ZCyberNews
中文

#phishing

54 articles

Financial services, government, and hospitality organisations bore the brunt of a concentrated phishing wave between 8 April and 13 May 2026, with 61 incidents logged. Threat actors Silver Fox, AccountDumpling, and Bluekit were observed exploiting vulnerabilities including CVE-2023-22515, CVE-2023-34048, CVE-2023-46805, CVE-2023-4966, and CVE-2024-21893. The campaign, composed of 53 high-severity and 8 medium-severity cases, affected targets across Latin America, the United States, Canada, and the Caribbean, alongside global operations in the cryptocurrency and technology sectors.

Signal Adds In-App Warnings to Block Russian-Linked Phishing AttacksHIGH
Tools & Techniques

Signal Adds In-App Warnings to Block Russian-Linked Phishing Attacks

Signal introduced new in-app confirmations and warnings to counter phishing attacks linked to Russian state hackers who abused the Linked Device feature to hijack high-profile...

3 min readRussian state-sponsored hackers
2026 World Cup Scam Economy Targets Fans With Fake Visas, TicketsHIGH
Threat Intel

2026 World Cup Scam Economy Targets Fans With Fake Visas, Tickets

Malwarebytes documents a four-part scam economy around the 2026 World Cup: fake visas, counterfeit tickets, phishing sites, and worthless crypto tokens targeting fans ahead of the…

2 min read
Amazon SES Abused in Phishing to Evade Email Security FiltersHIGH
Threat Intel

Amazon SES Abused in Phishing to Evade Email Security Filters

Threat actors exploit Amazon SES to send phishing emails that bypass SPF, DKIM, and DMARC checks, with a 40% rise in abuse since Q4 2025.

3 min read
Phishing Campaign Hijacks SimpleHelp, ScreenConnect RMM Tools at 80+HIGH
Threat Intel

Phishing Campaign Hijacks SimpleHelp, ScreenConnect RMM Tools at 80+

Securonix tracks VENOMOUS#HELPER phishing campaign using legitimate SimpleHelp and ScreenConnect RMM software for persistent remote access across 80+ organizations, mostly in the…

2 min readVENOMOUS#HELPER
Silver Fox Deploys ABCDoor Malware via Tax-Themed PhishingHIGH
Threat Intel

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing

China-linked Silver Fox group targets Indian and Russian organizations with ABCDoor backdoor via tax-themed phishing emails in December 2025 campaign.

2 min readSilver Fox
Telegram Mini Apps Fuel Crypto Scams, Android Malware CampaignHIGH
Threat Intel

Telegram Mini Apps Fuel Crypto Scams, Android Malware Campaign

Researchers uncovered a fraud network abusing Telegram Mini Apps to impersonate brands, steal crypto wallets, and push Android malware like SpyNote and ERMAC.

2 min read
Vietnamese Phishers Hijack 30K Facebook Accounts via Google AppSheetHIGH
Threat Intel

Vietnamese Phishers Hijack 30K Facebook Accounts via Google AppSheet

Guardio tracks AccountDumpling campaign using Google AppSheet as phishing relay to steal 30,000 Facebook accounts, resold via illicit storefront.

2 min readAccountDumpling
Silver Fox Targets Russia, India With ABCDoor BackdoorHIGH
Malware

Silver Fox Targets Russia, India With ABCDoor Backdoor

Silver Fox group impersonates tax authorities to deliver ValleyRAT and the new ABCDoor backdoor to organizations in Russia and India, per Kaspersky.

2 min readSilver Fox
Bluekit Phishing Service Offers AI Assistant, 40 TemplatesHIGH
Threat Intel

Bluekit Phishing Service Offers AI Assistant, 40 Templates

A new phishing-as-a-service platform called Bluekit provides over 40 templates targeting banks, social media, and email providers, plus an AI assistant for drafting lures.

2 min readBluekit
Canada Arrests Three Over SMS Blaster Phishing DeviceHIGH
Industry News

Canada Arrests Three Over SMS Blaster Phishing Device

Three men arrested in Toronto for operating an SMS blaster that impersonated cell towers to send phishing texts targeting banking credentials in a multi-month campaign.

