Gbhackers Phishing Campaign Exploits LiveChat for Data Theft
Article Content
- •Attackers are using LiveChat to conduct real-time phishing attacks.
- •Victims are coerced into providing sensitive information through impersonation of trusted brands.
- •The campaign demonstrates an evolution in phishing tactics, making detection more challenging.
A new phishing campaign has been identified that exploits LiveChat to steal sensitive user data by impersonating trusted brands like PayPal and Amazon. Attackers engage victims through real-time chat interactions, coercing them into providing account credentials, credit card details, and other personally identifiable information (PII). The campaign utilizes psychological tactics such as urgency and brand impersonation, with two main attack vectors: one offering a fake refund from PayPal and another prompting users about a pending order. Cofense's Phishing Defense Center discovered this scheme, highlighting the evolution of phishing tactics that make these threats harder to detect. The attackers employ poor grammar and punctuation, indicating a human operator rather than an automated system. This method represents a shift from traditional phishing techniques that typically rely on fake login pages. The campaign is ongoing, with no specific numbers on affected users reported yet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…