Skip to main content

Tag: credential harvesting

87 articles

Person's hand holds smartphone in brightly-lit urban setting with subtle hint of unease.

Chinese Phishing Services Shift to Live Credential Interception Tactics

Cyber attackers are now using live administration panels to interact with victims in real-time, capturing one-time passcodes and instantly bypassing multifactor authentication protections. This new tactic allows them to neutralize security measures and steal sensitive information more effectively.

Analyst 207
Dimly lit network closet with disarrayed cables and equipment.

Malware Worm Eliminates Rival, Seizes Control

Meet the malware worm with a ruthless streak - it not only eliminates rival malware from infected systems, but also seizes control and claims the compromised credentials for itself. This cunning worm is taking over, leaving other malicious operators with nothing.

Analyst 207
Students work on laptops in a dimly lit university computer lab with scattered papers and blurred screens.

MicroStealer Targets Education, Telecom with Credential Theft FTC Cracks Down on Kochava's Location Data Practices Proton Mail Adds Quantum-Safe Encryption Supply Chain Hardened with pnpm 11 Release Meta Deploys AI for Underage Enforcement North Korea-Linked Cybercrime Case Upheld ICS Security Flaws Disclosed in Eclipse BaSyx MOVEit Automation Exposes Critical Vulnerability VECT Ransomware Encryption Flaws Discovered Oracle Accelerates Patching with

MicroStealer malware is on the loose, targeting education and telecom sectors with a sneaky credential theft attack that's harvesting sensitive data, including browser credentials, cryptocurrency wallets, and system info. This stealthy threat uses a multi-stage delivery chain to quickly swipe valuable info and send it to hackers.

Analyst 207
Cluttered home office setup with gaming console and laptop surrounded by papers and snack packaging.

Ukraine Arrests Hackers Behind 610,000 Roblox Account Breach

Ukrainian authorities have cracked down on a group of hackers responsible for breaching over 610,000 Roblox accounts in a months-long phishing scam that harvested credentials and tokens. The stolen access was used to snag in-game items and Robux, Roblox's virtual currency.

Analyst 207
Windows computer workstation in an office setting with router and cables, and a blank laptop screen on the desk.

Python Backdoor Exploits Tunneling Service to Harvest Browser, Cloud Credentials

Meet DEEP#DOOR, a sneaky Python-based backdoor framework that's harvesting browser and cloud credentials by exploiting a tunneling service, and learn how it infiltrates systems through a clever sequence of stealthy steps. This sophisticated threat starts with a simple batch script that disables Windows security controls and ends with a fully featured Remote Access Trojan (RAT).

Analyst 207
Person at desk looks at laptop with Microsoft Teams on screen, background webpage blurred.

Google Exposes Microsoft Teams Phishing Campaign Using Custom Snow Malware

Beware of scammers posing as helpdesk heroes! They'll flood your inbox with spam, then reach out on Microsoft Teams with a fake fix that actually steals your password using custom Snow malware.

Analyst 207
Person sitting in dark room with laptop showing fake login prompt and nearby smartphone and torn paper with credentials.

macOS ClickFix Attacks Harvest Credentials via AppleScript Stealers

macOS users beware: a sneaky ClickFix campaign is using AppleScript stealers to harvest credentials from 14 browsers, 16 cryptocurrency wallets, and over 200 extensions. This targeted attack has already made off with a staggering amount of sensitive info - and it's still on the loose.

Analyst 207
Shadowy figure looms behind a login page on a laptop screen, poised to submit credentials.

VENOM Phishing Attacks Target C-Suite Microsoft Logins

A new phishing-as-a-service platform called VENOM is making it alarmingly easy for hackers to target senior executives, specifically seeking their Microsoft logins. This compact toolkit is putting the keys to the corner office within reach of any motivated adversary, leaving security teams scrambling to respond.

Analyst 207
Shadowy figure holds damaged laptop amidst glowing code, set against a dark cityscape and Russian map backdrop.

Feds Disrupt Russia-Backed Espionage Network Infecting 18,000 Devices

Federal authorities have successfully disrupted a massive Russia-backed espionage operation that had infiltrated nearly 18,000 devices, stealing sensitive account credentials and tokens by hijacking internet traffic. This significant takedown thwarts the efforts of Forest Blizzard, a notorious threat group linked to Russia's GRU.

Analyst 207
LiteLLM Supply-Chain Compromise Exposes Mercor Data

LiteLLM Supply-Chain Compromise Exposes Mercor Data

A single faulty AI dependency can become a backdoor for attackers - as seen in the recent LiteLLM supply-chain compromise that exposed sensitive data, source code, and internal credentials at Mercor. This alarming incident highlights the risks of relying on third-party dependencies and the importance of securing your supply chain.

Analyst 207
Hackers Exploit React2Shell Flaw to Breach 766 Next.js Hosts

Hackers Exploit React2Shell Flaw to Breach 766 Next.js Hosts

In a massive credential harvesting operation, hackers exploited the React2Shell vulnerability to breach 766 Next.js hosts, scooping up sensitive database credentials, SSH private keys, and other valuable secrets. This single software flaw was turned into an automated threat, compromising hundreds of sites and putting their digital kingdoms at risk.

Analyst 207
Phantom Stealer Emerges as Sophisticated Stealer-as-a-Service Tool

Phantom Stealer Emerges as Sophisticated Stealer-as-a-Service Tool

Imagine your entire online life being stolen and sold for just a few hundred dollars - that's the harsh reality with Phantom Stealer, a powerful and stealthy tool that's making it easy for cybercriminals to get their hands on your sensitive information. This sophisticated .NET-based stealer can harvest everything from login credentials to payment card details, putting your digital identity at risk.

Analyst 207
Cisco Hit by Alarming Code Heist After Trivy Breach

Cisco Hit by Alarming Code Heist After Trivy Breach

A shocking code heist has hit Cisco, with hackers making off with sensitive source code after infiltrating the company's internal development environment through a Trivy supply-chain attack. This brazen breach raises urgent questions about the hidden vulnerabilities lurking in today's interconnected development ecosystems.

Analyst 207
Multifaceted Phishing Scheme Stunningly Damages Bitpanda

Multifaceted Phishing Scheme Stunningly Damages Bitpanda

Thousands of Bitpanda users are reeling after a sophisticated phishing campaign spun up convincing lookalike sites—with disposable domains and SSL certificates—to harvest credentials and fuel criminal markets. The attack shows how industrialized phishing‑as‑a‑service turns takedown efforts into whack‑a‑mole, leaving customers, companies and regulators scrambling to restore digital trust.

Analyst 207
TGR-STA-1030 Exclusive: Severe Breach Hits 70 Sites

TGR-STA-1030 Exclusive: Severe Breach Hits 70 Sites

Meet TGR-STA-1030: a stealthy Asia-based espionage crew that’s quietly breached at least 70 government and critical‑infrastructure networks across 37 countries, using bespoke tools, credential harvesting and meticulous reconnaissance to keep long‑term, hard-to-detect access to telecom and communications systems.

Analyst 207
LastPass Warns: Critical Phishing Steals Master Passwords

LastPass Warns: Critical Phishing Steals Master Passwords

If you get a frantic LastPass email demanding a 24‑hour backup, pause — its a phishing campaign trying to steal your master password, the single key that unlocks everything in your vault. Never click the links or enter your master password — LastPass will never ask for that.

Analyst 207
Phishing Attacks Exclusive: Critical Risk to Microsoft 365

Phishing Attacks Exclusive: Critical Risk to Microsoft 365

Think an email from your CEO is safe? Microsoft 365 phishing campaigns now use cloud misconfigurations and device-code tricks to make external messages look internal and steal authentication tokens or MFA codes.

Analyst 207
Android TV: Must-Read Botnet Risk Alert

Android TV: Must-Read Botnet Risk Alert

Before you plug in that bargain Android TV box, know this: researchers say some models secretly route other peoples internet traffic through your home, effectively turning the device into a botnet node and putting you at risk of fraud and legal trouble.

Analyst 207
QR codes Exclusive Threat: Pyongyang’s Dangerous Phishing

QR codes Exclusive Threat: Pyongyang’s Dangerous Phishing

Think twice before you scan: the FBI warns North Korean hackers are using QR-based quishing to turn innocent-looking codes into multi-step traps that steal cloud credentials and bypass enterprise defenses.

Analyst 207
QR codes Stunning Pyongyang Phishing Threat

QR codes Stunning Pyongyang Phishing Threat

QR codes have gone from handy shortcuts to attack vectors—North Korean actors are using QR-based phishing to steal cloud credentials by hiding multi-step payloads inside seemingly legitimate scans. The real question now isnt whether to scan, but how to verify what the square tells you.

Analyst 207
FBI Reveals Stunning Rise in Costly AI Phishing Scams

FBI Reveals Stunning Rise in Costly AI Phishing Scams

Imagine a voicemail that sounds exactly like your daughter begging for help — only its a scam. The FBI warns cheap AI tools are fueling a surge of hyper‑personalized phishing scams that have already cost victims hundreds of millions and can fool individuals, businesses, and banks alike.

Analyst 207
Smishing Triad Impersonation Campaigns: Exclusive Threat

Smishing Triad Impersonation Campaigns: Exclusive Threat

Think that bank-looking text is really from your provider? Smishing Triad attackers now pair believable sender IDs with lookalike Egyptian domains, SIM farms and hijacked devices to harvest credentials and bypass 2FA—one click can mean compromise.

Analyst 207
FlexibleFerret Exclusive: Dangerous macOS Go Backdoor

FlexibleFerret Exclusive: Dangerous macOS Go Backdoor

Think a harmless Mac script cant hurt? FlexibleFerret proves otherwise — a modular, multistage campaign that uses staged shell/AppleScript and a Go-based backdoor to quietly harvest credentials and maintain stealthy, long-term access across macOS systems.

Analyst 207
CTM360 Exclusive: Alarming WhatsApp Hijack Campaign Exposed

CTM360 Exclusive: Alarming WhatsApp Hijack Campaign Exposed

CTM360 exposes HackOnChat, a clever and dangerous campaign that clones WhatsApp Web to trick users into revealing authentication codes and handing over their accounts. With thousands of malicious URLs and coordinated fronts, this WhatsApp account hijacking operation is alarmingly scalable and hard to takedown.

Analyst 207