Threat Watcher

Page 3 of 22
Fake Crypto “AML Checkers” Drain Wallets

Fake Crypto “AML Checkers” Drain Wallets

Scammers are running professional-looking “AML checker” websites that pretend to screen crypto wallets for suspicious activity, but are designed to trick people into connecting their wallet and approving a malicious transaction. Many impersonate a legitimate service (AMLBot) and use fake progress…

August 19, 2026
Fake N. Korean IT Workers Flood Job Applications

Fake N. Korean IT Workers Flood Job Applications

Research says a North Korea–linked operation (“PurpleDelta”) is using fake identities to apply for large volumes of remote IT jobs, sometimes successfully getting hired. Once inside a company, these “employees” can record meetings and steal sensitive information such as source code and internal…

August 19, 2026
Fake CAPTCHA on Hacked WordPress Spreads Malware

Fake CAPTCHA on Hacked WordPress Spreads Malware

Researchers described a real cybercrime operation (“StopAndProtect”) that compromised nearly 2,000 WordPress sites and used them to show fake CAPTCHA pages that trick visitors into running malicious commands. Victims can end up with malware that steals files and screenshots and, in some cases,…

August 19, 2026
Wrong-Number Texts That Turn Into Scams

Wrong-Number Texts That Turn Into Scams

The article describes how “wrong-number” SMS messages are used as a first-step social engineering test to identify people who will engage with strangers. If the target replies, scammers may either build a long relationship that leads to fake investment fraud (“pig butchering”) or recycle the…

August 19, 2026
ClickFix Tricks Mac Users Into Running Stealer

ClickFix Tricks Mac Users Into Running Stealer

Microsoft describes a real macOS data-stealing campaign (MacSync Stealer) that relies on social engineering rather than software exploits. Victims are tricked into pasting/running commands in Terminal, which downloads the payload and ultimately steals passwords, keys, and wallet data, then uploads…

August 19, 2026
Insider Used Extortion Emails After Contract Ended

Insider Used Extortion Emails After Contract Ended

A contractor at Brightly Software (owned by Siemens) used his legitimate access to steal sensitive employee and corporate data, then tried to extort the company for $2.5 million. Using the alias “Loot,” he sent dozens of threatening emails and attached screenshots of payroll-style spreadsheets to…

August 19, 2026
CoSnitch: One-Link Copilot Data Exfil Chain

CoSnitch: One-Link Copilot Data Exfil Chain

Researchers disclosed a critical Microsoft Copilot (personal) vulnerability chain that could let an attacker steal enterprise data by getting a user to open a legitimate-looking link or summarize a crafted webpage. The attack abuses Copilot features (auto-running prompts, connected-app access, and…

August 19, 2026
“Ransom Busters” Emails Victims for $60K “Help”

“Ransom Busters” Emails Victims for $60K “Help”

A criminal actor calling itself “Ransom Busters” is emailing organizations that recently suffered ransomware incidents, claiming it hacked ransomware groups’ servers and can delete the victim’s stolen data for a $20,000–$60,000 fee. The messages ask to speak with the CEO or IT leadership and…

August 18, 2026
Mac ClickFix Trick Drops MacSync Data Stealer

Mac ClickFix Trick Drops MacSync Data Stealer

Microsoft reports MacSync Stealer infections that start when a user is tricked into pasting or running commands in macOS Terminal (a “ClickFix” style lure). Those commands use built-in tools like curl to download and run the payload, then the stealer collects credentials and sensitive files, stages…

August 18, 2026
Spoofed Portal Drops APT36 Backdoor on Telecoms

Spoofed Portal Drops APT36 Backdoor on Telecoms

The bulletin describes an APT36 (Transparent Tribe) espionage campaign that uses social-engineering lures and spoofed download portals to trick targets into installing a malicious Windows installer. The installer (“TMS_AfghanTelecom.exe”) deploys the PATCHCORD backdoor, which then calls out to…

August 18, 2026
Fake CAPTCHA Trick Spreads StopAndProtect

Fake CAPTCHA Trick Spreads StopAndProtect

Researchers uncovered a large campaign called StopAndProtect that uses hacked WordPress sites to show visitors a fake CAPTCHA and trick them into running a PowerShell command. That one action kicks off a multi-stage infection that can encrypt files (ransomware), steal documents, passwords/wallet…

August 18, 2026
Fake IT Support on Teams Drops TWINLOOT

Fake IT Support on Teams Drops TWINLOOT

Researchers observed an active campaign where attackers used Microsoft Teams to impersonate IT support and trick a user into running a PowerShell command. That action downloaded a malicious package that enabled credential theft (via a fake lock screen) and helped attackers move through internal…

August 18, 2026
One-Click Copilot Link Triggers Data Exfil

One-Click Copilot Link Triggers Data Exfil

Researchers showed how an attacker could trick Microsoft Copilot into running a malicious prompt automatically just by getting a user to click a specially crafted link. The prompt can then make Copilot search connected accounts (like email and cloud storage) and send information to an external…

August 18, 2026
Typosquat RubyGems Stealer Hits Dev Machines

Typosquat RubyGems Stealer Hits Dev Machines

Researchers found 16 look‑alike (typosquatted) RubyGems packages that trick developers into installing a Windows information stealer. The malicious gems run code automatically during installation, pull down additional malware, and then steal browser logins and crypto wallet data before uploading it…

August 18, 2026
TWINLOOT Fakes Lock Screen to Steal Passwords

TWINLOOT Fakes Lock Screen to Steal Passwords

Researchers uncovered an active malware campaign ("TWINLOOT") that hides its command-and-control traffic inside trusted Microsoft services like SharePoint, Teams, and Microsoft Graph. It can trick users by showing a realistic Windows lock screen and capturing every password attempt, then sending…

August 18, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026
Azure Employee Directories Dumped via Stolen Access

Azure Employee Directories Dumped via Stolen Access

A threat actor called “TheHatman” claims they stole and posted large internal employee directories from multiple Fortune 500 companies’ Microsoft Azure tenants. Hudson Rock says the leaked samples look like real Azure directory exports, but the exact way the attacker got in is still unclear. One…

August 18, 2026
“Quote Review” Email Drops PhantomStealer

“Quote Review” Email Drops PhantomStealer

AhnLab reported a real phishing email campaign that pretends to be a sales representative asking the victim to review and revise a quote and verify product versions. The email includes a malicious compressed attachment that leads to an executable which ultimately installs PhantomStealer, an…

August 18, 2026
Fake Transaction Receipt Emails Drop Remote Access Tool

Fake Transaction Receipt Emails Drop Remote Access Tool

Researchers observed real phishing emails posing as transaction receipts to trick people into opening a PDF attachment. The PDF claims an “Adobe Flash Player update is required,” leading victims to download and run a script that silently installs ScreenConnect for persistent remote access.

August 18, 2026
Quishing Emails Use QR Codes to Bypass Filters

Quishing Emails Use QR Codes to Bypass Filters

The article describes how attackers use QR codes in emails (“quishing”) to hide malicious links, push victims onto less-protected mobile phones, and steal credentials or MFA tokens. It also cites an FBI notice describing North Korea’s Kimsuky using QR codes in spearphishing emails targeting think…

August 18, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo