Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active „widespread email-driven phishing campaign“ that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. „The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic, Quelle: Zum Originalbeitrag

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake … Weiterlesen

Die Doppel-Überweisung: Wie Kriminelle mit einer Masche zweifach abkassieren wollen

Mit einem Fake-Shop und einem gestohlenen Impressum werden Opfer in eine Falle gelockt, die doppelt zuschnappen soll. Nach erfolgter Bezahlung via Überweisung, erhalten Betroffene eine E-Mail, in der von „Problemen mit dem Banksystem“ die Rede ist. Man solle die alte Überweisung stornieren und den Betrag auf ein anderes Konto transferieren. Quelle: Zum Originalbeitrag

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat Quelle: Zum Originalbeitrag

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. „Greatness supports AiTM [adversary-in-the-middle] credential and Quelle: Zum Originalbeitrag