Attackers have also used Vercel's infrastructure for hosting logos of the spoofed companies and other resources, according to a report from Okta Threat Intelligence researchers.
Attacks part of the campaign, which was initially discovered by Mexican journalist Ignacio Gomez Villaseñor in May, involved malicious websites with fraudulent checkout pages and scraped product listings that facilitate the exfiltration of card data, a report from Silent Push showed.
Malicious QR code phishing emails with PDF attachments have been leveraged to trick victims into entering a phone call with the attacker purporting to be a customer service representative who coaxes sensitive information disclosures or malware installation, according to an analysis from Cisco Talos.
BleepingComputer reports that threat actors could facilitate covert malicious script execution by using a new variant of the FileFix attack technique, which entails the abuse of browsers' management of saved HTML pages.
Advanced persistent threat operation Blind Eagle, also known as APT-C-36, APT-Q-98, and AguilaCiega, has been leveraging Proton66, a Russian bulletproof hosting service, as part of its infrastructure in recent phishing attacks against banks and other financial entities across Colombia, including BBVA, Davivienda, Banco Caja Social, and Bancolombia, reports The Hacker News.
More than 350 organizations and nearly 1,800 email addresses were discovered by Proofpoint researchers to have been targeted by a new phishing fraud scheme involving the spoofing of the Department of Government Efficiency initially flagged by the Scoop News Group, according to FedScoop.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.