Skip to main content

Social Engineering

Python-Based WhatsApp Worm Exclusive: Dangerous Stealer

Python-Based WhatsApp Worm Exclusive: Dangerous Stealer

What would you do if your WhatsApp started messaging your friends without you? Researchers warn the Delphi-based Eternidade Stealer is hijacking accounts and weaponizing contact lists—using social engineering and IMAP-resolved C2 to spread quickly and dodge static defenses.

Analyst 207
2FA Phishing Kit: Exclusive Alert on Dangerous BitB Pop-ups

2FA Phishing Kit: Exclusive Alert on Dangerous BitB Pop-ups

Think your 2FA push is safe? Browser-in-the-Browser phishing kits like Sneaky 2FA now mimic real browser dialogs to trick users into approving account takeovers, making powerful relay attacks cheap and easy to rent.

Analyst 207
Google Files Lawsuit Against Lighthouse Kit Exclusive Blow

Google Files Lawsuit Against Lighthouse Kit Exclusive Blow

Google just went to court to take apart a sprawling smishing operation it says was run by 25 people tied to a Chinese cyber collective, accusing them of using deceptive texts to spread malware, recruit botnets, and sell stolen credentials. The company is seeking asset freezes and third-party cooperation — pairing legal muscle with technical takedowns to short-circuit the infrastructure behind SMS-based attacks.

Analyst 207
ThreatsDay Bulletin: Exclusive Critical Cyber Roundup

ThreatsDay Bulletin: Exclusive Critical Cyber Roundup

Every click can be the opening move in a campaign of trust-based deception. This bulletin shows how fast-moving actors like COLDRIVER are making signatures obsolete and why shifting to behavioral, intent-driven defenses is now essential.

Analyst 207
Quantum Route Redirect Phishing Kit: Stunningly Dangerous

Quantum Route Redirect Phishing Kit: Stunningly Dangerous

The Quantum Route Redirect phishing kit quietly hijacks web traffic, rerouting victims to eerily convincing fake sites. Learn how this route redirect phishing attack works and what you can do to stay one step ahead.

Analyst 207
China-Aligned UTA0388 Exclusive: Dangerous AI Phishing

China-Aligned UTA0388 Exclusive: Dangerous AI Phishing

Imagine your inbox posing as a trusted colleague—researchers say UTA0388, a China‑aligned cluster, now uses AI to craft eerily personalized, time‑sensitive spear‑phishing that steals credentials and plants stealthy, long‑term access.

Analyst 207
ClickFix Phishing Exclusive: Critical Hotel Malware Alert

ClickFix Phishing Exclusive: Critical Hotel Malware Alert

Imagine a routine support ticket that silently installs malware—attackers are using ClickFix‑style pages sent from compromised hotel emails to steal credentials or drop remote‑access tools like PureRAT. Be cautious: don’t paste commands or log in from unexpected support links—verify the sender and the page first.

Analyst 207
Google Maps Launches Exclusive Effortless Tool vs Extortion

Google Maps Launches Exclusive Effortless Tool vs Extortion

When a one-star review reads like a ransom note, Google Maps is giving small businesses a direct line to fight back. The new dedicated form makes reporting review bombing and extortion attempts effortless, helping protect reputations and revenue.

Analyst 207
I Paid Twice Phishing: Exclusive Scam Alert for Booking.com

I Paid Twice Phishing: Exclusive Scam Alert for Booking.com

Think you paid the hotel twice? A sophisticated I Paid Twice phishing campaign is hijacking Booking.com, Airbnb and Expedia bookings—using injected scripts and fake payment pages to trick travelers into handing over extra payments.

Analyst 207
Tangled fishing lines and hooks on a cluttered academic desk with scattered papers and broken stationery, featuring a shiny…

UNK_SmudgedSerpent Exclusive: Dangerous Lures for Academics

Think your inbox is just clutter? A newly observed actor, UNK_SmudgedSerpent, is luring academics with plausible conference invites, fake collaboration requests and weaponized drafts to steal unpublished research and private correspondence—forcing universities to choose between openness and much tougher defenses.

Analyst 207
Dark, ominous nighttime scene of a tech company HQ with a serpentine shadow coiled around shattered devices and scattered…

SmudgedSerpent Exclusive: Dangerous Hackers Target Experts

Meet SmudgedSerpent: during the summer 2025 Iran–Israel flare-up a stealthy cyber cluster used precision social engineering to target academics and policy experts. By exploiting researchers’ networks and unpublished work, these attacks show how adversaries now shape information and influence far faster than old‑school espionage.

Analyst 207
Cybercriminals Targeting Payroll Sites Exclusive Warning

Cybercriminals Targeting Payroll Sites Exclusive Warning

Imagine your paycheck landing in a strangers account—criminals are targeting payroll systems with social‑engineering scams that hijack credentials and reroute direct deposits. Simple fixes like multi‑factor authentication, tighter admin privileges, and out‑of‑band approvals can stop them before paychecks disappear.

