❌

Reading view

There are new articles available, click to refresh the page.

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting β€œprominent victims, their family members, and personal acquaintances.”

OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

Warning: Replying to a β€œWrong Number” Text Marks You as a Target for Scams

Attackers are using β€œwrong-number” texts to identify potential targets for scams, according to researchers at Malwarebytes.

These texts appear to be harmless messages meant for another person, such as β€œAre we still on for dinner tomorrow?” or β€œWhere’s the PowerPoint?” Recipients often try to be helpful by replying to let the person know they’ve got the wrong number. This reply, however, informs the threat actor that the phone number is active and marks it for future scams.

Attackers Use Vishing Attacks to Distribute New Android Malware

Attackers are distributing a new Android malware called β€œWindRelay” via phone-based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employeesΒ and instruct them to install a malicious app. In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.

❌