-
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ong…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of the Brazilian-origin banking trojan, first documented in 2019, which has consistently focused on…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Authorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated so…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


