Cybersecurity News

Filters
Tag
Reset

Filtered by tag: social engineering × Clear

Of course, this fake GTA VI ISO download is malware — testers reveal 113GB download is 99.99% empty zeroes, with a tiny virus attached

A fake GTA VI ISO circulating on torrent sites is almost entirely empty data, with testers finding 113GB of zeroes concealing a roughly 50KB malware payload. The inflated file size was designed to mimic a legitimate game release. The malicious code reportedly disables Windows Defender and other security tools via PowerShell commands. Interest in GTA VI leaks has made fans easy targets, with Rockstar's official release scheduled for November.

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

Matched: cryptocurrency, health

Scammers are running fake Microsoft-branded security scan websites that display fabricated results showing poor scores and false warnings. The sites instruct visitors to uninstall their antivirus software, then collect personal and banking details through a form before redirecting victims to await a callback. Callers then request remote access to the device. Malwarebytes identified 11 related sites sharing one server, all using similar SysScan branding.

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

Matched: cryptocurrency

ClickFix campaigns are delivering PavinLoader malware through fake CAPTCHA pages, software downloads, and malicious game installers that trick users into running malicious commands. The loader uses legitimate Windows tools like MSBuild to hide its activity, employs blockchain-based command-and-control via EtherHiding to obscure infrastructure, and deploys payloads including Amatera Stealer and HijackLoader to steal passwords, browser data, and cryptocurrency wallet information.

Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds

Matched: cryptocurrency

Cybercriminals are using stolen Google Ads accounts and Google Sites to impersonate OpenAI's Codex download page, targeting macOS users. The fake site avoids detection by hosting malicious content via an iFrame elsewhere. Victims are tricked into pasting Terminal commands, which install AMOS, a macOS infostealer that harvests passwords, browser data, and crypto wallet information. The Windows download button was non-functional — only the Mac payload worked.

New malware targets Microsoft Teams users by posing as your company's IT helpdesk

A new backdoor malware called SynkLoader is targeting Microsoft Teams users via fake IT helpdesk messages urging victims to install a malicious "PowerShell Cleaner" hosted on Azure. Key modules include PhishLocker, which displays a fake Windows login screen to steal passwords, and Interactive Shell, enabling full remote control. Organizations are advised to treat unsolicited Teams messages with suspicion and verify requests directly with IT.

Fake Codex Download Uses Google Sites to Deliver macOS Malware

Attackers created fake codec download pages hosted on Google Sites to distribute macOS malware. The campaign used sponsored search results to drive traffic and employed a ClickFix-style social engineering technique, tricking users into manually running malicious commands. The use of Google's infrastructure helped bypass security warnings and lend the pages false legitimacy.

Private equity giant Apollo confirms data breach saw personal info stolen

Apollo Global Management confirmed a cyberattack between July 6–10, 2026, in which a threat actor used social engineering to access its cloud environment. Stolen data included names, dates of birth, contact information, addresses, and Social Security numbers. Financial data was not compromised. Apollo notified authorities, engaged forensic experts, and is offering affected individuals two years of free identity protection. No group has claimed responsibility and the data has not appeared on the dark web.

Security experts targeted by fake crypto conference in scam to hand over details

Cybersecurity researchers are being targeted by a scam involving a fake cryptocurrency conference. Attackers invite professionals to speak or attend, then direct them to a fraudulent website that delivers information-stealing malware, including AMOS. The scheme exploits the credibility of conference invitations to trick even security-savvy victims into compromising their own systems.

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

Matched: cryptocurrency

A platform called "Kriminal" offers an AI service with no content restrictions, marketed toward cybercriminals. Accessible via cryptocurrency, it provides social engineering scripts, offensive hacking tools, and open-source intelligence scanning. Despite official terms prohibiting illegal use, researchers warn the guardrail-free system meaningfully lowers the barrier for cybercrime, enabling even unskilled actors to conduct sophisticated attacks.

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Researchers at Check Point identified a ransomware operation called StopAndProtect in May 2026. The campaign uses the ClickFix social-engineering technique to trick victims into running a PowerShell command, triggering a multi-stage downloader chain. Thousands of hacked WordPress sites serve as infrastructure for the operation, which researchers have now partially unmasked through analysis of its infection chain and supporting infrastructure.

Crypto Scammer Uses Claude Code to Process 100,000+ Phone Numbers for Victim Targeting

Matched: cryptocurrency

A cryptocurrency fraud operation called Operation ASTERIX used AI coding tools to process over 100,000 phone numbers for targeted victim selection. The scheme combined account verification, phishing emails, phone calls, and fake wallet software to identify and pursue likely cryptocurrency holders, offering researchers an unusually detailed look at a modern crypto fraud pipeline.

Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT

Matched: cryptocurrency

Attackers posing as Web3 recruiters on LinkedIn lured cryptocurrency professionals into fake job interviews, ultimately tricking Windows users into installing malware via a signed ClickOnce application. The infection deployed NeedleStealer, which harvested private keys and browser data, alongside an hVNC remote access trojan. The campaign used Calendly scheduling and technical assessments to appear legitimate.

Why was there an 'evil’ Delta airlines Wi-Fi network? The experts weigh in

An Australian man was arrested after allegedly creating a fake Wi-Fi hotspot on a Delta flight, mimicking the plane's legitimate network to steal passengers' credentials. Security experts say such "evil twin" attacks are simple to execute and hard to detect. They advise avoiding logging into sensitive accounts on public Wi-Fi and using a VPN, noting airlines should better educate passengers about network safety.

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Matched: cryptocurrency

Researchers created a fake crypto startup and hired three suspected North Korean IT workers to study their tactics. Every company device was monitored. The operation revealed red flags hiring teams can watch for: one worker claimed to live in Texas but submitted a California driver's license and a New York bank account, exposing the inconsistencies North Korean operatives typically display during onboarding.

Bank of America Phishing Email Delivers ScreenConnect Malware

A phishing campaign impersonating Bank of America delivers ScreenConnect remote access malware through a multi-stage infection chain. The convincing fake emails trick recipients into actions that ultimately install the legitimate remote access tool, which attackers abuse to control victims' systems. The campaign highlights how cybercriminals exploit trusted brand names and repurpose legitimate software to evade detection.

North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials

Matched: cryptocurrency

North Korean hackers are using fake macOS update screens to deploy malware targeting cryptocurrency wallets, browser data, and developer credentials. The campaign uses a ClickFix-style lure that makes browser pages appear broken, prompting users to run malicious commands. Entry points include routine web searches, making the attack difficult to detect.

Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

A malvertising campaign discovered in late July used a fake Claude AI artifact hosted on Anthropic's legitimate domain to trick users into downloading malware. The attack, dubbed FakeAgent, infected 29 organizations with SectopRAT, an information-stealing trojan capable of harvesting credentials and sensitive data. The campaign exploited user trust in the authentic Claude domain to bypass suspicion.

Custom HTML for Custom Phishing: Make the Fake Feel Real

Huntress offers a Custom HTML feature for phishing simulations, allowing organizations to build tailored, realistic phishing scenarios. Rather than using generic templates, security teams can design emails that mirror actual vendors and risks specific to their environment, making training more relevant and effective at preparing employees for real-world threats.

5 Modern Threats You Need to Watch

Cybersecurity threats increasingly bypass traditional malware, instead starting with legitimate-looking logins. Key patterns to watch include ransomware, business email compromise, and social engineering attacks. IT and security teams are urged to recognize these threats early, focusing on detecting suspicious access attempts rather than relying solely on conventional malware-detection approaches.