Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
A new Russian loader-as-a-service (LaaS) operation named DOUBLECUP is leveraging ClickFix social engineering lures and steganographic PNG images cached in victims' browsers…
DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since June 2026. It uses ClickFix lures and steganographic PNG images to deliver malware…
The Chinese cybercrime group Silver Fox has been observed targeting a Japanese industrial manufacturing organization with a sophisticated attack chain that leverages…
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies to siphon funds…
The Federal Security Service of the Russian Federation (FSB) has charged Telegram founder Pavel Durov with aiding terrorist activity and failing to…
TA4922 is a Chinese-speaking cybercrime actor associated with tax-themed phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams. The group…
The operators of the DevMan ransomware-as-a-service (RaaS) scheme maintain a dedicated web platform that offers affiliates the ability to build payloads, oversee…
eCrime.ch, a Swiss cybercrime monitoring platform, contributed to attributing the Windchill web shell to Clop.
Golden Chickens, also tracked as Venom Spider and TAG-195, is a financially motivated malware-as-a-service developer. It has resurfaced with four new malware…