Tycoon and Storm-1575 Linked to Phishing Attacks on US Schools

By Deeba Ahmed
Tycoon and Storm-1575 threat actors launched targeted spear phishing attacks to bypass MFA protections, targeting officials at large US school districts.
This is a post from HackRead.com Read the original post: Tycoon and Storm-1575 Link… Continue reading Tycoon and Storm-1575 Linked to Phishing Attacks on US Schools

Spam and phishing in 2023

This report contains spam and phishing statistics for 2023, along with descriptions of the main trends, among these artificial intelligence, instant messaging phishing, and multilingual BEC attacks. Continue reading Spam and phishing in 2023

Hundreds of orgs targeted with emails aimed at stealing NTLM authentication hashes

A threat actor specializing in establishing initial access to target organizations’ computer systems and networks is using booby-trapped email attachments to steal employees’ NTLM hashes. Why are they after NTLM hashes? NT LAN Manager (NTLM… Continue reading Hundreds of orgs targeted with emails aimed at stealing NTLM authentication hashes

New CHAVECLOAK Banking Trojan Targets Brazilians via Malicious PDFs

By Deeba Ahmed
The CHAVECLOAK banking Trojan employs PDFs, ZIP downloads, DLL sideloading, and deceptive pop-ups to target Brazil’s unsuspecting banking users financial sector. 
This is a post from HackRead.com Read the original post: New CHAVECLOAK Ba… Continue reading New CHAVECLOAK Banking Trojan Targets Brazilians via Malicious PDFs

Phishers target FCC, crypto holders via fake Okta SSO pages

A new phishing campaign is using fake Okta single sign-on (SSO) pages for the Federal Communications Commission (FCC) and for various cryptocurrency platforms to target users and employees, Lookout researchers have discovered. The phishing campaign By … Continue reading Phishers target FCC, crypto holders via fake Okta SSO pages

95% believe LLMs making phishing detection more challenging

More than 95% of responding IT and security professionals believe social engineering attacks have become more sophisticated in the last year, according to LastPass. Recent AI advancements, particularly generative AI, have empowered cybercriminals to co… Continue reading 95% believe LLMs making phishing detection more challenging