MailSecHub aggregates coverage of phishing campaigns, business email compromise, malware delivery, spoofing and email authentication (SPF, DKIM, DMARC) from top reputable sources. The pipeline polls every two hours, deduplicates and classifies each story by threat category — filter by source or topic to get to what is relevant to your environment.
A weekly briefing summarizes the most significant developments, and the same digest is delivered every Monday morning via the newsletter.
RATHat Android malware leverages Gemini AI to control infected phones while evading normal permission restrictions. Distributed via malicious ads and phishing SMS, it exploits Accessibility features to establish persistent command channels targeting users in Europe, Latin America, and Southeast Asia.
Sauron Loader malware targets German organizations via spam emails and fake IT support calls, delivering additional payloads. It uses DLL side-loading and in-memory decryption to evade detection, with some victims first encountering ClickFix-style fake prompts.
RatHat Android malware steals banking PINs and credentials through fake screens, persists after deletion, and spreads via SMS phishing and malicious ads. It targets banking customers with account takeover and payment fraud risks.
Attackers are exploiting ScreenConnect remote-access software to distribute worm-like malware across Windows networks via social engineering and phishing. Infected systems can spread payloads to connected machines without requiring individual phishing lures per victim, significantly expanding attack impact.
Cybercriminals disguise malware as a Google Gemini installer to distribute Vidar stealer, targeting saved browser passwords and credentials. The attack exploits routine software searches rather than email phishing, demonstrating credential-theft risks from trojanized downloads.
A misconfigured WebDAV server exposed a malware factory containing over 1,000 attack files, including phishing lures, droppers, and malware variants. The GenAI-powered operation targeted Windows users with fake documents and malicious shortcuts. The discovery reveals detailed insights into attacker infrastructure and malware development practices.
Attackers distribute malicious Windows shortcuts via spam emails disguised as booking confirmations. Clicking the LNK file triggers PowerShell and Node.js to install a backdoor, enabling remote code execution and further system compromise.