Threat Watcher

Page 2 of 22
Fake “Ransom Busters” Hijacks Ransom Payments

Fake “Ransom Busters” Hijacks Ransom Payments

Researchers say a group calling itself “Ransom Busters” contacted ransomware victims before the attacks became public, pretending to be a recovery firm. The emails offered to delete stolen data and provide decryption keys for $20,000–$60,000, likely diverting payments away from the victim’s…

August 20, 2026
Wall Street Hit by Help Desk Impersonation Calls

Wall Street Hit by Help Desk Impersonation Calls

A real campaign of voice-phishing (vishing) calls targeted major hedge funds and private equity firms by impersonating internal IT/help desk staff. Victims were pressured into completing “routine” security steps and were sent to fake login pages that captured usernames, passwords, and MFA codes in…

August 20, 2026
Manic Android Spyware Uses Fake Utility Apps

Manic Android Spyware Uses Fake Utility Apps

A new Android malware family called “Manic” is being used in real campaigns targeting banking, government identity, and messaging apps, especially in Ukraine and parts of Europe. It spreads through phishing sites and “dropper” apps disguised as legitimate utilities (including a booking-app lure),…

August 20, 2026
Russian Clusters Abuse Login Flows to Steal Accounts

Russian Clusters Abuse Login Flows to Steal Accounts

Google says three suspected Russian espionage clusters are targeting academics, think tanks, diplomats, and related nonprofit staff by abusing legitimate login and verification workflows that may not look like “classic phishing.” The campaigns include app-password scams, OAuth/device-code tricks,…

August 20, 2026
Grok Trick Lets Web Pages Steal Chat History

Grok Trick Lets Web Pages Steal Chat History

Researchers say xAI’s Grok web chat can be manipulated by a poisoned web page so the AI follows hidden attacker instructions. The twist is the instructions are strongly encrypted, so safety scanners don’t recognize them, yet Grok can decrypt and act on them, including leaking a user’s chat details…

August 20, 2026
Fake Airline Apps Push Android Banking Fraud

Fake Airline Apps Push Android Banking Fraud

Researchers report two Android banking malware families (ToxicPanda 2.0 and GoldDigger) that rely on tricking people into installing malicious apps and granting powerful permissions. GoldDigger campaigns impersonate airlines and shopping retailers and then abuse Android Accessibility to take over…

August 20, 2026
Fake Firefox Web3 Extensions Steal Wallet Secrets

Fake Firefox Web3 Extensions Steal Wallet Secrets

Researchers found 40 malicious Firefox extensions pretending to be popular Web3 wallet products (like OKX, Rabby Wallet, and TronLink) to steal crypto wallet secrets. The extensions trick users into installing them, then capture recovery phrases/private keys and send them to attacker-controlled…

August 20, 2026
Fake Gemini Installer Lures Users via Google Colab

Fake Gemini Installer Lures Users via Google Colab

Attackers tricked a user into downloading a fake “Google Gemini” Windows installer by using a Google Colab page that looked trustworthy and then redirecting to a spoofed software download site. The downloaded file delivered the Vidar infostealer, which is commonly used to steal browser-stored…

August 20, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Def Con DMs Lure Targets Into Fake Google Docs

Def Con DMs Lure Targets Into Fake Google Docs

A researcher was targeted after Black Hat/Def Con by an attacker posing as a CoinDesk executive and using X direct messages to build trust. The scam used familiar platforms (Google Docs and Dropbox DocSend) to push “ClickFix”-style steps or a fake installer intended to get the victim to run malware.

August 20, 2026
Fake CAPTCHA Tricks Users Into Running Malware

Fake CAPTCHA Tricks Users Into Running Malware

Researchers found a criminal operation (StopAndProtect) that used nearly 2,000 hacked WordPress sites as a delivery network. Visitors were shown a fake CAPTCHA that pressured them to copy and run a PowerShell command, which then installed malware that could steal data, capture screenshots, and…

August 20, 2026
APT Groups Lure Targets Into Fake Zoom/Teams Meets

APT Groups Lure Targets Into Fake Zoom/Teams Meets

This threat trend report describes multiple real-world APT campaigns where attackers rely on social engineering and trusted services (Zoom/Teams, Telegram, webmail, GitHub) to steal credentials and access cloud accounts. Notable examples include fake meeting lures to deliver malware, and abuse of…

August 20, 2026
AI Voice Impostor Posed as Marco Rubio on Signal

AI Voice Impostor Posed as Marco Rubio on Signal

Governments are responding to deepfakes by shifting from “detecting fakes” to building systems that prove where digital content came from and whether it was altered. The article cites real AI-impersonation activity targeting government officials, including text and AI-voice impersonation intended…

August 20, 2026
Fake Download Pages Trick Users Into Download Studio

Fake Download Pages Trick Users Into Download Studio

Researchers found 41 convincing “download” websites that impersonate popular games and Windows apps. The pages show legitimate-looking download links when you hover, but clicking triggers hidden scripting that redirects visitors to install “Download Studio” instead. The installer is validly signed,…

August 19, 2026
MacSync Stealer Uses ClickFix Terminal Paste Trap

MacSync Stealer Uses ClickFix Terminal Paste Trap

Microsoft reports real-world macOS infections where victims were tricked into pasting commands into Terminal (a “ClickFix”-style social-engineering method). The malware then downloads a payload, steals credentials and other sensitive data (like Keychain and browser sessions), and uploads it in…

August 19, 2026
Fake reCAPTCHA “Fix” Spreads MaaS Malware

Fake reCAPTCHA “Fix” Spreads MaaS Malware

Researchers observed real campaigns using compromised WordPress sites to show fake verification/BSOD-style prompts that trick users into running a copied PowerShell command. The technique (ClickFix) was paired with MaaS tools (ErrTraffic and Cruciferra) to deliver malware while attempting to kill…

August 19, 2026
AI-Aided Crypto Scam Used Phishing + Vishing Combo

AI-Aided Crypto Scam Used Phishing + Vishing Combo

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those…

August 19, 2026
Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

The article describes how modern phishing can start with an email impersonation and then move into live deepfake video calls to pressure employees into sending money. It cites a widely reported case at engineering firm Arup where an employee, convinced by a deepfake video call featuring synthetic…

August 19, 2026
SilkParasite Uses Ministry-Themed Phishing to Drop RATs

SilkParasite Uses Ministry-Themed Phishing to Drop RATs

Researchers reported a real espionage campaign (“SilkParasite”) targeting Central Asian government bodies using spear‑phishing emails. The attack uses password‑protected RAR files containing malicious Microsoft Office documents; when opened, macros trigger a DLL sideloading chain to install remote…

August 19, 2026
AI-Scaled BEC Targets Small Orgs Too

AI-Scaled BEC Targets Small Orgs Too

The article describes a real business email compromise (BEC) attempt against a small community sports club, where an attacker impersonated a superior and requested an urgent payment. It explains how attackers can use AI to automate the research and message-writing steps, making it easier to target…

August 19, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo