Threat Watcher

Page 31 of 32
FaceTime Spoof Calls Steal Codes and Money

FaceTime Spoof Calls Steal Codes and Money

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords, security codes, and financial details. The callers use personal information to sound legitimate, then create urgency to keep victims from…

July 17, 2026
ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
Spear-Phishing RTF Hits Bangladesh Defense Targets

Spear-Phishing RTF Hits Bangladesh Defense Targets

Researchers reported a targeted espionage operation against Bangladesh’s military and defense organizations using spear‑phishing emails with a booby‑trapped RTF document. When opened, the file pulls malicious content remotely and installs an implant that persists on the device while quietly sending…

July 17, 2026
Fake “AI Tool” Ads Drop MediaArena Persistence

Fake “AI Tool” Ads Drop MediaArena Persistence

A malvertising campaign is luring users with fake free “AI tool” downloads (recipe/meal-planning apps) delivered via paid search ads. Even when Microsoft Defender later quarantines the detected file, the installer can already have created persistence (Startup shortcut and HKCU Uninstall key),…

July 17, 2026
Fake Zoom/Webex Installers Drop Starland RAT

Fake Zoom/Webex Installers Drop Starland RAT

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools like Zoom, Webex, and MobaXterm. Victims are socially engineered via a “ClickFix” style trick into running a command that silently…

July 17, 2026
Fake Font Attachment Used in Global Phishing

Fake Font Attachment Used in Global Phishing

Researchers report a real, ongoing phishing campaign where attackers impersonate well-known companies and send business or payment-themed emails that trick recipients into opening a compressed attachment. Inside is heavily obfuscated script and a file disguised as a TrueType font (.ttf) that…

July 17, 2026
One-Click Google SSO Takeover via Device-Code Bug

One-Click Google SSO Takeover via Device-Code Bug

A researcher found two bugs in Google’s “device code” sign-in flow that could let an attacker get a valid Google sign-in token for a victim by getting them to open a single crafted link. In the most dangerous version, the victim sees no consent screen and no extra 2FA prompt, yet the attacker can…

July 17, 2026
AI Vishing Works Because Scripts Persuade

AI Vishing Works Because Scripts Persuade

Researchers tested AI and human voice scam calls and found people comply mainly because the caller’s script is persuasive, not because the voice sounds perfectly human. Even when listeners correctly suspect the voice is synthetic, many still continue the conversation and may hand over sensitive…

July 17, 2026
LinkedIn Chat Leads to Screen-Share Scam Calls

LinkedIn Chat Leads to Screen-Share Scam Calls

The article describes multiple real-world suspected social engineering attempts that begin with friendly LinkedIn messages and quickly move to an off-platform meeting invite (often via Calendly). On the video call, the attacker refuses to turn on camera, uses a personal email address, asks the…

July 17, 2026
ClickFix Lures Spread ACR Stealer in Two Chains

ClickFix Lures Spread ACR Stealer in Two Chains

Microsoft observed real-world ACR Stealer campaigns where users are tricked by “ClickFix” prompts into running attacker-provided commands. Two main intrusion chains were seen: one loads a DLL from a remote WebDAV share and later uses Python-based loaders, and the other uses MSHTA and an image-based…

July 17, 2026
Trojanized Zoom/Webex Installers Spread Starland RAT

Trojanized Zoom/Webex Installers Spread Starland RAT

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software (like Webex, Zoom, and MobaXterm). Once a victim runs the fake installer, a custom remote-access tool (“Starland RAT”) is installed and used to…

July 16, 2026
ClickLock Tricks Mac Users Into Pasting Malware

ClickLock Tricks Mac Users Into Pasting Malware

Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake “verification” page that tells them to copy and paste a command into Terminal, which silently installs a stealer and then pressures them to enter their…

July 16, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Phishers Hide Lua Malware as “.TTF Font”

Phishers Hide Lua Malware as “.TTF Font”

A real, ongoing phishing campaign is tricking recipients into opening malicious archives that appear to contain harmless TrueType font files (.ttf) but actually hide a Lua-based loader. Once executed, the loader uses stealthy, mostly in-memory techniques to install remote access trojans and…

July 16, 2026
TELEPUZ Spreads via ClickFix “Fix” Web Lures

TELEPUZ Spreads via ClickFix “Fix” Web Lures

Researchers report a real, active malware operation where compromised websites use “ClickFix” style prompts to trick people into manually pasting and running malicious commands. The result is a multi-stage infection that downloads additional payloads and ultimately runs TELEPUZ, which can steal…

July 16, 2026
Sandworm Uses Fake CAPTCHAs to Spread Malware

Sandworm Uses Fake CAPTCHAs to Spread Malware

Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA checks. Victims are instructed to copy and paste a PowerShell command, which downloads malware and can lead to deeper compromise. CERT also…

July 16, 2026
ClickLock macOS Stealer Forces Password via Kill Loops

ClickLock macOS Stealer Forces Password via Kill Loops

Researchers observed a real macOS information-stealing campaign that tricks victims into pasting a command into Terminal from a “ClickFix” web page. After running, the malware shows a fake macOS password prompt and can repeatedly crash key apps (Finder/Dock/browsers) for hours or days to pressure…

July 16, 2026
Hijacked .gov.br Sites Used as Malware Lures

Hijacked .gov.br Sites Used as Malware Lures

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to deliver malware. The lure used official-looking police-themed documents (sometimes with QR codes) and emails that could pass common email…

July 16, 2026
ClickLock Tricks Mac Users Into Running Malware

ClickLock Tricks Mac Users Into Running Malware

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command. It then steals browser, crypto wallet, and Keychain data and sends it to attackers via a Telegram bot, while killing processes to hide…

July 16, 2026
Planted Text Tricks AI Agents Into Bad Clicks

Planted Text Tricks AI Agents Into Bad Clicks

Researchers demonstrated a new “agent data injection” technique where attackers plant content (like a review or GitHub comment) that an AI agent mistakenly treats as trusted system data. In tests, this caused web-browsing agents to click the wrong buttons (e.g., “Buy Now”) and coding agents to run…

July 16, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo