Threat Watcher

Page 7 of 22
Fake WhatsApp/Instagram Sites Abuse HTTPS Padlock

Fake WhatsApp/Instagram Sites Abuse HTTPS Padlock

Researchers reported a phishing setup that clones WhatsApp and Instagram login pages and uses valid HTTPS (TLS) certificates to look legitimate. Victims are lured via WhatsApp messages about “verification,” “pending payments,” or “customer support,” then sent to typosquatted lookalike domains to…

August 11, 2026
Fake Recruiters Push ‘SopraVPN’ Malware in Interviews

Fake Recruiters Push ‘SopraVPN’ Malware in Interviews

Ukrainian CERT says Sandworm-linked actors (UAC-0145) posed as recruiters to lure IT workers into a fake hiring process. Victims were guided from job-site chats to Telegram and Zoom, then emailed “VPN assessment” files that pushed a trojanized WireGuard-based VPN client capable of silently running…

August 11, 2026
Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Drone Game Used as Recruitment Funnel

Drone Game Used as Recruitment Funnel

Investigators say an online game, “Drone Battle: Ukraine,” is being used as a lure to draw young people into a broader recruitment pipeline connected to Russia’s Alabuga Special Economic Zone. The campaign reportedly uses social media, influencers, esports, and promises like scholarships and travel…

August 11, 2026
Fake IT Help Desk Calls Hit Private Equity

Fake IT Help Desk Calls Hit Private Equity

Researchers say a threat group tracked as UNC6671 is calling employees and posing as IT help desk staff to steal login credentials and multi-factor authentication (MFA) tokens. After gaining access, the attackers reportedly exfiltrate large amounts of corporate data and then issue extortion…

August 11, 2026
FBI: Fake “Account Locked” Alerts Steal Intimate Media

FBI: Fake “Account Locked” Alerts Steal Intimate Media

The FBI warned that criminals are breaking into personal and social media accounts to steal and share intimate images and videos without consent. The campaign uses social engineering like fake customer-service texts and phishing “new login” emails to trick victims into handing over verification…

August 11, 2026
Fake Remote Dev Hires Linked to North Korea

Fake Remote Dev Hires Linked to North Korea

Researchers created a fake crypto startup and successfully hired three suspected North Korean IT workers by letting them pass normal remote hiring and onboarding checks. The suspected operatives used inconsistent identity documents and remote-access tooling to obtain legitimate employee accounts…

August 11, 2026
Deepfake Glitch Exposes Digital ID Impostor

Deepfake Glitch Exposes Digital ID Impostor

Spanish police arrested a suspect accused of using deepfake face-swapping and forged documents to pass live video identity checks and obtain digital certificates in other people’s names. Investigators say he attempted impersonation 38 times against a certificate-issuing security company, succeeding…

August 11, 2026
Ransomware Groups Impersonate IT Support on Teams

Ransomware Groups Impersonate IT Support on Teams

Dragos reports that ransomware operators are increasingly disrupting industrial production by targeting the business IT systems that support operations, even without touching industrial control systems. The report highlights real-world social engineering where attackers impersonate internal IT on…

August 11, 2026
Fake TikTok Shop Sites Mimic Badges to Steal Pay

Fake TikTok Shop Sites Mimic Badges to Steal Pay

Scammers are setting up lookalike websites that copy TikTok Shop’s design, trust badges, and wording to trick people into thinking they’re shopping inside TikTok. The main risk is entering payment (and sometimes loan-application) details into a site that has no real connection to TikTok, leading to…

August 11, 2026
Kimsuky Uses AI-Polished Phishing Lures

Kimsuky Uses AI-Polished Phishing Lures

Researchers say North Korea-linked Kimsuky is using AI tools to improve phishing campaigns that deliver malware through ZIP files containing malicious Windows shortcut (LNK) files. The lures are designed to look like legitimate international event materials, research reports, or meeting requests,…

August 10, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Levi’s Breach Started With IT Helpdesk Impersonation

Levi’s Breach Started With IT Helpdesk Impersonation

Levi Strauss reported that an unauthorized party used social-engineering to compromise three employees’ company-issued computers and steal corporate data. Reporting tied the incident to a wider campaign where attackers impersonated IT help desks using spoofed phone numbers and fraudulent websites…

August 10, 2026
Fake VS Code Extensions Spied on Devs and CI/CD

Fake VS Code Extensions Spied on Devs and CI/CD

Researchers found a short burst of counterfeit extensions on the Open VSX marketplace that copied the names and descriptions of legitimate Visual Studio Code extensions. Some of these “evil twin” extensions quietly sent developer and CI/CD environment details to a newly registered domain, creating…

August 10, 2026
Fake ‘The Odyssey’ Downloads Drop Lumma Stealer

Fake ‘The Odyssey’ Downloads Drop Lumma Stealer

Criminals are using fake pirated downloads of Christopher Nolan’s “The Odyssey” to trick people into running password-stealing malware. The files look like normal movie downloads (and may even use VLC-style icons), but are actually Windows executables that install Lumma Stealer to grab saved…

August 10, 2026
Turnkey “$TSLA Token” Kit Phishes Crypto Wallets

Turnkey “$TSLA Token” Kit Phishes Crypto Wallets

Researchers found a ready-made “scam-in-a-box” kit being sold on a cybercrime forum that impersonates Tesla and offers an exclusive “$TSLA token presale” for X (Twitter) users. The site uses personalization, urgency (countdown timers/progress bars), and a fake dashboard to trick victims into either…

August 10, 2026
RovoBlast Link Seeds Prompts to Leak Atlassian Data

RovoBlast Link Seeds Prompts to Leak Atlassian Data

Researchers found a flaw in Atlassian’s Rovo AI assistant where a single crafted link could inject attacker instructions into a user’s already-logged-in session. With one click, Rovo could be tricked into gathering internal company content and using its built-in web browsing tool to publish that…

August 10, 2026
Prompt Injection Hijacks AI Agents via “Normal” Repos

Prompt Injection Hijacks AI Agents via “Normal” Repos

The article describes how attackers can manipulate autonomous AI agents using “prompt injection,” including a Mozilla-tested proof-of-concept that hid malicious instructions inside an ordinary-looking code repository. When a developer’s AI coding agent processed and executed those instructions, it…

August 10, 2026
Levi’s Breach Tied to Phone-to-Phish Workflow

Levi’s Breach Tied to Phone-to-Phish Workflow

Levi Strauss disclosed a breach after attackers used social engineering to access three employees’ work computers and steal some corporate data. Separately, reporting and Google’s tracking describe a broader campaign where criminals call employees while posing as coworkers or IT, then send them to…

August 10, 2026
Impostor Calls Target US Finance With Spoof Sites

Impostor Calls Target US Finance With Spoof Sites

Researchers reported a real campaign against large U.S. financial firms where callers pretend to be coworkers or IT to trick employees into entering passwords and multi-factor codes on spoofed websites. After access is gained, the attackers pressure victims with data-leak threats and demand large…

August 10, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo