
Fake GitHub Repos and Trojan Apps Steal Data
Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…
This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned into training simulations: getting a user to run an installer/script, persuading a victim to “invest” more money over time, and quietly enabling browser syncing to exfiltrate private browsing data.
This roundup covers three distinct techniques that rely on manipulating trust and access rather than exploiting software flaws alone.
In the investment fraud scheme, call-center staff posed as financial advisors and built rapport with victims over a period of months. Victims were guided to make a small initial deposit that showed an immediate profit on a realistic-looking platform, which encouraged them to deposit larger sums over time, often in cryptocurrency.
Separately, a financially motivated group used ClickFix lures, prompts that convince a user to run a script to fix an issue, to distribute HTA scripts. These scripts downloaded trojanized installers disguised as common tools such as Zoom, WebEx, MobaXterm, DBeaver, and FaceIT.
The third technique described abuse of Chrome Sync. With only brief physical access to an unlocked phone, an attacker can add their own Google account to Chrome and enable Sync, after which the victim's browsing activity is copied to the attacker's account in the background, viewable at any time.
Each technique exploited a different form of trust:
Organizations and individuals can reduce exposure by verifying investment opportunities independently before depositing funds, treating “fix it now” prompts with suspicion unless they originate from the official vendor, and locking devices while periodically reviewing browser accounts and sync settings for anything unexpected. These habits address the trust-based mechanics behind each technique described here, rather than relying solely on technical detection.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Callers pose as financial advisors and build trust over months, encouraging victims to start with a small deposit that shows an immediate profit, then push for increasingly larger deposits, often paid in cryptocurrency.
A ClickFix lure convinces a user to run a script or installer to fix a problem, but it actually downloads a trojanized installer disguised as common software like Zoom, WebEx, or MobaXterm.
Yes, if someone gets brief physical access to an unlocked phone, they can add their own Google account to Chrome and enable Sync, which copies browsing activity to their account in the background.
Fake platforms can look identical to real ones and show fabricated profits, so the takeaway is to independently verify the firm rather than trusting the dashboard's appearance.
Imagine this: a “financial advisor” calls, you make a tiny crypto deposit, and the dashboard shows instant profit. On the phone they sound legit, pose as your financial advisor, keep chatting for months, and keep nudging: 'You see the gains, add more.' The platform looks real, but you can’t verify the firm anywhere. Here’s the creepy twist: give someone your unlocked phone for a minute, they open Chrome, add their own Google account, flip on Sync, and now your browsing, autofill, even passwords quietly copy to them in the background. Your move: if anyone contacts you about investing, hang up, search the firm yourself, and only use a company website and platform you can independently verify.

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…