The Nigerian police's National Cybercrime Centre has arrested suspected RaccoonO365 phishing-as-a-service kit developer Okitipi Samuel and two others through information from the FBI, the U.S. Secret Service, and Microsoft, according to The Record, a news site by cybersecurity firm Recorded Future.
Threat actors have ramped up phishing campaigns harnessing Microsoft's OAuth device code authorization flow to compromise Microsoft 365 accounts since September, according to Infosecurity Magazine.
NBC News reports that Google has filed a lawsuit seeking a temporary restraining order against Chinese-speaking cybercriminal operation Darcula, which has offered the Magic Cat software to facilitate widespread phishing scams spoofing the Internal Revenue Service and the U.S. Postal Service.
The operation, run by M/s Lord Mahavira Services India Pvt. Ltd., utilized an online platform to control approximately 21,000 SIM cards, obtained in violation of telecommunications rules.
BleepingComputer reports that legitimate PayPal emails with fraudulent purchase notifications have been sent by exploiting the fintech platform's "Subscriptions" billing functionality as part of a new email scam.
Newly emergent phishing kits BlackForce, GhostFrame, InboxPrime AI, and a Salty-Tycoon hybrid could allow extensive credential exfiltration activities, according to The Hacker News.