2 min read
LAC Cybercrime Ecosystem Matures with RaaS, Crypto Fraud SurgeHIGH
Threat Intel

LAC Cybercrime Ecosystem Matures with RaaS, Crypto Fraud Surge

Recorded Future's Insikt Group maps a maturing Latin American cybercrime ecosystem: RaaS affiliates, crypto fraud rings, and targeted phishing against financial and government…

2 min readLockBit
Recorded Future Maps Latin America's Maturing Cybercrime EcosystemMEDIUM
Threat Intel

Recorded Future Maps Latin America's Maturing Cybercrime Ecosystem

Insikt Group report details how LAC cybercrime evolved in 2025: RaaS adoption, crypto fraud, and phishing-as-a-service expand across the region.

2 min read
Silver Fox APT Spoofs Japanese Tax Emails in Targeted CampaignHIGH
Threat Intel

Silver Fox APT Spoofs Japanese Tax Emails in Targeted Campaign

ESET details Silver Fox APT targeting Japanese firms with tax-themed phishing emails delivering malware via weaponized Excel attachments during tax season.

2 min readSilver Fox
Kaspersky: Financial Cyber Threats Surged 15% in 2025HIGH
Threat Intel

Kaspersky: Financial Cyber Threats Surged 15% in 2025

Kaspersky reports a 15% year-over-year increase in financial cyber threats in 2025, with infostealers and phishing dominating. Android banking malware rose 20% in Latin America.

2 min read
Toronto Police Bust SMS Blaster Phishing OperationHIGH
Industry News

Toronto Police Bust SMS Blaster Phishing Operation

Three men arrested in Canada's first SMS blaster case — device impersonated cell towers to send mass phishing messages and disrupt mobile networks in Toronto.

2 min read
North Korean Hackers Steal $12 Million in Crypto via TrojanizedHIGH
Malware

North Korean Hackers Steal $12 Million in Crypto via Trojanized

North Korean hackers siphoned over $12 million from crypto users in Q1 2026 using trojanized trading apps like CoinStats and TradingView AI Agent to steal recovery phrases and…

2 min readLazarus Group
Fake TradingView AI Agent Site Drops Browser-Hijacking MalwareHIGH
Malware

Fake TradingView AI Agent Site Drops Browser-Hijacking Malware

A malicious website impersonating a TradingView AI agent deploys malware that hands attackers full control of victims' browsers, enabling account theft and financial data…

2 min read
Phishing Reclaims Top Initial Access Vector in Q1 2026, Cisco TalosHIGH
Threat Intel

Phishing Reclaims Top Initial Access Vector in Q1 2026, Cisco Talos

Cisco Talos found phishing accounted for over a third of initial access engagements in Q1 2026, surpassing exploitation of public-facing apps for the first time since Q2 2025.

2 min read
Malicious Crypto Apps Hijack Recovery Phrases from Apple App StoreHIGH
Malware

Malicious Crypto Apps Hijack Recovery Phrases from Apple App Store

Apple removed 45 malicious cryptocurrency apps from its App Store after they stole recovery phrases and private keys from users, mimicking legitimate wallets like MetaMask and Coinbase.

3 min read
British National Pleads Guilty to SIM Swapping, SMS Phishing for Crypto TheftHIGH
Threat Intel

British National Pleads Guilty to SIM Swapping, SMS Phishing for Crypto Theft

Tyler Robert Buchanan admitted to a U.S. conspiracy that stole over $1 million in cryptocurrency via SMS phishing, corporate network intrusions, and SIM swapping attacks targeting victims nationwide.

3 min readScattered Spider
GitHub Issue Notifications Hijacked for Developer Phishing via OAuth AppsHIGH
Threat Intel

GitHub Issue Notifications Hijacked for Developer Phishing via OAuth Apps

Threat actors are using GitHub's trusted notification system to phish developers, pushing malicious OAuth apps that steal account data and hijack repositories. The campaign exploits the platform's own infrastructure to bypass traditional email security.

3 min read
Identity-Based Attacks Dominate Breaches as Attackers Bypass ExploitsHIGH
Threat Intel

Identity-Based Attacks Dominate Breaches as Attackers Bypass Exploits

The Hacker News reports identity-based attacks, using stolen credentials and MFA bypass, are the dominant initial access vector in modern breaches, rendering sophisticated exploits unnecessary for initial entry.

3 min read
SideWinder APT Deploys Fake Chrome PDF Viewer and Zimbra Clone to StealHIGH
Threat Intel

SideWinder APT Deploys Fake Chrome PDF Viewer and Zimbra Clone to Steal

SideWinder APT targets South Asian government bodies with a phishing campaign using a fake Chrome PDF viewer and a cloned Zimbra login portal to steal webmail credentials, active since February 2026.

3 min readSideWinder
FakeWallet Crypto Stealer Infects iOS Devices via Apple App StoreHIGH
Malware

FakeWallet Crypto Stealer Infects iOS Devices via Apple App Store

Kaspersky discovered 22 malicious iOS apps on the official App Store impersonating crypto wallets like MetaMask and Coinbase, stealing seed phrases and private keys from over 1,000 victims.

3 min readFakeWallet
Apple Account Change Alerts Hijacked for Phishing ScamsHIGH
Threat Intel

Apple Account Change Alerts Hijacked for Phishing Scams

Threat actors are abusing Apple's legitimate notification system to send iPhone purchase phishing emails from Apple's own servers, bypassing spam filters and targeting millions of Apple ID users.

3 min read
Proofpoint Finds FIFA World Cup 2026 Partners Vulnerable to Email SpoofingMEDIUM
Threat Intel

Proofpoint Finds FIFA World Cup 2026 Partners Vulnerable to Email Spoofing

Proofpoint reports 36% of FIFA World Cup 2026 commercial partners fail to implement DMARC, exposing fans to spoofed email fraud. The analysis of 39 official partners found 14 lack basic email authentication.

3 min read
Fake Data Breach Notifications Deploy Malware, Steal CredentialsHIGH
Threat Intel

Fake Data Breach Notifications Deploy Malware, Steal Credentials

Threat actors are weaponizing data breach notifications, sending fake alerts that trick users into downloading malware or entering credentials on phishing sites, according to ESET research.

4 min read
Tycoon 2FA Phishing Kit Disruption Fuels Surge in Copycat AttacksHIGH
Threat Intel

Tycoon 2FA Phishing Kit Disruption Fuels Surge in Copycat Attacks

The disruption of the Tycoon 2FA phishing-as-a-service platform has led to a surge in copycat attacks, as threat actors reuse its tools and techniques in other kits, increasing the overall volume of multi-factor authentication bypass attempts.

4 min read
UAC-0247 Threat Actor Deploys Data-Stealing Malware Against Ukrainian TargetsHIGH
Threat Intel

UAC-0247 Threat Actor Deploys Data-Stealing Malware Against Ukrainian Targets

The Ukrainian CERT-UA attributes a new campaign to threat actor UAC-0247, which uses phishing lures to deploy malware that steals data from Chromium browsers and WhatsApp on government and healthcare systems.

4 min readUAC-0247
DHL-Themed Phishing Campaign Delivers Remote Access SoftwareHIGH
Threat Intel

DHL-Themed Phishing Campaign Delivers Remote Access Software

A new phishing campaign impersonates DHL to trick recipients into installing legitimate remote access software, which attackers then use as a foothold to deploy additional malware, including ransomware.

4 min read
Email-Borne Worm Surge Targets Industrial Control SystemsHIGH
Threat Intel

Email-Borne Worm Surge Targets Industrial Control Systems

A global wave of email-borne worms, driven by a single piece of malware, targeted industrial control systems (ICS) in Q4 2025, marking a significant shift in OT threats.

3 min read
Phishing Remains Primary Attack Vector as MSPs Struggle with Evolving ThreatsHIGH
Threat Intel

Phishing Remains Primary Attack Vector as MSPs Struggle with Evolving Threats

Phishing continues to be the dominant initial attack vector for cybercrime, driving a surge in incidents that managed service providers (MSPs) and their clients are struggling to contain with traditional defenses.

