Category: Phishing Attacks


  • Bluekit Phishing Kit Adds Browser-in-the-Middle Attacks to Steal Accounts

    The Bluekit phishing kit has received a significant upgrade that allows cybercriminals to steal authenticated user sessions more effectively. Security researchers have discovered that the phishing-as-a-service (PhaaS) platform now supports browser-in-the-middle (BitM) attacks, replacing its previous interception technique with a more advanced method for compromising online accounts. The latest version also introduces additional evasion capabilities,…

  • WhatsApp Phishing Attack Uses Fake Documents to Deploy RAT

    A WhatsApp phishing attack is targeting businesses with fake document requests that lead to malware infections. Researchers say attackers are posing as business contacts and sending messages that appear to contain legitimate files. Instead of delivering invoices or contracts, the campaign installs ConnectWise RAT, a remote access tool that allows attackers to take control of…

  • World Cup Scams Exploit Fans With Fake Streaming Sites

    Football fans searching for free World Cup coverage are facing a growing wave of online threats. Security researchers have uncovered more than 40 websites posing as free streaming platforms for the 2026 FIFA World Cup. While these sites promise live access to matches, many serve a different purpose entirely. Instead of delivering reliable streams, the…

  • AI Phishing Service Disrupted in Major FBI Takedown

    An AI phishing service disrupted by U.S. authorities has exposed the growing role of artificial intelligence in cybercrime. The FBI, working alongside Google and security researchers, helped dismantle a large-scale phishing operation known as Outsider. Investigators linked the service to more than one million malicious URLs designed to steal credentials and payment card information from…

  • WhatsApp Phishing Attacks Linked to NSO Group Disrupted

    Meta says it has disrupted a new campaign of WhatsApp phishing attacks linked to spyware vendor NSO Group. The company claims the activity violated a court order that permanently prohibited NSO from targeting WhatsApp users after a lengthy legal battle over the deployment of Pegasus spyware. The latest discovery suggests that efforts to target WhatsApp…

  • Polyfill Phishing Attack Injects Fake Logins Into Trusted Sites

    Visitors to several well-known websites recently faced an unexpected threat when fake Microsoft login prompts began appearing on pages associated with trusted brands. Security researchers traced the activity to a Polyfill-related compromise that allowed attackers to inject phishing content into legitimate websites, including pages connected to Toshiba and Muji. The incident demonstrates how cybercriminals continue…

  • Hotel Phishing Attacks Follow Major European Data Breach

    Cybercriminals are targeting hotel guests with convincing payment scams after a data breach affected more than 100 hotels across Europe. The incident exposed reservation information belonging to travelers staying at properties in the Netherlands, Belgium, and Ireland. Attackers are now using the stolen data to send phishing messages that appear to come from legitimate hotels,…

  • BTMOB Malware Generates Custom Android Phishing Payloads

    Security researchers have uncovered a malware-as-a-service platform called BTMOB malware that allows cybercriminals to generate custom Android phishing payloads with minimal technical knowledge. The service gives attackers tools to create malicious Android applications, manage phishing campaigns, and remotely control infected devices. Researchers warned that the platform lowers the barrier for cybercriminals looking to target Android…

  • Kali365 Phishing Kit Bypasses Microsoft 365 MFA

    The FBI warned that cybercriminals are increasingly using the Kali365 phishing kit to hijack Microsoft 365 accounts while bypassing multi-factor authentication protections. According to investigators, Kali365 operates as a phishing-as-a-service platform distributed through Telegram channels and underground cybercrime communities. Instead of stealing passwords directly, the toolkit focuses on stealing OAuth access tokens and authenticated sessions.…

  • Tycoon2FA Phishing Hijacks Microsoft 365 Accounts

    The Tycoon2FA phishing platform has resurfaced with a new attack method designed to hijack Microsoft 365 accounts through device-code phishing. Researchers warn that the updated campaign allows attackers to gain account access without directly stealing passwords, making the attacks more difficult to detect and block. Tycoon2FA already gained attention for bypassing multi-factor authentication through adversary-in-the-middle…