Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal
Normal view
-
KnowBe4 Security
- Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy
Anatomy of an Agent Tesla BEC Attack: From Inbox to In-Memory Infostealer
The Blind Spot: How βBulletproofβ Phishing Redirectors Slip Past SEGs
By Shikhar Dalela and Jeewan Singh Jalal
The operators named the kit themselves.
Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called β/.bulletproofβ, and the PHP session cookie the kit sets on every visitor is named βbp_redir_sess.β The βbpβ stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.
Inside the OS-Aware Phishing Kit Profiling Your Device
From Inbox to Encryption: How Ransomware Delivery Has Evolved
Cybercriminals Are Targeting the FIFA World Cup 2026
Lead Analysts: Jeewan Singh Jalal and Louis Tiley
KnowBe4 ThreatLabs tracked phishing campaign activity from the first week of April through June 22, 2026 β covering the pre-tournament build-up, tournament kickoff and the first twelve days of live match play. Our latest intelligence adds crucial mid-tournament telemetry (June 15-22), a newly identified reply-back campaign track and additional infrastructure intelligence.