressured with […]

The post Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Attackers Exfiltrate AnyDesk Configuration Data via Blat SMTP in Aerospace Phishing Campaign

A targeted spear-phishing campaign that configures AnyDesk for silent, persistent remote access and exfiltrates its configuration using the Blat SMTP utility. The campaign uses an aerospace-themed invoice lure that impersonates the Russian research institute VNIIR via a freshly registered spoof domain (vniir-avia.space) and delivers a password-protected archive that, when opened, triggers a multi-stage dropper and […]

The post Attackers Exfiltrate AnyDesk Configuration Data via Blat SMTP in Aerospace Phishing Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake Interview Phishing Campaign Impersonates Top Brands to Steal Gmail Credentials

A sophisticated interview-themed phishing campaign that impersonates major global brands to harvest Gmail credentials. Attackers pose as recruiters offering marketing roles at well-known companies, leveraging personalized targeting and a layered redirection chain that uses legitimate platforms to mask malicious intent. The result is a convincing lure that directs recipients to a Gmail credential prompt embedded […]

The post Fake Interview Phishing Campaign Impersonates Top Brands to Steal Gmail Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