Category Phishing & Scams

DarkCloud Infostealer Relaunched to Grab Credentials, Crypto, and Contacts

A revamped version of the DarkCloud Infostealer has reemerged, according to researchers at eSentire’s Threat Response Unit (TRU). The malware, now at version 4.2, is being actively marketed to cybercriminals and has already been spotted in attacks against the manufacturing sector. DarkCloud’s Return DarkCloud is not new, but the malware…

Read MoreDarkCloud Infostealer Relaunched to Grab Credentials, Crypto, and Contacts

Microsoft Shuts Down RaccoonO365 Phishing Ring, Seizes 338 Websites

Microsoft’s Digital Crimes Unit (DCU) has dismantled a major phishing-as-a-service operation known as RaccoonO365, which stole thousands of Microsoft 365 credentials and targeted victims worldwide, including U.S. healthcare organizations. The takedown, announced on September 16, 2025, was made possible through a court order from the Southern District of New York.…

Read MoreMicrosoft Shuts Down RaccoonO365 Phishing Ring, Seizes 338 Websites

MostereRAT Targets Windows Using AnyDesk and TightVNC for Remote Control

Cybersecurity researchers at FortiGuard Labs have discovered a new malware threat called MostereRAT, which is being spread through phishing campaigns targeting Windows devices. Classified as high severity, this Remote Access Trojan (RAT) provides attackers with full control of compromised systems using tools like AnyDesk and TightVNC. How the Malware Works…

Read MoreMostereRAT Targets Windows Using AnyDesk and TightVNC for Remote Control

Amazon Disrupts APT29 Watering Hole Phishing Campaign

Amazon’s threat intelligence team has disrupted a watering hole campaign conducted by APT29, the Russian state-linked threat group also known as Midnight Blizzard. The operation used compromised websites to redirect visitors into a phishing scheme designed to hijack Microsoft accounts through the device code authentication flow. How the Campaign Worked…

Read MoreAmazon Disrupts APT29 Watering Hole Phishing Campaign

TamperedChef Infostealer Spread via Fraudulent PDF Editor Ads

Security researchers have uncovered a large-scale malware campaign distributing an infostealer dubbed TamperedChef through fake PDF editing applications. The campaign relied on Google ads to drive victims to fraudulent websites hosting malicious downloads, blending legitimate branding with carefully timed activation of hidden payloads. How the Campaign Works According to researchers,…

Read MoreTamperedChef Infostealer Spread via Fraudulent PDF Editor Ads

Fake Facebook Ads Push Brokewell Spyware to Android Users

Security researchers have uncovered a Facebook malvertising campaign spreading Brokewell spyware to Android devices. The campaign uses fake TradingView ads to lure victims into downloading a trojanized app, which then steals cryptocurrency wallet details, personal data, and other sensitive information. How the Malware Works According to researchers, attackers cloned TradingView…

Read MoreFake Facebook Ads Push Brokewell Spyware to Android Users