Cybersecurity News
Filters
Filtered by tag: phishing × Clear
Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access
Matched: cryptocurrency, health
Scammers are running fake Microsoft-branded security scan websites that display fabricated results showing poor scores and false warnings. The sites instruct visitors to uninstall their antivirus software, then collect personal and banking details through a form before redirecting victims to await a callback. Callers then request remote access to the device. Malwarebytes identified 11 related sites sharing one server, all using similar SysScan branding.
New malware targets Microsoft Teams users by posing as your company's IT helpdesk
A new backdoor malware called SynkLoader is targeting Microsoft Teams users via fake IT helpdesk messages urging victims to install a malicious "PowerShell Cleaner" hosted on Azure. Key modules include PhishLocker, which displays a fake Windows login screen to steal passwords, and Interactive Shell, enabling full remote control. Organizations are advised to treat unsolicited Teams messages with suspicion and verify requests directly with IT.
Private equity giant Apollo confirms data breach saw personal info stolen
Apollo Global Management confirmed a cyberattack between July 6–10, 2026, in which a threat actor used social engineering to access its cloud environment. Stolen data included names, dates of birth, contact information, addresses, and Social Security numbers. Financial data was not compromised. Apollo notified authorities, engaged forensic experts, and is offering affected individuals two years of free identity protection. No group has claimed responsibility and the data has not appeared on the dark web.
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
A threat actor dubbed Doubloon Dredger used malicious PDFs to redirect victims to fake Microsoft login pages hosted via Notion. The campaign harvested Microsoft authentication tokens, exploiting Notion's legitimate infrastructure to evade detection. The abuse of trusted platforms helped the attackers bypass security filters while capturing credentials from targeted users.
Shop now? Banking malware campaign posing as Woolworths active in Australia
Matched: Australia
A banking malware campaign is targeting Australians by impersonating Woolworths and other trusted brands to distribute an Android trojan. The malware can access bank accounts, read SMS messages, and activate device cameras. Users are urged to avoid downloading apps from unofficial sources and to verify the legitimacy of any links before clicking.
Crypto Scammer Uses Claude Code to Process 100,000+ Phone Numbers for Victim Targeting
Matched: cryptocurrency
A cryptocurrency fraud operation called Operation ASTERIX used AI coding tools to process over 100,000 phone numbers for targeted victim selection. The scheme combined account verification, phishing emails, phone calls, and fake wallet software to identify and pursue likely cryptocurrency holders, offering researchers an unusually detailed look at a modern crypto fraud pipeline.
Scammers hijack real Shopify notifications to swindle victims — here's how to stay safe
Cybercriminals are exploiting Shopify's legitimate notification system to send fraudulent messages that appear authentic. By creating fake stores, scammers trigger real Shopify emails to potential victims, making them harder to detect. Experts recommend verifying unexpected order confirmations directly through official websites, avoiding links in unsolicited emails, and enabling two-factor authentication to protect accounts.
Fake Refund Scam Hits Shopify Shop App Users
Scammers are targeting users of Shopify's Shop app with fake refund schemes. The scam operates directly within the app, contacting users with fraudulent refund offers. The campaign has been active for several months. Users are advised to be cautious of unsolicited refund messages received through the platform and to verify any communications through official Shopify channels.
Scammer beware: Why scams spike around Census time, and what to look out for
Matched: Australia
Scammers are exploiting Australia's Census period, sending fraudulent emails to trick people into handing over personal details. Authorities warn that the timing is deliberate, as people are more likely to share sensitive information during Census time. Australians are urged to be cautious and verify any Census-related communications through official government channels.
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
A Mac user was tricked by a fake CAPTCHA prompt into running a Terminal command that installed Go-based malware. The attack, a variant of the ClickFix scam, gave attackers access to macOS Keychain passwords and cryptocurrency wallets. Security researchers warn the technique is growing more common and targets users across platforms.
Bank of America Phishing Email Delivers ScreenConnect Malware
A phishing campaign impersonating Bank of America delivers ScreenConnect remote access malware through a multi-stage infection chain. The convincing fake emails trick recipients into actions that ultimately install the legitimate remote access tool, which attackers abuse to control victims' systems. The campaign highlights how cybercriminals exploit trusted brand names and repurpose legitimate software to evade detection.
Device Code Phishing Keeps Evolving. Here’s What to Watch For
Attackers are abusing Microsoft 365's device code authentication flow to steal tokens without needing credentials. Victims are tricked into entering attacker-generated codes at legitimate Microsoft login pages, granting persistent access. The technique bypasses MFA and leaves minimal obvious indicators. Huntress advises monitoring for unusual device code authentication requests, unexpected token grants, and sign-ins from unfamiliar locations or clients.
Custom HTML for Custom Phishing: Make the Fake Feel Real
Huntress offers a Custom HTML feature for phishing simulations, allowing organizations to build tailored, realistic phishing scenarios. Rather than using generic templates, security teams can design emails that mirror actual vendors and risks specific to their environment, making training more relevant and effective at preparing employees for real-world threats.
