Threat Watcher

Page 25 of 33
AiTM Phishing Now #1 Break-In Method for Law Firms

AiTM Phishing Now #1 Break-In Method for Law Firms

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because it can bypass MFA by stealing valid session cookies. The report highlights deadline-driven lures (fake document/court portal errors) and…

July 31, 2026
Fake China Police App Tied to Android RAT Ring

Fake China Police App Tied to Android RAT Ring

Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked Android remote-access tool (RAT) framework called “Flying Eagle.” The tooling lets criminals build convincing look‑alike apps and then steal…

July 31, 2026
Fake Cloudflare Pages Hijack Trusted Websites

Fake Cloudflare Pages Hijack Trusted Websites

Attackers compromised hundreds of legitimate websites and injected code that sent visitors to a fake Cloudflare page. The fake page used a “ClickFix” trick to convince users to run steps that installed malware. The incident shows how criminals can use trusted brands and trusted sites as the…

July 30, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Fake IT Support Hits Teams to Drop Ransomware

Fake IT Support Hits Teams to Drop Ransomware

Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked into starting remote-control sessions (Quick Assist or RemSupp), after which the attackers used PowerShell to maintain access and, in some…

July 30, 2026
Romance Scammer Stole $10M by Weaponizing Trust

Romance Scammer Stole $10M by Weaponizing Trust

U.S. prosecutors said Derrick Van Yeboah ran long-running romance scams by posing as fake romantic partners online and persuading mostly older, vulnerable victims to send money. In one example, he claimed he needed funds for his mother’s funeral and to recover “imaginary gold and diamonds” from…

July 30, 2026
TA488 “Half-Click” Email Triggers OWA Exploit

TA488 “Half-Click” Email Triggers OWA Exploit

Researchers reported a real TA488 campaign where a specially crafted email exploits an Outlook Web Access (OWA) flaw and runs malicious JavaScript as soon as the user opens the message. The attack relies on normal-looking business topics to get people to quickly view the email, and then uses…

July 30, 2026
Lazarus-Linked Lures Hit Korea via Surveys & Sites

Lazarus-Linked Lures Hit Korea via Surveys & Sites

South Korean agencies and AhnLab warn that tools tied to North Korea’s Lazarus Group appear to be shared with the Gunra ransomware operation targeting South Korean organizations. The campaign used compromised legitimate websites (watering-hole attacks) and spearphishing emails, including messages…

July 30, 2026
Hidden Prompt Turns Copilot Docs Into a Worm

Hidden Prompt Turns Copilot Docs Into a Worm

A security researcher demonstrated that Microsoft Copilot for Word can be tricked by hidden text inside a Word document, causing Copilot to follow attacker instructions. The result is a self-propagating “AI worm” that silently modifies documents and embeds the same hidden prompt into new files,…

July 30, 2026
Teams HR Phish Used Real Microsoft Login Flow

Teams HR Phish Used Real Microsoft Login Flow

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When victims approved the requested permissions, the attackers obtained an authorization token and could access Microsoft 365 data like Outlook,…

July 30, 2026
Phishers Hide Behind Real Microsoft Login

Phishers Hide Behind Real Microsoft Login

Researchers observed a phishing campaign that tricks employees into clicking a fake Microsoft Planner task email, then sends them to a real Microsoft login page. After the user signs in, the scam relies on an OAuth permissions prompt; approving it can grant attackers ongoing access to Microsoft 365…

July 30, 2026
“Half-Click” OWA Email Trap Spreads

“Half-Click” OWA Email Trap Spreads

Proofpoint reports a Russian-linked espionage group is using booby-trapped emails that infect users simply when they open the message in Outlook Web Access (OWA) on on‑premises Exchange. The attack runs malicious JavaScript inside the victim’s logged-in mail session and installs a stealthy…

July 30, 2026
Invoice Phish Drops ValleyRAT via BYOVD Drivers

Invoice Phish Drops ValleyRAT via BYOVD Drivers

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed phishing message that leads victims to open a ZIP file, triggering a DLL sideloading chain and installing ValleyRAT for persistent remote…

July 30, 2026
Fake Resumes + Watering Holes Hit AnySign4PC Users

Fake Resumes + Watering Holes Hit AnySign4PC Users

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed. In some cases, simply visiting a compromised page triggered the exploit and installed SIGNBT or COPPERHEDGE backdoors without any download…

July 30, 2026
AI Chatbots Outperform Humans in Romance Scams

AI Chatbots Outperform Humans in Romance Scams

Researchers simulated “pig butchering” romance-style scams and found an AI chatbot built trust more effectively than a human scammer over a week of texting. In the test, victims were significantly more likely to comply with the AI’s request to install an app, showing how AI could automate the long…

July 30, 2026
“No-Action” Emails Trigger OWA Mailbox Takeover

“No-Action” Emails Trigger OWA Mailbox Takeover

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access (OWA) could trigger a hidden exploit. The campaign targeted government and multiple industries, then installed a stealthy browser-based implant…

July 30, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Fake Job Interview Lure Targets Crypto Staff

Fake Job Interview Lure Targets Crypto Staff

A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to harvest personal details and potentially compromise corporate access, especially targeting non-technical staff in crypto firms who can…

July 30, 2026
Fake iPhone Wallet App Stole $1.8M in Bitcoin

Fake iPhone Wallet App Stole $1.8M in Bitcoin

Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow Wallet. The victims trusted the app because it was available in the App Store, then entered their wallet “seed phrase” into the counterfeit…

July 30, 2026
Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users into entering their wallet recovery phrase, then criminals used it to drain about $1.8 million in Bitcoin. The case highlights how…

July 29, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo