Trusted Channels Hijacked for Phishing and Malware

eSecurity Planet · Medium sophistication
Last updated September 18, 2026

The article describes multiple real-world social engineering operations this week, including phishing sent from a legitimate Trezor newsletter channel and malware pushed through a verified HBO Max Reddit ad account. It also highlights a large-scale network of fake online stores impersonating real brands to steal payment details, showing how attackers use trusted brands and realistic storefronts to trick people into unsafe clicks and purchases.

Key findings

  • Attackers used a compromised Brevo account to send phishing emails through Trezor’s legitimate newsletter channel to 347,000 subscribers; ~2,500 recipients clicked before it was stopped.
  • Attackers compromised HBO Max’s verified Reddit advertising account and ran 108 malicious ads over ~48 hours, driving users to fake sites that used ClickFix instructions to get them to install malware.
  • Researchers identified 119,000 fake shopping domains (DoppelCart) impersonating 44,000+ brands, using realistic storefronts and steep discounts to steal payment and personal information.
  • The article notes that exposed personal data (e.g., from large breaches) can increase the success of impersonation and targeted phishing by making messages seem more credible.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Marketing/Advertising teams, Helpdesk/IT support.
  • Affected industries: Cryptocurrency / digital assets, Media and advertising, Retail / e-commerce, Government.
  • Attack channels: email, website.
  • Impersonated: Trezor (using its legitimate newsletter channel), HBO Max (via a verified Reddit advertising account), Impersonated retail brands (fake storefronts).

Awareness takeaways

  • Treat ‘trusted’ senders and platforms as untrusted until verified; always validate via an independent method (known website/app or trusted contact path).
  • Never follow instructions that ask you to paste or run commands to ‘fix’ something, report it to IT/Security instead.
  • Be skeptical of steep discounts and unfamiliar stores; verify the domain and brand independently before entering payment details.
  • Assume leaked personal data can be weaponized to make phishing more believable; be extra cautious when messages include accurate personal details.

Red flags to watch for

  • Unexpected “security” email prompting action even though it appears to come from a legitimate brand/channel
  • Pressure to click quickly before verifying through an independent path
  • Link-led workflow instead of directing users to log in via a known, bookmarked site/app
  • A “fix” workflow that asks you to paste or run commands
  • A link from an ad leading to a lookalike website rather than a known official domain
  • Unexpected install prompts or security warnings after clicking an advertisement
  • Prices/discounts that seem too good to be true and create urgency
  • Unfamiliar domain/storefront for a well-known brand
  • Lack of trustworthy contact/return details or inconsistent branding
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a real Trezor newsletter in your inbox… and it’s actually a phishing email. Attackers hijacked Trezor’s Brevo account and blasted 347,000 customers. In 20 minutes, 2,500 people clicked a fake security link, because it came from a channel they trusted. Same trick with ads: a verified HBO Max Reddit ad pushes you to a fake site using ClickFix steps, 'paste this command to fix it', and that’s how the malware lands. Aha moment: if a “trusted” email or ad ever tells you to click a link or paste commands, stop. Your move: close it and go to the official site or app yourself to check.

Similar attacks

Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026