NBC News reports that Google has filed a lawsuit seeking a temporary restraining order against Chinese-speaking cybercriminal operation Darcula, which has offered the Magic Cat software to facilitate widespread phishing scams spoofing the Internal Revenue Service and the U.S. Postal Service.
The operation, run by M/s Lord Mahavira Services India Pvt. Ltd., utilized an online platform to control approximately 21,000 SIM cards, obtained in violation of telecommunications rules.
BleepingComputer reports that legitimate PayPal emails with fraudulent purchase notifications have been sent by exploiting the fintech platform's "Subscriptions" billing functionality as part of a new email scam.
Newly emergent phishing kits BlackForce, GhostFrame, InboxPrime AI, and a Salty-Tycoon hybrid could allow extensive credential exfiltration activities, according to The Hacker News.
Threat actors could stealthily compromise Microsoft accounts through the exploitation of the Azure CLI OAuth app as part of the new ConsentFix attack, which is yet another twist to the ClickFix social engineering technique, according to BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.