phishing

Quantum Route Redirect PhaaS Targets Microsoft 365 Users Worldwide

Quantum Route Redirect, a new phishing automation platform, uses around 1,000 domains to steal Microsoft 365 credentials, primarily targeting users in the U.S. It automates phishing attacks by routing victims to malicious sites through deceptive emails. The kit is designed for ease of use, even for less skilled attackers, and incorporates mechanisms to evade detection by automated security tools. Security analysts recommend implementing robust URL filtering to combat this threat.

https://www.bleepingcomputer.com/news/security/quantum-route-redirect-phaas-targets-microsoft-365-users-worldwide/

5 Reasons Why Attackers Are Phishing Over LinkedIn

LinkedIn phishing is rising, with 34% of attacks occurring outside email. Key reasons include:

  1. Bypasses traditional security tools since LinkedIn DMs evade email security protections.
  2. Cheap and easy for attackers, leveraging legitimate account hijacking.
  3. Facilitates targeting high-value individuals due to easy reconnaissance.
  4. Users more likely to trust messages from familiar contacts.
  5. Potential rewards are high because breaches can compromise core business accounts and data.

Organizations must adapt security to guard against these threats across multiple channels, not just email.

https://www.bleepingcomputer.com/news/security/5-reasons-why-attackers-are-phishing-over-linkedin/

Anatomy of Tycoon 2FA Phishing: Tactics Targeting M365 and Gmail

Tycoon 2FA Phishing Kit Overview:
Emerging in August 2023, Tycoon 2FA is a sophisticated phishing threat leveraging multi-factor authentication (MFA) bypass techniques, primarily targeting Microsoft 365 and Gmail users. With over 64,000 incidents reported in 2025, it employs a Phishing-as-a-Service platform to capture user credentials via a reverse proxy and deceptive login pages. The attack exploits various distribution methods, including PDFs, and evades detection with anti-research mechanisms and real-time MFA code capture. Enhanced security measures and user education are essential to mitigate risks associated with Tycoon 2FA.

https://gbhackers.com/tycoon-2fa-phishing/

Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation

Smishing Triad linked to over 194,000 malicious domains in a global phishing scheme since January 2024, targeting various services. The group, based in China, scams users with fake notifications, generating over $1 billion in three years. Their infrastructure uses U.S. cloud services, registering many disposable domains to evade detection. These campaigns increasingly target brokerage accounts, manipulating stock prices under the “phishing-as-a-service” model, employing a network of developers and spammers.

https://thehackernews.com/2025/10/smishing-triad-linked-to-194000.html

AI Makes Phishing 4.5x More Effective, Microsoft Says

Microsoft's report reveals AI enhances phishing emails, boosting click rates from 12% to 54% and potentially increasing profitability by 50 times. Cybercriminals exploit AI for targeted attacks, utilizing tools like voice cloning and deepfakes. Nation-state actors are also adopting AI for cyber operations. Additionally, new tactics like “ClickFix” have emerged, allowing attackers to manipulate users into executing malware. Overall, AI significantly alters phishing strategies, making attacks more efficient and harder to detect.

https://www.theregister.com/2025/10/16/ai_makes_phishing_45x_more_effective/

AI Vs. AI: Detecting an AI-obfuscated Phishing Campaign

A blog post discusses a phishing campaign in which AI was likely used to create complex, obfuscated code, disguising it as a legitimate document. Microsoft Defender for Office 365 successfully detected and blocked this campaign through behavioral and infrastructural analysis, emphasizing the need for continuous vigilance against AI-aided threats. Recommendations for organizations include improved email settings and user education to protect against such phishing tactics.

https://www.microsoft.com/en-us/security/blog/2025/09/24/ai-vs-ai-detecting-an-ai-obfuscated-phishing-campaign/

Defending Against Evolving Identity Attack Techniques

Microsoft's blog discusses evolving identity attack methods by threat actors, emphasizing the rise in sophisticated phishing techniques targeting cloud identities despite advances like MFA and passwordless solutions. The article highlights various modern phishing methods, including adversary-in-the-middle attacks, device code phishing, OAuth consent phishing, and phishing via enterprise communication platforms, particularly Microsoft Teams. It stresses the importance of user education and advanced security measures (e.g., conditional access policies and Zero Trust) to protect against these threats. Recommendations for organizations include implementing phishing-resistant MFA, user training, and leveraging Microsoft Entra for enhanced security.

https://www.microsoft.com/en-us/security/blog/2025/05/29/defending-against-evolving-identity-attack-techniques/

Phishing Attack Uses Blob URIs to Show Fake Login Pages in Your Browser

Cofense Intelligence reports a phishing technique using blob URIs to create fake login pages in browsers, evading email security and stealing credentials. Blob URIs, which store data temporarily on local machines, make it difficult for security systems to detect malicious activity since external checks cannot see them. Attackers often redirect users from trustworthy sites to fake pages, posing a serious challenge for email security systems.

https://hackread.com/phishing-attack-blob-uri-fake-login-pages-browser/

Catching a Phish With Many Faces

Summary: Phishing attacks are evolving, utilizing phishing-as-a-service toolkits to create dynamic, customizable fake login pages in real-time. These pages appear legitimate by using logos and branding from legitimate sources, making detection difficult. Attackers leverage urgency-inducing messages to entice victims to click links, often sending login credentials directly via AJAX. To protect against these threats, users should verify link authenticity, use strong passwords, enable two-factor authentication, and employ robust security measures. Cybercriminals continue to adapt their tactics, making awareness and technological defenses crucial.

https://www.welivesecurity.com/en/scams/spotting-phish-many-faces/

CISA and FBI Warn Fast Flux Is Powering Resilient Malware, C2, and Phishing Networks

CISA and FBI warn that “fast flux” technique aids malware, C2, and phishing networks by obscuring malicious server locations through rapid DNS record changes. It's a persistent network security threat, complicating tracking and blocking by authorities. Recommended countermeasures include blocking malicious IPs and domains and enhancing monitoring.

https://thehackernews.com/2025/04/cisa-and-fbi-warn-fast-flux-is-powering.html

Threat Actors Leverage Tax Season to Deploy Tax-themed Phishing Campaigns

Microsoft warns of tax-themed phishing campaigns as Tax Day approaches, where attackers use social engineering to steal credentials and deploy malware. Techniques include URL shorteners, QR codes, and fake IRS notifications leading to malicious downloads, such as BruteRatel and Latrodectus. Microsoft’s recommendations for protection emphasize user education, advanced anti-phishing solutions, and using tools like Microsoft Defender Office 365 to block suspicious emails.

https://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/

The Weaponization of PDFs : 68% of Cyber Attacks Begin in Your Inbox, With 22% of These Hiding in PDFs

68% of cyberattacks start via email; 22% involve malicious PDFs. With over 400 billion PDFs opened in a year, PDFs serve as effective delivery mechanisms for attacks due to their complexity and perceived safety. Attackers leverage social engineering and advanced evasion techniques, making it hard for security systems to detect threats. Typical PDF attacks include link-based campaigns leading to phishing sites, utilizing benign links and QR codes for obfuscation. Users are advised to verify senders, be cautious with unexpected attachments, and keep software updated to mitigate risks.

https://blog.checkpoint.com/research/the-weaponization-of-pdfs-68-of-cyberattacks-begin-in-your-inbox-with-22-of-these-hiding-in-pdfs/

YouTube Warns of AI-generated Video of Its CEO Used in Phishing Attacks

YouTube warns that scammers are using AI-generated videos of CEO Neal Mohan in phishing attacks to steal creators' credentials. These videos are sent via emails claiming changes to monetization policies, urging recipients to click links leading to credential-stealing sites. YouTube advises against clicking suspicious links and highlights that it will never communicate through private videos. Many creators have already been victimized, resulting in hijacked accounts used for scams.

https://www.bleepingcomputer.com/news/security/youtube-warns-of-ai-generated-video-of-its-ceo-used-in-phishing-attacks/

LARVA-208

LARVA-208 is a threat actor known for sophisticated spear-phishing attacks since June 2024, utilizing smishing and vishing tactics to install RMM software on victims' machines. Their methods include creating phishing sites to harvest VPN credentials and using fake calls or messages to divert victims to malicious links. They deploy data stealers and ransomware after gaining access, having compromised over 618 organizations, often linked to LARVA-148 for domain acquisitions. LARVA-208 exemplifies advanced, targeted cyber attack strategies emphasizing social engineering and evasion of security measures, posing ongoing threats to corporate networks.

https://catalyst.prodaft.com/public/report/larva-208/overview

Cybercriminals Weaponize Graphics Files in Phishing Attacks

Cybercriminals are increasingly using graphics files, especially SVGs, in phishing attacks to bypass traditional security measures. These files can contain active web content, allowing attackers to link to malicious websites while disguising their intent. The tactics have evolved, with attacks impersonating known brands and employing various lures, such as notifications and confirmations. The attacks often capture victim login credentials, showcasing new phishing techniques aimed at evading detection and multi-factor authentication protections.

https://www.infosecurity-magazine.com/news/cybercriminals-graphics-files/

Scroll to Top