Threat Watcher

Page 4 of 22
BlackFile Vishing Poses as IT Support to Extort Firms

BlackFile Vishing Poses as IT Support to Extort Firms

Researchers say the BlackFile extortion group is actively targeting large financial and other organizations using voice-phishing calls where attackers impersonate IT support to get initial access. Victims are then pressured with multimillion-dollar extortion demands and, in some cases, escalations…

August 17, 2026
SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal disclosed that nearly 40,000 customers had personal and order information exposed due to an authorization flaw in an order-tracking plug-in. While wallet secrets were not exposed, SafePal warned that criminals can use the leaked order details to run highly convincing scams (fake support,…

August 17, 2026
APT42 Lures Targets With Podcast Invites

APT42 Lures Targets With Podcast Invites

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut…

August 17, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake CAPTCHA ClickFix Delivers Stealer + MFA Relay

Fake CAPTCHA ClickFix Delivers Stealer + MFA Relay

This weekly recap includes a real attempted “ClickFix” social-engineering attack where a fake CAPTCHA on a compromised website tricks a user into running a command. The workflow leads to multiple staged downloads and ends with credential theft, including an adversary-in-the-middle (AiTM) method…

August 17, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
Brand Impersonation Emails Push Victims to Call

Brand Impersonation Emails Push Victims to Call

Cofense reports ongoing mass email campaigns that impersonate trusted brands (and even government agencies) to trick recipients into calling a phone number for “remediation.” The lures typically claim an unauthorized purchase or a password reset and use urgency to pressure victims into acting…

August 17, 2026
Fake TikTok Rewards Trap Users in Payout Loop

Fake TikTok Rewards Trap Users in Payout Loop

Scammers are creating TikTok-branded “rewards” websites that promise big cash payouts for simple actions like daily check-ins and small tasks. The sites show large balances and use countdown timers to rush users, but when users try to withdraw, the site keeps adding new requirements (referrals,…

August 17, 2026
Fake GitHub Page Tricks Mac Users Into Malware

Fake GitHub Page Tricks Mac Users Into Malware

Researchers found a real macOS malware campaign that uses a fake GitHub download page to convince users to paste a command into Terminal and enter their Mac password. The malware then steals credentials, cookies, and files, and can even turn the victim’s Chromium browser into a remotely controlled…

August 17, 2026
Public Wi‑Fi DNS Hijacks Steal Microsoft 365 Logins

Public Wi‑Fi DNS Hijacks Steal Microsoft 365 Logins

Attackers are compromising public Wi‑Fi equipment (such as in hotels and conference centers) and changing DNS settings so victims are silently redirected to look‑alike login pages. The goal is to capture usernames and passwords, including Microsoft 365 credentials, when users try to sign in.

August 17, 2026
WindRelay Scam: Tap Your Card, Lose Your Money

WindRelay Scam: Tap Your Card, Lose Your Money

Researchers say criminals are using a two-part Android malware setup (SpyNote + WindRelay) to trick victims into turning their own phones into NFC “relays” for contactless payment fraud. Victims are lured via phishing/smishing/vishing to install a malicious app, then persuaded on a live call to tap…

August 17, 2026
Recruitment Emails Hide BitB Google/Facebook Traps

Recruitment Emails Hide BitB Google/Facebook Traps

Researchers found a large recruitment-themed phishing campaign where victims receive unsolicited interview invites and are sent to fake scheduling or recruitment pages. The pages use “Browser-in-the-Browser” fake login popups to steal Google/Facebook passwords and, in some cases, capture MFA codes…

August 17, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
SafePal Leak Fuels Phishing by Fake “Support”

SafePal Leak Fuels Phishing by Fake “Support”

SafePal says an order-tracking plug-in flaw exposed order data for 39,798 customers, including names, contact details, shipping addresses, and purchase information. A customer reported receiving a suspicious email, letter, and phone call from someone pretending to be SafePal and urging them to…

August 17, 2026
DPRK “Remote Worker” Scam Slips Into Real Jobs

DPRK “Remote Worker” Scam Slips Into Real Jobs

The article describes North Korean operatives posing as legitimate remote IT candidates to get hired, obtain real company credentials, and gain trusted internal access. It cites an FBI investigation into a DPRK remote IT worker at a U.S. federal agency and a research “hire-and-observe” operation…

August 17, 2026
Vishing Console + Fake CCleaner Trap Users

Vishing Console + Fake CCleaner Trap Users

This bulletin highlights multiple real-world threats, including voice-phishing (vishing) operations that industrialize account takeovers and a fake CCleaner download site that installs spyware. The items provide concrete, repeatable lures (a vishing-driven takeover workflow and a lookalike software…

August 17, 2026
SafePal Breach Spurs Phishing & Fake Support Scams

SafePal Breach Spurs Phishing & Fake Support Scams

SafePal disclosed a breach that exposed order and contact details for nearly 40,000 customers, and warned the stolen data may be used to run targeted phishing and impersonation scams. The company cautioned customers to expect fake support messages, refund offers, and firmware-update requests…

August 17, 2026
Hidden AI Prompts in Court Filing Trigger Sanctions

Hidden AI Prompts in Court Filing Trigger Sanctions

A self-represented litigant hid “prompt injection” instructions in a court filing using tiny white text, aiming to influence any AI system that might read the document into ruling in his favor. The judge identified the concealed instructions as abusive and revoked the litigant’s electronic filing…

August 17, 2026
Fake VPN Installers Hit Afghan Telecom Targets

Fake VPN Installers Hit Afghan Telecom Targets

Acronis reported a real espionage campaign delivering a backdoor (PATCHCORD) to Afghan telecom providers and South Asian critical infrastructure by tricking victims into installing look‑alike VPN and telecom tools. The operation also used cloud services like Google Sheets (and GitHub Gists) to…

August 16, 2026
Singapore Runs AI Scam Call “Fire Drills”

Singapore Runs AI Scam Call “Fire Drills”

Singapore’s Cyber Security Agency is running a national exercise where volunteers receive simulated robocalls that mimic government impersonation scams, including AI-enabled calls. The article also points to real-world cases where criminals impersonated company executives on WhatsApp and even used…

August 15, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo