KeyVal Used as Dead Drop Resolver in Phishing Campaign
KeyVal is a free public key-value store that developers use via REST API. In this campaign, it was abused as a dead…
KeyVal is a free public key-value store that developers use via REST API. In this campaign, it was abused as a dead…
Google Chrome's Safe Browsing blocklist was used to block a typosquatted Microsoft login domain used in the campaign, prompting the threat actor…
The remote logic in the campaign currently redirects victims to the legitimate ChatGPT website, but could be weaponized to deliver ClickFix or…
A large-scale phishing campaign dubbed Mirage2FA has impacted over 4,500 organizations in the US and EU, abusing Microsoft 365 login flows to…
Mirage2FA is a commercial phishing-as-a-service toolkit that targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. Active from…
SynkLoader is a Python-based loader distributed through Microsoft Teams phishing, presenting as a PowerShell Cleaner. It installs multiple modules including a fake…
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit Ravie LakshmananAug 24, 2026Cybercrime / Malware Cybersecurity…
Suspected Russian cyber espionage groups are abusing legitimate authentication flows, including Google OAuth and WhatsApp device linking, to hijack accounts across Europe…
UNC6293 is a suspected Russian cyber espionage sub-cluster of Ice Relic (APT29), first detailed in June 2025. It conducts small-scale phishing campaigns…
Vidar is a commodity infostealer used by UNC7005 to siphon data from Windows hosts. It is distributed via malicious URLs and phishing…