Browsing Tag
Phishing
8 posts
Phishing attacks, impersonation scams, and credential theft.
SourTrade Malvertising Makes Browsers Build Malware in Memory
Confiant says the SourTrade malvertising campaign impersonates TradingView, Solana, and Luno, then uses service workers and shared workers to make a victim’s browser assemble a unique Windows malware file in memory. The technique weakens hash-based detection and gives crypto users another reason to avoid sponsored-download paths.
ACR Stealer Turns ClickFix Lures Into Browser-Token Theft
Microsoft says ACR Stealer activity rose across customer environments from late April to mid-June, with campaigns using ClickFix lures, WebDAV, MSHTA, obfuscated PowerShell, and even JPEG-hidden payloads. Security teams should treat infections as token and document-exposure events, not just password resets.
Signal Backup-Key Phishing Turns Account Recovery Into an Espionage Target
The FBI and CISA warn that Russian intelligence-linked actors are impersonating messaging-app support accounts to steal Signal backup recovery keys, verification codes, and account PINs. The attacks do not break encryption, but they can expose message backups and keep account-takeover paths alive until users replace compromised keys.
LastPass Says Klue Breach Exposed Support Case Data, Not Password Vaults
LastPass says attackers used Klue-held OAuth tokens to access customer CRM and support case data in Salesforce, while its password vaults and core infrastructure were not affected. The practical risk is targeted phishing and social engineering built from real support histories.
Android Fake Call Detection Uses RCS to Fight AI Voice Scams
Google’s Android fake call detection uses an encrypted RCS signal in Phone by Google to warn when a saved contact’s number may be spoofed. The protection is useful, but only works when both phones meet the requirements.
Maine’s Fake Breach Notices Expose a New Weak Point in Cyber Reporting
Maine temporarily shut down public access to its breach-notice database after fake Discord and VRChat filings appeared there, showing how official transparency systems can be abused for misinformation.
Google Targets Outsider Enterprise as AI Scam Texts Become Infrastructure
Google says the Outsider Enterprise used phishing kits, fake sites, Telegram coordination, and mass text campaigns to turn scam messages into a repeatable criminal business.