More than 15,000 fraudulent websites impersonating TikTok Shop have been leveraged to facilitate the deployment of information- and cryptocurrency-stealing malware, as well as spyware, as part of the global ClickTok scam campaign, Cybernews reports.
Hackread reports that threat actors have been exploiting Microsoft 365's Direct Send feature, which is originally meant to expedite fax and scan deliveries to email addresses, to facilitate a phishing campaign that involves malicious internal-looking emails.
Artificial intelligence has been used to create a new malicious npm package impersonating the "NPM Registry Cache Manager" that includes a clandestine cryptocurrency wallet drainer that could compromise Windows, Linux, and macOS systems, reports The Register.
Hackread reports that malicious actors have begun using malicious Windows shortcut files to distribute the Remcos RAT malware as part of a new attack campaign.
Android users across Europe have been targeted with attacks involving a more sophisticated iteration of the DoubleTrouble banking trojan, Infosecurity Magazine reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.