India’s markets watchdog has warned about a rising “Boss Scam,” a reminder that social engineering can be more dangerous than malware when authority is the weapon.
A reported campaign tied to APT-C-60 shows how a legitimate file-sharing service, a Windows shortcut, and a normal developer tool can be chained into a deceptive delivery path.
A phishing lure impersonating India’s tax authority reportedly used fake government branding and a six-step delivery path to reach in-memory RAT-style payloads.
A single command-and-control indicator can be enough to expose the wider shape of a credential-theft operation, especially when the target is a sector where email trust and operational continuity matter.
A counterfeit Indian tax notice was used as bait for a staged Windows payload chain, showing how authority-themed lures can turn a simple click into a layered malware problem.
A tax-branded phishing operation uses a lookalike portal and a disk-image attachment to exploit trust, urgency, and the habit of opening official-looking files.
A malicious VBScript lure dressed up as a document shows how trusted chat channels can carry administrative tools into the wrong hands.
India's temporary block on Telegram highlights a familiar security problem: digital content can be staged to look like proof, even when the timeline is the real target.
Fake SMS and WhatsApp messages are being used in phishing campaigns aimed at SBI digital banking customers, turning account anxiety into a weapon.
Fraudulent YONO messages use Aadhaar-related urgency to push SBI customers toward unsafe actions, a pattern that looks more like social engineering than any platform exploit.
A campus-themed spear-phishing campaign pairs a believable university notice with folder camouflage and staged execution to make malware harder to spot.
Targeted fraud against Indian students shows how digital education can expand convenience while also giving impersonators more believable pretexts.
Fraudulent Android apps promised secret call histories, but left users with empty wallets and fake data.
A cunning phishing campaign weaponized genuine legal files and modular malware to steal credentials and spy on executives in Vietnam and the Philippines.
A sprawling network of fake “call history” apps duped millions, exploiting Google Play’s trust and draining wallets across Asia.
Over 7 million Android users fell victim to fraudulent apps promising impossible access to private call histories-and paid the price.
A wave of fake tax notices unleashes powerful backdoors, blending public tools and custom malware to target organizations across India, Russia, and Southeast Asia.
Chinese-linked hackers exploit tax season panic with sophisticated malware chain, targeting organizations in India and Russia.
State-backed hackers are zeroing in on universities and research centers, using spear-phishing and supply chain attacks to steal sensitive data and disrupt education worldwide.