-
A routine threat-feed alert for a RedLine Stealer command-and-control (C2) IP morphed into a full-scale pivot investigation that exposed a tailored maritime spear‑phishing and business email compromise (BEC) ecosystem. The starting signal a UniqueSigna…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An emergent supply-chain attack vector they term “phantom squatting,” in which large language models (LLMs) routinely hallucinate plausible but nonexistent domains for legitimate brands and adversaries then preemptively register those domai…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
EvilTokens phishing hides takeover clues until browser execution leaving SOC teams needing deeper visibility to validate threats faster and reduce account risk.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A fake FIFA World Cup 2026 T-shirt giveaway scam is spreading Voidrift malware through personalized emails using company logos and trusted websites to bypass security filters.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Japan’s hotel sector is the latest target of a sophisticated phishing and remote-access trojan (RAT) campaign that leverages guest-complaint lures and an unusual resilience mechanism: a TON blockchain–based dead-drop resolver. Beginning in late May 202…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new phishing-as-a-service (PHaaS) platform called Bluekit is letting cybercriminals steal user accounts using a tricky method. While…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A concise but sophisticated phishing campaign that targeted AWS console users by abusing Cloudflare-hosted domains to deliver adversary-in-the-middle (AiTM) credential theft. Each domain served an almost identical clone of the AWS console sign-in page …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A multi-organization phishing campaign attributed to the CodeStorm family is actively targeting Microsoft 365 tenants with a tenant-aware AiTM (adversary-in-the-middle) phishing kit that combines rotating frontends and backend replay behavior under a s…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A growing trend in which attackers weaponize Microsoft 365 collaboration features to deliver persistent phishing lures via Outlook calendar invites. By abusing Microsoft 365 Groups and Outlook calendar functionality, threat actors move malicious intent…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


