A reported campaign tied to APT-C-60 shows how a legitimate file-sharing service, a Windows shortcut, and a normal developer tool can be chained into a deceptive delivery path.
A single command-and-control indicator can be enough to expose the wider shape of a credential-theft operation, especially when the target is a sector where email trust and operational continuity matter.
A single RedLine-linked host became the starting point for mapping infrastructure that appears designed for maritime-themed spear phishing and BEC support.
A reported APT37 intrusion chain shows how a familiar brand, a Windows shortcut, and a legitimate cloud service can be stitched into a low-noise control path.
WhatsApp says it detected and disrupted a new wave of spear-phishing attempts linked to NSO Group, while also seeking contempt relief over an alleged breach of a court order.
An alleged Pakistan-linked operation aimed at Afghanistan’s Finance Ministry shows how a common RAT, paired with ordinary social engineering, can still carry serious intelligence value.
A likely SideCopy-linked phishing run paired a Windows .LNK file with a Pashto lure and Xeno RAT, showing how ordinary file types still anchor high-risk intrusion chains.
Operation Dragon Whistle shows how a tailored university-themed lure, a disguised Windows shortcut, and Cobalt Strike can be chained into a focused phishing operation against China’s education sector.
A reported phishing campaign uses an official-looking university notice and macOS-style folder layering to make inspection harder, showing how ordinary archives can be turned into delivery vehicles for malware.
Targeted fraud against Indian students shows how digital education can expand convenience while also giving impersonators more believable pretexts.
The real risk is not just stolen mailboxes; it is how privileged identity, trust, and rushed decisions can turn a single lure into a company-wide problem.
A reported phishing operation uses an Adobe Reader lookalike to push EchoGather RAT, showing how software-brand impersonation can make espionage payloads look routine.
Russian hackers’ new tradecraft weaves Tor and SSH into a near-undetectable backdoor for long-term espionage.
A sophisticated malware campaign weaponizes trust and advanced evasion to harvest credentials and data-right under defenders’ noses.
A new wave of targeted email attacks exploits trust and technology to breach business defenses.
Cybercriminals are hijacking the trusted PDF24 App to deploy a stealthy backdoor, bypassing modern defenses and targeting high-value victims.