3 min read
Tycoon 2FA Phishing Group Shifts to Device Code AttacksHIGH
Threat Intel

Tycoon 2FA Phishing Group Shifts to Device Code Attacks

The Tycoon 2FA phishing group has abandoned its namesake toolkit, adopting device code phishing to bypass multi-factor authentication and compromise Microsoft 365 and Gmail accounts.

4 min readTycoon 2FA
W3LL Phishing Platform Disrupted in International Law Enforcement OperationHIGH
Threat Intel

W3LL Phishing Platform Disrupted in International Law Enforcement Operation

A coordinated law enforcement operation has disrupted the W3LL phishing-as-a-service platform, which was used to target over 800,000 corporate Microsoft 365 accounts globally.

4 min readW3LL
Booking.com Breach Fuels Sophisticated Hotel Impersonation ScamsHIGH
Threat Intel

Booking.com Breach Fuels Sophisticated Hotel Impersonation Scams

A data breach at Booking.com is providing threat actors with detailed guest reservation data, enabling highly convincing scams where attackers impersonate hotels to steal payment details and credentials.

4 min read
ClickFix Phishing Campaign Masquerades as Claude AI InstallerHIGH
Threat Intel

ClickFix Phishing Campaign Masquerades as Claude AI Installer

A phishing campaign uses fake Claude AI installer lures and 'ClickFix' social engineering to trick users into granting remote access, enabling credential theft and financial fraud.

4 min read
Scammers Revive iCloud Storage Full Scam to Steal Payment DetailsMEDIUM
Threat Intel

Scammers Revive iCloud Storage Full Scam to Steal Payment Details

A phishing campaign impersonates Apple to pressure users with fake 'iCloud storage full' alerts, aiming to steal credit card information and Apple ID credentials.

4 min read
Threat Actors Abuse Google Cloud Storage to Evade Filters, Deliver Remcos RATHIGH
Threat Intel

Threat Actors Abuse Google Cloud Storage to Evade Filters, Deliver Remcos RAT

Cybercriminals are hosting phishing pages on Google Cloud Storage to bypass email security and reputation checks, delivering the Remcos remote access trojan in campaigns observed since early 2026.

4 min read
Credit Resources Vault Scam Targets Financially Vulnerable with Deceptive FeesMEDIUM
Threat Intel

Credit Resources Vault Scam Targets Financially Vulnerable with Deceptive Fees

A sophisticated email scam impersonating the 'Credit Resources Vault' uses urgency and official-looking documents to trick financially distressed individuals into paying recurring fees for worthless credit repair services.

4 min read
Fake YouTube Copyright Notices Steal Google Credentials via PhishingHIGH
Threat Intel

Fake YouTube Copyright Notices Steal Google Credentials via Phishing

YouTube creators are targeted by a sophisticated phishing campaign using fake copyright infringement notices to steal Google account credentials, enabling channel takeover and broader account compromise.

4 min read
Threat Actors Weaponize n8n Workflow Platform for Phishing and Payload DeliveryHIGH
Threat Intel

Threat Actors Weaponize n8n Workflow Platform for Phishing and Payload Delivery

Attackers have been abusing the legitimate n8n workflow automation platform since October 2025 to send phishing emails and deliver malware, leveraging its trusted infrastructure to bypass email security filters.

3 min read
Fake Ledger Live App on Apple App Store Steals $9.5M in CryptocurrencyHIGH
Malware

Fake Ledger Live App on Apple App Store Steals $9.5M in Cryptocurrency

A malicious Ledger Live app distributed via Apple's official App Store for macOS stole approximately $9.5 million from 50 victims by harvesting recovery phrases.

4 min read
FBI Dismantles W3LL Phishing Kit, a $500 Service Behind $20M in FraudHIGH
Threat Intel

FBI Dismantles W3LL Phishing Kit, a $500 Service Behind $20M in Fraud

The FBI and Indonesian authorities dismantled the W3LL phishing-as-a-service platform, a $500 kit used to steal credentials and linked to over $20 million in attempted fraud.

