phishing

Phishing Campaign Baits Hook With Malicious Amazon PDFs

Phishing campaign uses malicious PDFs claiming expired Amazon Prime memberships to trick users into revealing personal and financial data. Researchers at Palo Alto Networks Unit42 found 31 such PDFs linking to fake Amazon sites, utilizing cloaked domains to evade detection. Users are advised to be cautious of suspicious emails.

https://www.darkreading.com/cyberattacks-data-breaches/phishing-campaign-malicious-amazon-pdfs

Targeted Supply Chain Attack Against Chrome Browser Extensions

TLDR: On December 26, 2024, Cyberhaven reported a targeted supply chain attack on their Chrome extension via compromised developer permissions gained through phishing. The attacker injected malicious code into a dozen extensions, aiming to harvest sensitive data (API keys, session cookies) from hundreds of thousands of users, including those of ChatGPT and Facebook. The report details phishing tactics, the compromised extensions, and the adversary's infrastructure, urging users to remove affected extensions and monitor their accounts for suspicious activity.

https://blog.sekoia.io/targeted-supply-chain-attack-against-chrome-browser-extensions/

Sneaky 2FA: Exposing a New AiTM Phishing-as-a-Service

TLDR: Sekoia.io identified a new phishing kit named “Sneaky 2FA,” part of a phishing-as-a-service operation targeting Microsoft 365 accounts. Discovered in December 2024, it utilizes advanced techniques, including autograb for email input and anti-bot measures. The service is marketed via a Telegram bot and relies on compromised domains. It captures session cookies post-authentication, making it a significant threat. Detection measures focus on identifying inconsistent user-agent strings indicative of phishing attempts.

https://blog.sekoia.io/sneaky-2fa-exposing-a-new-aitm-phishing-as-a-service/

Scroll to Top