Analyst 207
Scattered Spider Exclusive: Dangerous Unified Collective

Scattered Spider Exclusive: Dangerous Unified Collective

Imagine low‑tech social engineering and SIM swaps teaming up with mass data brokers — that’s Scattered Spider, ShinyHunters and LAPSUS$ fusing tactics to turn bulk theft into pinpoint extortion. Security teams and cloud customers now face a hybrid, high‑leverage threat targeting SaaS platforms like Salesforce.

Analyst 207
Teams Flaw: Stunning Reveal of Critical Boss Spoofing

Teams Flaw: Stunning Reveal of Critical Boss Spoofing

A newly revealed Microsoft Teams vulnerability let attackers convincingly impersonate executives, forge messages and even rewrite chat history—turning everyday collaboration into a pathway for fraud and data theft. Learn how Check Point’s findings expose the danger of boss‑spoofing and what organizations need to patch now.

Analyst 207
Person's hand grips smartphone with eerie glow, shadowy figure lurks in background.

Social Engineering: Exclusive Tips to Stop Costly Fraud

Think a caller with a supervisor sounds legit? Social engineering preys on our trust — and with leaked data and mass spoofing it can cost you dearly; these exclusive, easy-to-follow tips will help you spot scams and shut them down.

Analyst 207
Person staring at laptop with concern, surrounded by ghostly figures making phone calls in a dark cityscape.

Europol Exclusive: Alarming Rise in Caller ID Spoofing

Europol’s recent takedown ripped the curtain back on how caller ID spoofing and SIM farms let criminals rent anonymity at scale — a win that still reads like a warning. With fraudsters shifting to SIMless virtual numbers and VoIP farms, the phone number we trust as ID has become a commodity for scams.

Analyst 207
Shaq’s new ride Exclusive: Costly Hijack Exposed

Shaq’s new ride Exclusive: Costly Hijack Exposed

Shaq’s new ride reveals a surprising weak spot: when celebrities rely on niche customization shops for bespoke engineering, those small specialists — holding valuable blueprints and client data — become prime targets for savvy criminals. A breach can mean leaked designs, stolen invoices and lucrative leverage for extortion.

Analyst 207
Iran’s MuddyWater: Stunning, damaging 100+ network breach

Iran’s MuddyWater: Stunning, damaging 100+ network breach

A single hijacked government mailbox became MuddyWater’s battering ram, letting Tehran-linked operators quietly harvest credentials and pivot into 100+ networks across the Middle East and North Africa. It’s a stark reminder that low-cost social engineering and trusted infrastructure can give attackers exponential reach without a single zero-day.

Analyst 207
SpaceX Exclusive: Cuts 2,500 Starlink Terminals, Major Hit

SpaceX Exclusive: Cuts 2,500 Starlink Terminals, Major Hit

When investigators found scam camps and trafficking rings using consumer Starlink terminals to run cyber‑fraud and “cyber‑slavery,” SpaceX pulled the plug on about 2,500 devices — a bold move to stop connectivity from enabling exploitation.

Analyst 207
Blitz Spear Phishing Campaign Exclusive: NGOs at Risk

Blitz Spear Phishing Campaign Exclusive: NGOs at Risk

Imagine the inbox that coordinates relief suddenly opening the door to attackers: a one-day spear-phishing blitz—dubbed PhantomCaptcha—targeted NGOs and regional offices helping Ukraine with convincing impersonations and weaponized attachments to harvest credentials and deploy malware. It’s a stark reminder that adversaries now weaponize trust and identity to disrupt aid, not just networks.

Analyst 207
Blitz Spear Phishing Campaign Exclusive: Severe NGO Threat

Blitz Spear Phishing Campaign Exclusive: Severe NGO Threat

What do you do when a helpful-looking email hands attackers your keys? In October’s PhantomCaptcha spear‑phishing campaign, NGOs and local governments supporting Ukraine were hit with short, surgical, time‑sensitive lures and weaponized attachments that harvested credentials and opened the door to loaders and remote access trojans.

Analyst 207
Dark laptop screen with distorted CAPTCHA, Ukraine map, cracked glass, and ominous glowing eyes in shadows.

PhantomCaptcha Campaign: Stunning Threat to Ukraine Aid

What if the message promising help handed attackers the keys? The PhantomCaptcha campaign did exactly that — a surgical phishing blitz using believable impersonation and innocuous-looking attachments to steal credentials and threaten Ukraine relief efforts.

Analyst 207
PhantomCaptcha Campaign Exclusive: Critical Ukraine Threat

PhantomCaptcha Campaign Exclusive: Critical Ukraine Threat

Meet the PhantomCaptcha campaign: a short, surgical phishing blitz that tricks aid groups with believable emails and weaponized attachments to steal credentials and install persistent backdoors. The result puts NGOs, local governments and Ukraine relief efforts at risk of disrupted operations, exposed donor and logistics data, and long‑term compromise.

Analyst 207
PhantomCaptcha Campaign: Exclusive Danger to Ukraine Relief

PhantomCaptcha Campaign: Exclusive Danger to Ukraine Relief

PhantomCaptcha hijacks trusted-looking emails to trick aid workers into opening weaponized attachments that install credential stealers and remote access tools, risking disruption of Ukraine relief operations. Learn its tradecraft—plausible senders, urgent subjects, and innocuous file types—so a single click doesn’t hand attackers the keys.

Analyst 207