MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
37 articles from Infosecurity Magazine in Phishing
A phishing campaign disguises a Lua-based loader as a TrueType font file to distribute remote access trojans and information-stealing malware. The attack uses email-based delivery to compromise targets globally.
A six-month phishing campaign leveraged seasonal eCard lures to deliver legitimate remote management tools to victims. The attack used social engineering via email to compromise targets. Email security professionals should monitor for eCard-themed phishing and suspicious RMM tool deployments.
Sophos research reveals compromised credentials have become the primary ransomware entry point, surpassing software vulnerabilities. Phishing and brute force attacks enable attackers to gain initial access before deploying ransomware, affecting organizations across sectors.
A misconfigured open directory exposed infrastructure details for three phishing operators using Evilginx, a tool that bypasses multi-factor authentication. This reveals active phishing campaigns targeting email credentials and MFA tokens, directly impacting email security defenses.
Phishing attacks targeted Facebook users with fake verification offers and a compromised chatbot to steal sensitive information from business accounts. Attackers impersonated legitimate verification processes to compromise credentials and data.
Cybercriminals impersonate Interpol in phishing emails to distribute ransomware to businesses globally. This attack leverages authority spoofing to increase email credibility and infiltration success rates against organizational targets.
Brazilian banking trojan Ousaban is actively targeting Spain and Portugal through phishing campaigns. FortiGuard has identified the threat, which uses email as a delivery vector to compromise financial accounts in the region.
Hackers sent phishing emails to Japanese hotels partnered with Booking.com in May, distributing malware hosted on blockchain networks. The campaign targeted accommodation partners through credential-stealing phishing, enabling unauthorized access to booking accounts and guest data.
The FBI warns that Russian intelligence actors are conducting phishing campaigns to steal Signal backup encryption keys. This targets users' end-to-end encrypted communications. Email security professionals should monitor for phishing emails luring users to compromise their encrypted messaging credentials.
A serverless phishing kit named GitBait exploits GitHub Pages and SheetBest API to target Mexican banks and steal credentials. The kit leverages hosting and data aggregation services to facilitate credential theft at scale.
Interpol dismantled SniperDz, a decade-old phishing-as-a-service platform exposed by Group-IB. The operation provided phishing infrastructure to cybercriminals targeting organizations globally. This takedown is significant for email security professionals as it disrupts a major phishing distribution network.
Menlo Security research reveals that traditional cybersecurity tools fail to detect 20% of browser-based phishing attacks, leaving enterprises vulnerable as applications shift to browser-based platforms.
Attackers are exploiting ChatGPT's shared content feature to deliver malware in phishing campaigns. Threat actors use the chatgpt.com/s/ domain to host malicious files, leveraging the trusted platform to bypass security controls. This poses a risk to organizations relying on email-based threat detection.
Group-IB discovered 4,300 fake FIFA World Cup domains and a phishing campaign called Ghost Stadium targeting fans during the World Cup. These fraudulent domains impersonate legitimate FIFA services to harvest credentials and personal data from victims.
Chinese threat actors are evolving phishing tactics by replacing static pages with live credential interception systems. They primarily target non-Chinese organizations, indicating deliberate avoidance of domestic targets to minimize political risk.