3 min readW3LL Team
FIFA 2026 Partners' Email Security Gaps Expose Public to Impersonation FraudHIGH
Threat Intel

FIFA 2026 Partners' Email Security Gaps Expose Public to Impersonation Fraud

Proofpoint research reveals 36% of FIFA World Cup 2026 official partners lack essential DMARC email authentication, exposing fans to high-risk domain impersonation and fraud.

4 min read
JanelaRAT Evolves with New Anti-Analysis and Data Theft CapabilitiesHIGH
Malware

JanelaRAT Evolves with New Anti-Analysis and Data Theft Capabilities

Kaspersky researchers detail an updated JanelaRAT campaign targeting Latin American users with enhanced anti-analysis, credential theft, and remote access capabilities delivered via phishing.

3 min read
Booking.com Confirms Data Breach Exposing Reservation and User DataHIGH
Threat Intel

Booking.com Confirms Data Breach Exposing Reservation and User Data

Booking.com confirms a data breach exposing sensitive reservation and user data, forcing PIN resets for affected customers.

3 min read
Booking.com Confirms Data Breach via Social Engineering AttackMEDIUM
Threat Intel

Booking.com Confirms Data Breach via Social Engineering Attack

Booking.com confirms a data breach where attackers used social engineering to compromise employee accounts and access customer travel booking information. The company states the incident has been contained.

4 min read
Canadian Payroll Phishing Campaign Exploits Office 365 Search PoisoningHIGH
Threat Intel

Canadian Payroll Phishing Campaign Exploits Office 365 Search Poisoning

A financially motivated group is hijacking Office 365 search results to steal employee paychecks via phishing and account takeover.

3 min readStorm-2755
SANS Stormcast: Exploits Target Ivanti, Fortinet, and VMware FlawsHIGH
Threat Intel

SANS Stormcast: Exploits Target Ivanti, Fortinet, and VMware Flaws

The SANS Internet Storm Center reports active exploitation of vulnerabilities in Ivanti, Fortinet, and VMware products, alongside a new phishing campaign using malicious OneNote attachments.

CVE-2024-21893CVE-2024-22024CVE-2023-34048+3
4 min read
VENOM PhaaS Platform Targets C-Suite Credentials in Sophisticated CampaignHIGH
Threat Intel

VENOM PhaaS Platform Targets C-Suite Credentials in Sophisticated Campaign

A new phishing-as-a-service platform dubbed VENOM is being used to steal Microsoft credentials from senior executives via sophisticated, multi-stage email campaigns.

4 min read
Fake Claude AI Site Delivers PlugX Malware in Trojanized InstallerHIGH
Malware

Fake Claude AI Site Delivers PlugX Malware in Trojanized Installer

A sophisticated phishing campaign uses a counterfeit Claude AI website to distribute a trojanized installer, deploying the remote access trojan PlugX to establish persistent backdoor access.

4 min read
AI-Powered Threat Actor Breaches Mexican Government, Exposes Citizen DataHIGH
Threat Intel

AI-Powered Threat Actor Breaches Mexican Government, Exposes Citizen Data

A sophisticated attacker leveraged AI tools like Claude and ChatGPT to breach nine Mexican government agencies, exfiltrating hundreds of millions of citizen records in a multi-month campaign.

4 min read
Fake BTS World Tour Ticket Sites Target Fans in Multi-Country ScamMEDIUM
Threat Intel

Fake BTS World Tour Ticket Sites Target Fans in Multi-Country Scam

A widespread phishing campaign uses fraudulent BTS concert ticket websites to steal payment information from fans across at least nine countries.

3 min read
GPT-5 Release: Security Implications for Enterprise DefendersHIGH
AI Security

GPT-5 Release: Security Implications for Enterprise Defenders

OpenAI's GPT-5 raises the bar for AI-assisted cyberattacks — spear-phishing at scale, automated exploit generation, and deepfake social engineering. Here's what security teams need to know and do.

3 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.