MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
28 articles from Infosecurity Magazine in Phishing
A serverless phishing kit named GitBait exploits GitHub Pages and SheetBest API to target Mexican banks and steal credentials. The kit leverages hosting and data aggregation services to facilitate credential theft at scale.
Interpol dismantled SniperDz, a decade-old phishing-as-a-service platform exposed by Group-IB. The operation provided phishing infrastructure to cybercriminals targeting organizations globally. This takedown is significant for email security professionals as it disrupts a major phishing distribution network.
Menlo Security research reveals that traditional cybersecurity tools fail to detect 20% of browser-based phishing attacks, leaving enterprises vulnerable as applications shift to browser-based platforms.
Attackers are exploiting ChatGPT's shared content feature to deliver malware in phishing campaigns. Threat actors use the chatgpt.com/s/ domain to host malicious files, leveraging the trusted platform to bypass security controls. This poses a risk to organizations relying on email-based threat detection.
Group-IB discovered 4,300 fake FIFA World Cup domains and a phishing campaign called Ghost Stadium targeting fans during the World Cup. These fraudulent domains impersonate legitimate FIFA services to harvest credentials and personal data from victims.
Chinese threat actors are evolving phishing tactics by replacing static pages with live credential interception systems. They primarily target non-Chinese organizations, indicating deliberate avoidance of domestic targets to minimize political risk.
BTMOB Android RAT is a remote access trojan distributed as a service with a no-code builder enabling rapid creation of region-specific phishing lures. The threat primarily targets Android devices through phishing campaigns. This affects email security professionals who must monitor phishing emails delivering Android malware payloads.
Iran-linked Nimbus Manticore launched phishing and SEO poisoning attacks targeting US aviation sector to distribute the AI-built MiniFast backdoor. Email-based phishing remains a key delivery vector for this advanced persistent threat against critical infrastructure.
The FBI warns of Kali365, a phishing-as-a-service platform that targets Microsoft 365 OAuth tokens, lowering barriers for cybercriminals. The attack directly compromises email and cloud accounts, making it a critical threat to defenders managing M365 environments.
Researchers detected a significant rise in phishing campaigns exploiting Vercel's platform to host malicious content. Attackers leverage Vercel's legitimate hosting service to bypass email security controls and increase campaign credibility. This trend highlights how threat actors abuse trusted infrastructure to improve phishing delivery and evasion.
Microsoft detected a large-scale phishing campaign using fake compliance emails to steal credentials from 35,000 users across 13,000 organizations globally. The attack demonstrates how threat actors abuse common organizational compliance processes to deceive targets into surrendering sensitive information.
Attackers impersonating the US Social Security Administration send phishing emails containing signed Remote Monitoring and Management software to establish persistent access on American networks. This Venomous#Helper campaign uses credential theft and RMM deployment for ongoing compromise.
BlueNoroff, a North Korean hacking group, targeted cryptocurrency firms with spear-phishing campaigns using ClickFix malware and AI-generated Zoom lures. The campaign demonstrates sophisticated social engineering techniques to deliver malware to financial sector targets.