Advertisement
Phishing Campaign Leverages Invisible Unicode to Bypass Filters
A high-volume phishing campaign uses invisible Unicode tag characters to evade email security filters, mimicking financial lures for fraud and credential harvesting.
ClickFix Ecosystem: Evasive Attack-as-a-Service & YARA Detection
The ClickFix ecosystem offers rented, evasive attack vectors bypassing AV/EDR. Learn why YARA analysis is crucial for detecting this scalable threat.
Stealthy Phishing Abuses ConnectWise ScreenConnect, AnyDesk RMM
Attackers leverage legitimate RMM tools like ConnectWise ScreenConnect and AnyDesk in a sophisticated phishing campaign, impacting over 80 organizations and evading…
Detect Obfuscated JavaScript Phishing Delivered via RAR Archives
Security researchers identify a new phishing campaign using heavily obfuscated JavaScript within RAR archives to bypass traditional endpoint detection.
Emoji-Based C2: Threat Actors Adopt Covert Communication Tactics
Threat actors are increasingly using emojis for covert Command and Control communications to evade security filters. Learn how to detect these obfuscated TTPs.
DeepLoad Malware Leverages AI for Evasion and Credential Theft
DeepLoad, an AI-powered malware, uses massive junk code to evade detection while stealing credentials. Learn its TTPs and mitigation strategies.
Advertisement
ClickFix Attack: Windows Terminal Used for Detection Evasion
The ClickFix attack leverages fake CAPTCHA pages to trick users into pasting malicious commands into Windows Terminal, bypassing traditional detection methods.
Abusing .arpa DNS and IPv6 to Bypass Phishing Defenses
Threat actors exploit .arpa domains and IPv6 reverse DNS for phishing evasion, bypassing email security gateways and domain reputation checks.