Related Threat Clusters
-
Phishing Campaign Targets Japanese Hotels with Multi-Stage Malware
A phishing campaign impersonating Booking.com has targeted hotel operators in Japan, utilizing emails with malicious attachments. The attack employs a multi-stage malware process involving a ZIP archive containing a…
2 articles · Updated June 12, 2026 -
Targeted AWS Phishing Campaign Captures Credentials and MFA Codes
A sophisticated phishing campaign targeting Amazon Web Services (AWS) users has emerged, utilizing cloned login pages to capture credentials and multifactor authentication (MFA) codes in real-time. The attackers have…
4 articles · Updated June 25, 2026 -
Scattered Spider Reclassified as Decentralized Cybercrime Collective
Scattered Spider, a cybercrime entity linked to various high-profile attacks since 2022, has been reclassified as a decentralized collective rather than a unified group. Group-IB's analysis indicates that it consists of…
2 articles · Updated July 7, 2026 -
ZeroTokens Phishing Platform Enables Real-Time Attacks on Financial Institutions
The ZeroTokens phishing platform has been identified as a sophisticated tool enabling real-time phishing attacks against financial institutions. Attackers can monitor victims' sessions and adapt prompts based on the…
2 articles · Updated August 25, 2026 -
Identity-Based Attacks Target Authentication Systems and Credentials
Recent identity-based attacks have exploited vulnerabilities in authentication systems, targeting credentials and identity infrastructure. Notable incidents include the compromise of over 18,000 routers by APT28 to…
62 articles · Updated May 29, 2026 -
Phishing Campaign Exploits ICE Messaging to Steal Credentials
A phishing campaign is targeting users of email marketing platforms by sending messages that include a fake 'Support ICE' button. This tactic aims to create panic and urgency, tricking recipients into revealing…
4 articles · Updated March 6, 2026 -
Scammers Exploit Microsoft Email System for Phishing Attacks
Cybercriminals have discovered a method to exploit Microsoft's internal email system, specifically the [email protected] address, to send phishing emails that appear legitimate. This vulnerability…
8 articles · Updated May 21, 2026 -
Exposed API Credentials Found on Thousands of Websites
A study analyzing 10 million websites has uncovered nearly 2,000 exposed API credentials across 10,000 webpages. Researchers from Stanford, led by Nurullah Demir, utilized the tool TruffleHog to identify 1,748 valid…
2 articles · Updated March 27, 2026 -
AI-Driven Email Fraud Threatens Banks in Australia and India
Proofpoint's analysis reveals that a significant number of banks in Australia and major companies in India are not enforcing the strongest DMARC email authentication protocols, leaving them vulnerable to AI-enhanced…
9 articles · Updated July 1, 2026 -
Huntress Warns of Vishing Scams Targeting Individuals and Families
Huntress reported a vishing scam where attackers impersonated the U.K. tax authority, exploiting urgency and identity-theft fears to extract sensitive information from victims. The firm emphasized that the attack relied…
3 articles · Updated June 6, 2026
Recent Intelligence Reports
- Zerotokens Real Time Phishing Platform — abnormal.ai · August 25, 2026
- ZeroTokens Phishing Platform Steers Attacks in Real Time — Infosecurity-Magazine · August 25, 2026
- How Aitm Phishing Bypassed Mfa To Hijack A Microsoft 365 Mailbox In Bec Scheme — www.trendaisecurity.com · August 20, 2026
- Connecting Scattered Spider — www.group-ib.com · July 8, 2026
- Hotel Phishing Clears All Email Security Filters: Microsoft Names New Attack Class — Travelerstoday · June 27, 2026
- Hotel Phishing Attack Uses Calendly to Bypass Email Authentication Filters — Techtimes · June 26, 2026
- Fake AWS pages bypass MFA and put cloud credentials in cybercriminals' hands — Escudodigital · June 26, 2026
- Analysis of Suspicious Emails Targeting the Hotel Industry — Socprime · June 12, 2026