scams

Warning: Scammers Are Using FaceTime to Empty Bank Accounts

Scammers are exploiting FaceTime to conduct social engineering attacks, impersonating Apple Support or banks to trick users into revealing sensitive information or installing remote-access software, potentially leading to drained bank accounts. Apple urges users to avoid sharing personal data during unsolicited calls, keep devices updated, and report suspicious FaceTime calls to help mitigate these threats.

https://www.malwarebytes.com/blog/news/2026/07/warning-scammers-are-using-facetime-to-empty-bank-accounts

The Booking.com Phishing Campaign Targeting Hotels and Customers

Since January 2026, a phishing campaign has targeted hotels and their customers by impersonating Booking.com to conduct financial fraud. The attack unfolds in three stages: initial phishing emails sent to hotel partners to harvest credentials via a partner phishing kit, followed by customer-targeted phishing to steal financial information, delivered in part through WhatsApp. The campaign uses domain spoofing, typosquatting, and advanced evasion techniques such as user fingerprinting to avoid detection, posing significant risks to the hospitality sector.

https://www.bridewell.com/insights/blogs/detail/the-booking.com-phishing-campaign-targeting-hotels-and-customers

‘Deepfake as a Service’ Sees 39% Spike in Dark Web Conversations — and Experts Fear It Will Fuel the Next Wave of “Fake Boss” Scams

Discussions about “deepfake as a service” have surged by 39% on dark web forums, raising concerns among experts that this trend could intensify “fake boss” scams, where attackers impersonate executives to deceive employees. The rise of easily accessible deepfake technology lowers barriers for cybercriminals to conduct sophisticated social engineering attacks. Experts warn that this development may lead to more convincing and frequent fraud attempts targeting organizations.

https://www.techradar.com/pro/security/deepfake-as-a-service-sees-39-percent-spike-in-dark-web-conversations-and-experts-fear-it-will-fuel-the-next-wave-of-fake-boss-scams

88% of People Struggle to Tell What’s Real Online

A Malwarebytes survey of 1,500 adults across several countries found that 88% of people struggle to distinguish real online content from AI-generated fakes, with 85% reporting difficulty telling scams from genuine interactions—an increase from 66% last year. Half of respondents have encountered AI-driven fraud, including AI-generated product photos and personalized scams, while 19% experienced AI-related identity harms like non-consensual explicit content creation. The findings highlight growing challenges in online trust and identity due to AI-enabled deception, urging increased awareness and protective measures.

https://www.malwarebytes.com/blog/ai/2026/06/88-of-people-struggle-to-tell-whats-real-online

A Backdoor in a LinkedIn Job Offer

A LinkedIn message from a recruiter at a crypto startup led Roman Imankulov to analyze a suspicious GitHub repo purportedly needing a Node modules review. The repo contained a hidden backdoor in a test file that executed arbitrary code fetched from a remote server whenever dependencies were installed, triggered by an npm lifecycle script. The repo and recruiter used stolen identities, highlighting the risk of supply-chain and social engineering attacks via seemingly legitimate job offers.

https://roman.pt/posts/linkedin-backdoor/

These Convincing Copyright Notices Are Designed to Steal Google Logins

A new phishing scam targets Chrome extension developers with fake copyright removal notices designed to steal Google login credentials. The scam uses publicly available extension information to create convincing personalized warnings and a fake Google sign-in window, pressuring victims to enter their credentials before a fabricated deadline. Developers are advised to verify warnings only through their Chrome Web Store dashboard and to safeguard accounts with strong authentication and security software.

https://www.malwarebytes.com/blog/threat-intel/2026/06/these-convincing-copyright-notices-are-designed-to-steal-google-logins

Hundreds of Orgs Compromised Daily in Microsoft Device Code Phishing Attacks

A widespread Microsoft device-code phishing campaign has been compromising hundreds of organizations daily since mid-March 2026, using AI and automation to bypass multi-factor authentication and gain access to corporate Microsoft 365 accounts. The attackers generate dynamic device codes to trick victims into authorizing access, enabling them to steal sensitive financial emails and data, with the phishing infrastructure leveraging legitimate cloud services to evade detection. Microsoft recommends limiting the use of device code authentication and training employees to recognize phishing attempts to mitigate such attacks.

https://www.theregister.com/2026/04/07/microsoft_device_code_phishing/

New macOS Stealer Campaign Uses Script Editor in ClickFix Attack

A new macOS malware campaign delivering the Atomic Stealer exploits the built-in Script Editor app via a variation of the ClickFix attack, tricking users into running malicious scripts without manual Terminal interaction. The attack uses fake Apple-themed websites that launch Script Editor with pre-filled code to download and execute obfuscated payloads, targeting sensitive data such as Keychain items, browser passwords, and cryptocurrency wallets. Mac users are advised to treat Script Editor prompts with caution and rely only on official Apple documentation for system guidance.

