A July 2026 disruption did not end the threat around Kratos - it appears to have pushed its methods into fresh Microsoft 365 phishing campaigns.
A malvertising campaign is using Google Ads and a fake Claude Code installer to reach macOS users, showing how cybercrime now leans on trust instead of obvious exploits.
The disruption of Kratos may have removed one criminal service, but the deeper problem is the reusable playbook behind modern Microsoft 365 account-takeover campaigns.
A reported social-engineering intrusion used fake IT contact, Microsoft Teams, and Quick Assist to reach employee computers before the GoGRPC backdoor was installed, with ransomware ties still unconfirmed.
A counterfeit Microsoft Teams update flow is being used to push legitimate remote management tools onto victim systems, blurring the line between phishing and admin software abuse.
A cluster of impersonation domains shows how attackers can abuse search traffic, brand trust, and download reputation before any file ever reaches the desktop.
A large impersonation campaign used clone domains, copied branding, and AI-written pages to make bogus Windows app sites look routine and trustworthy.
A phishing run dressed up as shipping notices and tax-audit mail shows how attackers can turn everyday business trust into a credential-theft pipeline.
A guilty plea tied to a Snapchat phishing case shows how account takeover can turn routine social engineering into intimate privacy loss.
A guilty plea tied to Snapchat code theft shows how one-time codes can fail when attackers aim at the user, not the platform.
Attackers are using Microsoft Teams conversations to pose as internal IT support, turning a trusted workplace channel into a path for credentials, remote access, and account takeover attempts.
Microsoft’s warning points to a harder problem for defenders: attackers are increasingly exploiting the trust built into workplace communication tools, with Teams emerging as a prime social-engineering surface.
A credential-stuffing incident against Chick-fil-A One shows how stolen logins can turn a consumer rewards account into a fraud target without any need for a software exploit.
A new FBI warning shows how criminals are blending impersonation, synthetic media, and lookalike complaint portals to catch fraud victims at their most vulnerable.
A federal warning points to a sharper fraud pattern: synthetic media and spoofed complaint portals are being used to squeeze people who have already lost money once.
AiTM phishing turns a trusted login screen into a relay point for credentials, MFA output, and live session tokens, which can make account takeover look like a normal sign-in.
AiTM phishing can turn a routine vendor request into a live browser hijack, letting attackers reuse an authenticated Microsoft 365 session even after MFA is completed.
A fraud pattern built on deepfake video, spoofed complaint pages, and false recovery promises shows how criminals can turn trust in institutions into a second attack.
Fraudsters are using FaceTime calls to impersonate banks, tech support, and government officials, making old social engineering tactics feel more immediate and harder to question.
A macOS malware campaign used Google Ads and Claude shared-chat links as delivery channels, showing how attackers can turn familiar services into a credential-harvesting lure.