Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup post, augustus 12, 2026augustus 17, 2026 Back in December, we were the first ever to fully record the Famous Chollima infiltration cycle. From recruiting collaborators to help them land jobs at Western companies, to forging documents, shipping laptops to facilitators’ houses, and even using AI tools for live assistance and translation during interviews. During that investigation,… Continue Reading
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data post, augustus 7, 2026augustus 17, 2026 A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees… Continue Reading
CrowdStrike 2026 Global Threat Report post, februari 24, 2026februari 26, 2026 In the age of AI, even less sophisticated threat actors can execute complex attacks, and advanced adversaries have become dramatically more dangerous. This year’s report exposes the latest tradecraft of the evasive adversary, who is supercharging attacks with AI and posing an unprecedented threat. Attacks by AI-enabled adversaries increased by… Continue Reading
GitLab Threat Intelligence Team reveals North Korean tradecraft post, februari 19, 2026februari 23, 2026 Gain threat intelligence about North Korea’s Contagious Interview and fake IT worker campaigns and learn how GitLab disrupted their operations. Continue Reading
New Spiderman phishing service targets dozens of European banks post, december 10, 2025december 11, 2025 A new phishing kit called Spiderman is targeting customers of numerous European banks and cryptocurrency services using pixel-perfect replicas of legitimate sites. The platform allows cybercriminals to launch phishing campaigns that can capture login credentials, two-factor authentication (2FA) codes, and credit card data. The Spiderman phishing kit, analyzed by researchers at… Continue Reading
Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign post, oktober 22, 2025oktober 23, 2025 The Iranian nation-state group known as MuddyWater has been attributed to a new campaign that has leveraged a compromised email account to distribute a backdoor called Phoenix to various organizations across the Middle East and North Africa (MENA) region, including over 100 government entities. The end goal of the campaign is to… Continue Reading
Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign post, september 6, 2025september 8, 2025 A threat actor possibly of Russian origin has been attributed to a new set of attacks targeting the energy sector in Kazakhstan. The activity, codenamed Operation BarrelFire, is tied to a new threat group tracked by Seqrite Labs as Noisy Bear. The threat actor has been active since at least… Continue Reading
Threat Actor Impersonates Booking.com in Phishing Scheme post, maart 14, 2025maart 17, 2025 Microsoft detailed a sophisticated campaign that relies on a social engineering technique, “ClickFix,” in which a phisher uses security verification like captcha to give the target a false sense of safety. That’s according to Microsoft, which published threat intelligence on March 13 regarding a threat actor tracked as Storm-1865. The actor was… Continue Reading
A Signal Update Fends Off a Phishing Technique Used in Russian Espionage post, februari 19, 2025februari 20, 2025 Google warns that hackers tied to Russia are tricking Ukrainian soldiers with fake QR codes for Signal group invites that let spies steal their messages. Signal has pushed out new safeguards. For more than a decade now, Russian cyberwarfare has used Ukraine as a test lab for its latest hacking techniques, methods… Continue Reading
Threat Actors Exploit Government Website Vulnerabilities For Phishing Attacks post, januari 30, 2025februari 24, 2025 A recent report by Cofense Intelligence shows that how attackers are weaponizing .gov top-level domains (TLDs) across multiple countries for malicious purposes, including credential phishing, malware delivery, and command-and-control (C2) operations. Continue Reading