https://www.bleepingcomputer.com/news/security/new-macos-stealer-campaign-uses-script-editor-in-clickfix-attack/

Scam Compounds Hiring “AI Models” to Seal the Deal in Deepfake Video Calls

Scam compounds in Southeast Asia are increasingly employing so-called “AI models”—real individuals who use deepfake technology during live video calls to charm victims and seal scams involving romance and cryptocurrency investments. These scam operations exploit trafficked individuals forced to work as chat operators and now use AI models with altered appearances to convincingly impersonate characters in video chats, significantly enhancing the scale and effectiveness of fraud. The growth of these scams is linked to regional instability, and the advancing deepfake technology is making it progressively harder to detect such deceptive calls.

https://www.malwarebytes.com/blog/news/2026/03/scam-compounds-hiring-ai-models-to-seal-deal-in-deepfake-video-calls

InstallFix: Weaponizing Malvertized Install Guides

Attackers are using a technique called InstallFix, a social engineering attack where they clone installation pages of legitimate CLI tools and present victims with malicious install commands disguised as the real thing. This technique is particularly effective because it exploits the common practice of copying and pasting installation commands from websites, bypassing traditional security controls like email filtering. The attackers are using malvertising, specifically sponsored search results on Google, to distribute these fake installation pages, targeting popular tools like Claude Code.

https://pushsecurity.com/blog/installfix/

1Campaign: A New Cloaking Platform Helping Attackers Abuse Google Ads

1Campaign is a cloaking platform that helps attackers bypass Google Ads screening and evade security researchers. It uses real-time visitor filtering, fraud scoring, and geographic targeting to keep phishing and crypto drainer pages online longer. The platform enables ad fraud at scale by allowing attackers to impersonate legitimate brands in Google Ads campaigns.

https://www.varonis.com/blog/1campaign

Refund Scam Impersonates Avast to Harvest Credit Card Details

A phishing scam impersonating Avast tricks users into providing credit card details for a fake €499.99 refund. The scam employs a realistic site design, urgency tactics, and live chat support to deceive victims. Signs of such scams include unrecognized charges, urgent cancellation notices, and requests for complete card information. If victimized, contact your bank, dispute unauthorized charges, and enhance security practices.

https://www.malwarebytes.com/blog/threat-intel/2026/02/refund-scam-impersonates-avast-to-harvest-credit-card-details

Fake Zoom Meeting “Update” Silently Installs Surveillance Software

Fake Zoom meeting website installs surveillance software, Teramind, on Windows without user consent. Visitors encounter a fraudulent Zoom interface that prompts an automatic update, leading to malicious file download. The stealthily installed software monitors user activity without knowledge, resembling legitimate business surveillance tools. Users are advised not to open suspicious files from the site and to check for unauthorized installations. This exploit illustrates the rising trend of attackers using legitimate software for illicit purposes.

https://www.malwarebytes.com/blog/scams/2026/02/fake-zoom-meeting-update-silently-installs-surveillance-software

Facebook Ads Spread Fake Windows 11 Downloads That Steal Passwords and Crypto Wallets

Malicious Facebook ads mimicking Microsoft promote fake Windows 11 downloads, leading users to download malware instead of updates. This malware stealthily collects passwords and cryptocurrency data. It employs sophisticated evasion techniques, targeting regular users while avoiding detection by security systems. If affected, users should avoid logging in to accounts, scan their devices, change passwords on a secure device, and take precautions with any financial information. Security teams are advised to block phishing domains and monitor for specific malware signatures.

https://www.malwarebytes.com/blog/scams/2026/02/facebook-ads-spread-fake-windows-11-downloads-that-steal-passwords-and-crypto-wallets

How Global Cybercrime Syndicates Are Stealing Hearts — and Billions

Global cybercrime syndicates are exploiting romance scams, using AI to create convincing online identities to deceive victims, particularly during Valentine's season. In 2024, Americans lost over $16 billion to cybercrime, with one in seven adults affected by romance schemes. These scams, targeting older demographics, leverage trust and urgency to manipulate victims, often moving conversations off safer platforms. Law enforcement faces challenges due to the international nature of these operations, but agencies like the FBI are forming global partnerships to combat them. Vigilance is necessary for online daters, as pressure tactics are common indicators of scams.

https://www.politico.com/news/2026/02/14/how-global-cybercrime-syndicates-are-stealing-hearts-and-billions-00780481

Scroll to Top