
Phishers Hijack Meta/Google Ad Accounts for Profit
Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google…
Researchers found a campaign of deceptive Android apps on Google Play that pretend to be helpful tools (alarms, calendars, cleaners) but show full-screen ads right after a phone call ends. The apps persuade users to grant special “appear on top” (overlay) permissions so the ads can pop up over anything, then they hide to make removal harder.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Ever hang up a call and suddenly a full‑screen ad appears, like some weird ‘call info’ screen? That’s the ‘Aftercall’ trick: shady Android apps on Google Play posing as alarm clocks or calendars, then pushing you to enable ‘Display over other apps’ so they can pop ads over everything the moment a call ends. They even fake a ‘call info’ layout with caller details and a profile picture to make the ad feel legit, then hide from the Recent apps list so you can’t tell which so-called alarm or calendar is doing it. If you see ads right after calls, don’t ignore it, open Android Settings, check who has ‘Display over other apps’ permission, and strip it from anything that doesn’t truly need it.

Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…