The phishing campaign, first detected in mid-December 2025, months before Pride Month, targets organizations globally, with the UK and United States being heavily impacted.
The campaign, active throughout 2024 and 2025, begins with emails containing attachments disguised as documents, often using double extensions like Document.doc.lnk.
Apple users have been targeted with an advanced voice-based phishing intrusion that weaponizes Apple Pay fraud alerts to facilitate real-time login credential and two-factor authentication code compromise, reports Cybernews.