Martedi 28 Luglio 2026 21:48:31 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContattiLogin
ItalianoEnglish

#social engineering


TELEPUZ and the Trap of the Helpful Website

Published: 16 July 2026 16:55Category: Malware & BotnetsAuthor: SIGNALMONK

A modular malware campaign tied to ClickFix lures shows how a single user action can become the start of a much larger compromise.

When a CAPTCHA Becomes a Shell Prompt

Published: 16 July 2026 16:09Category: Cyber Warfare & Nation-State OperationsGeo: Europe / UkraineAuthor: AGONY

A trust signal built to block bots can be repurposed into a social-engineering step that nudges Windows users toward running PowerShell commands.

Arrests Expose the Industrial Scale of Crypto Fraud

Published: 16 July 2026 14:35Category: CybercrimeGeo: Europe / NetherlandsAuthor: CRYSTALPROXY

A cross-border police action against an alleged investment scam network shows how modern crypto fraud depends on persuasion, speed, and payment flows more than on malware.

Europe’s Scam Network Takedown Exposes the Scale of Organized Investment Fraud

Published: 16 July 2026 14:27Category: CybercrimeGeo: Europe / NetherlandsAuthor: CRYSTALPROXY

Dutch police and Europol moved against an alleged investment-fraud network after arrests in multiple European countries, underscoring how scam operations can grow across borders and industrialize trust abuse.

OkoBot Turns Crypto Security Into a Trap of Prompts, Extensions, and Stolen Secrets

Published: 16 July 2026 14:11Category: Malware & BotnetsAuthor: SIGNALMONK

The malware case shows how one hostile workflow can move from fake software delivery to browser abuse and wallet-app surveillance, all aimed at crypto credentials.

Paid Search, Shared AI Links, and a Mac Stealer: The New Trust Trap

Published: 16 July 2026 10:43Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A macOS malware campaign used Google Ads and Claude shared-chat links as delivery channels, showing how attackers can turn familiar services into a credential-harvesting lure.

Shared Chat Links, Silent Theft: How a Claude Lure Became a Mac Malware Trap

Published: 16 July 2026 10:06Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A ClickFix-style campaign is reportedly using shared Claude chats as bait, showing how a normal collaboration feature can be repurposed into a trust channel for macOS credential theft.

Fake Security Alerts Turn Password Trust Into a Phishing Trap

Published: 14 July 2026 18:03Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A campaign using spoofed security notices against LastPass and Bitwarden users shows how attackers can weaponize the very language of account protection to lure victims onto fraudulent websites.

Signal Under Pressure: When Secure Messaging Becomes a Battle Over Identity

Published: 14 July 2026 14:22Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

The strongest cryptography can still be undermined if an attacker goes after the account, the phone number, or the person holding the device.

Signal Under the Microscope: Why a Targeted Spy Hunt Points to Trust, Not Broken Encryption

Published: 14 July 2026 12:25Category: Cyber Warfare & Nation-State OperationsGeo: Europe / ItalyAuthor: AGONY

A suspected espionage effort aimed at a narrow circle of Italian figures shows how encrypted messaging can still be pressured through identity checks, linked devices, and account control.

Conference Optics, Security Signals: What a Public Delegation Really Means

Greenhat’s announced appearance at Web Summit Vancouver 2026 is not a breach story, but it does underline how public-facing tech events can increase the need for verification and identity discipline.

SMS Lure Masquerades as a Missed Bartolini Delivery

Published: 13 July 2026 18:14Category: Security Awareness & Social EngineeringGeo: Europe / ItalyAuthor: PATCHKNIGHT

A courier-themed phishing campaign uses a fake failed-delivery notice to push recipients toward a form that asks for personal details and payment-card data.

When the Scam Becomes the Trap: AI Personas Move Into Phishing Defense

Published: 13 July 2026 16:22Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

ScamBuster shows how defenders are starting to answer email fraud with their own scripted identities, turning attacker conversation into a potential intelligence source.

When a Conference Invite Turns into a Malware Delivery Lane

Published: 13 July 2026 10:43Category: Cyber Warfare & Nation-State OperationsGeo: Asia / South KoreaAuthor: AGONY

A reported spear-phishing campaign borrowed real event details, then used an ISO container and process injection to move RokRAT onto Windows systems.

Passkeys Become the Bait: A Vishing Crew Turns Microsoft Entra Enrollment Into a Trap

Published: 10 July 2026 14:46Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A panel-driven phishing operation is using fake security calls to pressure Microsoft 365 users into registering a new passkey, showing how identity attacks can target the enrollment process instead of the login itself.

Fake Microsoft Sign-In Pages Turn a Phone Call into an Identity Trap

Published: 10 July 2026 14:24Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.

Mac Malware Learns to Wear a Wallet: How Odyssey Stealer Uses Native macOS Tools for Theft

Published: 10 July 2026 12:38Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A macOS infostealer campaign is blending social engineering, AppleScript, and LaunchDaemons to collect credentials and push fake crypto-wallet software onto infected Macs.

The Phone Number Was the Trap: How a Robinhood Impersonation Campaign Escapes Email Defenses

Published: 10 July 2026 10:18Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A callback-phishing lure uses fake account sign-in alerts to pull targets off the inbox and into a live voice scam, where trust is easier to exploit and harder to automate away.

The Phone Call Was the Trap: Robinhood-Style Alerts Turn Trust into a Weapon

Published: 10 July 2026 10:16Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A callback-phishing campaign uses fake sign-in warnings to push recipients away from inbox checks and into attacker-controlled voice channels.

The Ransomware Market Is Growing - and AI Is Making the Human Part Cheaper

Published: 09 July 2026 18:27Category: Cyber Intelligence & Threat TrendsAuthor: GHOSTCOMPLY

A new ransomware snapshot points to a crowded criminal economy shaped by concentration at the top and by AI that appears to speed up familiar social-engineering work rather than invent a new kind of attack.