Smashing Security podcast #480: This is the AI service you should never sign up to
A fraudulent service called "Poison Claude" is luring users with counterfeit discounts on Anthropic's Claude AI, demonstrating how attackers exploit popular AI tools to compromise victims. Additionally, a phishing-as-a-service platform named "Greatness" has developed a sophisticated attack that leverages legitimate Microsoft login pages to bypass traditional security indicators and gain full organizational access without requiring fake URLs or password theft.
Researchers have identified iAuthFlow V2, a phishing toolkit that exploits passkey authentication by registering attacker-controlled passkeys to maintain persistent access to compromised accounts. This capability allows attackers to retain access even after victims reset their passwords or revoke active sessions, representing a significant evolution in phishing attack sophistication that targets modern authentication mechanisms.
Researchers at Allure Security discovered a widespread scam operation leveraging a cheap website template to create hundreds of fraudulent bank domains designed to deceive victims. The investigation began when a suspicious domain mimicking a legitimate financial services client was found hosting an unrelated bank's branding, ultimately revealing a coordinated scheme to build phantom banking sites for scamming purposes. The $25 template appears to have been a key tool enabling scammers to rapidly deploy deceptive financial websites at scale.
Russian threat actors are incorporating OAuth abuse tactics into their targeted phishing campaigns, leveraging legitimate authentication mechanisms to compromise victims. The attacks specifically impersonate State Department communications, making them particularly credible to government and diplomatic personnel.
Attackers are exploiting trusted enterprise collaboration tools to conduct identity phishing and steal credentials from organizations. Unit 42 provides analysis of these attack techniques and outlines key defensive strategies to mitigate the threat.
Smashing Security podcast #480: This is the AI service you should never sign up to | Threat Hunters Journal