abnormal.ai ATHR Platform Enables Scalable AI-Driven Vishing Attacks
Article Content
- •ATHR automates vishing attacks using AI agents and human operators.
- •The platform is sold for $4,000 plus a 10% profit share on underground forums.
- •ATHR enables attackers to bypass traditional email security with simple lure emails.
The ATHR cybercrime platform has emerged as a significant tool for executing automated voice phishing (vishing) attacks, utilizing AI agents and human operators to harvest credentials. Advertised on underground forums for $4,000 plus a 10% commission on profits, ATHR automates the entire telephone-oriented attack delivery (TOAD) process. Attackers send benign-looking emails containing only a phone number, prompting victims to call. Once connected, the AI agents guide victims through a scripted process designed to extract sensitive information, such as verification codes. The platform supports credential theft from multiple services, including Google, Microsoft, and Coinbase. ATHR's integration of various attack components allows even less technical criminals to conduct sophisticated phishing operations. Researchers have noted that ATHR's capabilities significantly reduce the manual effort required for such attacks. The platform's dashboard provides real-time monitoring and control over operations, enhancing its effectiveness.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…