PhishingSecurityWeek·2 days ago

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Researchers have identified iAuthFlow V2, a phishing toolkit that exploits passkey authentication by registering attacker-controlled passkeys to maintain persistent access to compromised accounts. This capability allows attackers to retain access even after victims reset their passwords or revoke active sessions, representing a significant evolution in phishing attack sophistication that targets modern authentication mechanisms.

PhishingHelp Net Security·2 days ago

A $25 template helped scammers build hundreds of phantom bank domains

Researchers at Allure Security discovered a widespread scam operation leveraging a cheap website template to create hundreds of fraudulent bank domains designed to deceive victims. The investigation began when a suspicious domain mimicking a legitimate financial services client was found hosting an unrelated bank's branding, ultimately revealing a coordinated scheme to build phantom banking sites for scamming purposes. The $25 template appears to have been a key tool enabling scammers to rapidly deploy deceptive financial websites at scale.

PhishingThe Register·2 days ago

Russian snoops add OAuth abuse to targeted phishing campaigns

Russian threat actors are incorporating OAuth abuse tactics into their targeted phishing campaigns, leveraging legitimate authentication mechanisms to compromise victims. The attacks specifically impersonate State Department communications, making them particularly credible to government and diplomatic personnel.

PhishingUnit 42·3 days ago

Identity Abuse Through Trusted Communication Channels

Attackers are exploiting trusted enterprise collaboration tools to conduct identity phishing and steal credentials from organizations. Unit 42 provides analysis of these attack techniques and outlines key defensive strategies to mitigate the threat.

PhishingThe Hacker News·4 days ago

Phishing 3.0: The Fight Moves to Agent Versus Agent

Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad

PhishingMalwarebytes Labs·4 days ago

Scammers are using fake crypto AML checkers to drain your wallet

Scammers have created fraudulent wallet-checking websites that impersonate legitimate anti-money laundering services to deceive users into granting unauthorized access to their cryptocurrency wallets. These fake AML checkers exploit users' trust in compliance tools, enabling attackers to drain funds from victims' digital assets. Security professionals should alert users to verify the authenticity of AML services and be cautious when approving wallet access permissions.

PhishingMalwarebytes Labs·4 days ago

Your polite reply to that text is worth $2 on the dark web

Scammers exploit victims' politeness by using replies to wrong-number texts as a profiling mechanism, gathering intelligence that feeds into larger fraud operations worth billions of dollars. What appears to be a harmless courtesy response can mark someone as an engaged target, with that information reportedly valued at approximately $2 on dark web markets. This tactic highlights how even minor interactions can expose users to coordinated social engineering schemes.

PhishingRapid7 Blog·6 days ago

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 researchers uncovered Operation ASTERIX, an active cryptocurrency fraud pipeline that combined phishing, vishing, and counterfeit wallet applications to steal recovery phrases from crypto users across 54 countries. The exposed infrastructure revealed the operator extensively leveraged AI coding assistants for development—and when one model resisted obfuscation tasks, switched providers and deployed a sophisticated multi-stage jailbreak prompt targeting the new model's safety controls. The campaign demonstrates how threat actors are integrating AI tools throughout malware development workflows rather than using them for isolated code snippets, with account enumeration, enriched lead databases, and coordinated voice-calling automation all supporting the theft operation.

PhishingSchneier on Security·6 days ago

Hacking Public Wi-Fi DNS to Steal Credentials

Attackers are compromising public Wi-Fi access points at hotels and conference centers globally to modify DNS configurations and redirect users to fraudulent login pages designed to harvest credentials. This attack vector exploits the trust users place in legitimate network infrastructure at these venues, making it an effective method for large-scale credential theft.

PhishingHuntress Blog·1 week ago

Fake Refund Scam Hits Shopify Shop App Users

Shopify Shop app users are being targeted by a fake refund scam that has been active for several months, with fraudsters operating directly within the application itself. Security professionals should be aware of this threat vector targeting a widely-used mobile commerce platform and the social engineering tactics being leveraged against its user base.

PhishingGraham Cluley·1 week ago

Smashing Security podcast #480: This is the AI service you should never sign up to

A fraudulent service called "Poison Claude" is luring users with counterfeit discounts on Anthropic's Claude AI, demonstrating how attackers exploit popular AI tools to compromise victims. Additionally, a phishing-as-a-service platform named "Greatness" has developed a sophisticated attack that leverages legitimate Microsoft login pages to bypass traditional security indicators and gain full organizational access without requiring fake URLs or password theft.

PhishingCheck Point Research·1 week ago

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Check Point Research has tracked a resurgence of the Operation Dream Job campaign since early 2026, which primarily targets the defense sector with focus on aerospace and aviation companies. The threat actors distribute modified PDF viewers that execute malicious payloads embedded in specially crafted files, using fake job offers as a social engineering vector. This campaign demonstrates how threat actors exploit industry-specific targeting and trusted application types to deliver zero-day exploits against critical infrastructure sectors.