Skip to main content
← All Articles

Tag

#Social Engineering

170 articles

Advertisement

HIGH
Threat Intel

UNC6783 Leverages BPOs to Steal Corporate Zendesk Tickets

New threat actor UNC6783 targets Business Process Outsourcing (BPO) providers to gain access to client Zendesk support tickets, risking sensitive data.

Runtime Rebel Intel
4 min read · Apr 9, 2026
Axios Attack: Industrialized Social Engineering on NPM Maintainers
HIGH
Supply Chain

Axios Attack: Industrialized Social Engineering on NPM Maintainers

An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.

Runtime Rebel Intel
4 min read · Apr 7, 2026
MEDIUM
Threat Intel

Analyzing the Frequency of Open Redirects in Phishing Campaigns

Examine the technical drivers behind the use of open redirects in phishing delivery and learn strategies for detection and vulnerability remediation.

Runtime Rebel Intel
3 min read · Apr 6, 2026
HIGH
Supply Chain

North Korean Social Engineering Targets Node.js Maintainers

North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.

Runtime Rebel Intel
3 min read · Apr 6, 2026
DPRK Social Engineering Behind $285 Million Drift Hack: Analysis
HIGH
Threat Intel

DPRK Social Engineering Behind $285 Million Drift Hack: Analysis

A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.

Runtime Rebel Intel
3 min read · Apr 5, 2026
HIGH
Supply Chain

Axios npm Hijack Attempt: Detecting Social Engineering Tactics

North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.

Runtime Rebel Intel
3 min read · Apr 5, 2026

Advertisement

UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise
HIGH
Supply Chain

UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise

Runtime Rebel details how North Korean threat actor UNC1069 leveraged targeted social engineering against an Axios npm package maintainer, leading to a critical supply…

Runtime Rebel Intel
4 min read · Apr 3, 2026
Drift Protocol Hacked for $285M via Durable Nonce Attack
HIGH
Data Breach

Drift Protocol Hacked for $285M via Durable Nonce Attack

Solana-based DEX Drift Protocol lost $285 million due to a social engineering and durable nonce attack, leading to Security Council takeover.

Runtime Rebel Intel
4 min read · Apr 3, 2026
Venom Stealer MaaS: Commoditizing Information Theft via ClickFix Attacks
HIGH
Malware

Venom Stealer MaaS: Commoditizing Information Theft via ClickFix Attacks

Analyze Venom Stealer MaaS, a new cybercrime platform enabling automated, persistent information-stealing through social engineering 'ClickFix' attacks.

Runtime Rebel Intel
4 min read · Apr 1, 2026
HIGH
Threat Intel

Routine Access Powers Intrusions: VPNs & RMM Tools Abused

Blackpoint Cyber's report reveals modern intrusions leverage routine access via compromised credentials, VPN abuse, RMM tools, and social engineering, not exploits.

Runtime Rebel Intel
5 min read · Apr 1, 2026
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
HIGH
Malware

DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft

DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.

Runtime Rebel Intel
5 min read · Mar 30, 2026
MEDIUM
Threat Intel

macOS Terminal ClickFix Protections: Blocking Malicious Shell Commands

Apple introduces Terminal warnings in macOS Sequoia 15.2 to combat ClickFix social engineering attacks that trick users into executing malicious shell scripts.

Runtime Rebel Intel
3 min read · Mar 30, 2026
HIGH
Malware

Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads

Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.

Runtime Rebel Intel
3 min read · Mar 28, 2026
HIGH
Threat Intel

ClickFix Social Engineering Drops Infiniti Stealer on macOS

Attackers use fake Cloudflare CAPTCHA pages and ClickFix tactics to deliver the Python-based Infiniti Stealer to macOS systems via terminal commands.

Runtime Rebel Intel
4 min read · Mar 28, 2026
MEDIUM
Threat Intel

Palo Alto Networks Recruiter Scam and Quantum Security Outlook

Threat actors are impersonating Palo Alto Networks recruiters to target security professionals, while Google sets a 2029 deadline for quantum computing.

Runtime Rebel Intel
3 min read · Mar 27, 2026
Palo Alto Networks Recruitment Fraud: Analysis of Phishing Tactics
MEDIUM
Threat Intel

Palo Alto Networks Recruitment Fraud: Analysis of Phishing Tactics

Phishing campaigns posing as Palo Alto Networks recruiters leverage LinkedIn data and psychological tactics to defraud job seekers in the security industry.

Runtime Rebel Intel
4 min read · Mar 25, 2026
ClickFix Social Engineering Clusters Target Windows and macOS Systems
MEDIUM
Threat Intel

ClickFix Social Engineering Clusters Target Windows and macOS Systems

Insikt Group identifies five ClickFix clusters using obfuscated commands to exploit native system tools via fake browser error overlays on Windows and macOS.

Runtime Rebel Intel
4 min read · Mar 25, 2026
Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys
HIGH
Threat Intel

Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys

Phishing campaign targets healthcare and government sectors with copyright infringement decoys to deliver Lumma Stealer via legitimate cloud services.

Runtime Rebel Intel
4 min read · Mar 23, 2026
MEDIUM
Threat Intel

Azure Monitor Alert Abuse: Detecting Callback Phishing Campaigns

Threat actors are abusing Microsoft Azure Monitor Action Groups to send legitimate-looking callback phishing emails to bypass traditional security filters.

Runtime Rebel Intel
4 min read · Mar 21, 2026
HIGH
Threat Intel

Russian Intelligence Phishing Targets Signal and WhatsApp Users

The FBI warns of sophisticated phishing campaigns by Russian intelligence targeting Signal and WhatsApp users to harvest credentials and bypass encryption.

Runtime Rebel Intel
4 min read · Mar 21, 2026
MEDIUM
Threat Intel

Professional Refund Fraud Economy Targets Major E-Commerce Retailers

An analysis of the professional refund-as-a-service economy, detailing TTPs used by fraudsters to exploit retailer return policies and payment platforms.

Runtime Rebel Intel
3 min read · Mar 18, 2026
Credential Theft Surge: Understanding Infostealer & AI Social Engineering
HIGH
Identity & Access

Credential Theft Surge: Understanding Infostealer & AI Social Engineering

Credential theft surged in late 2025, driven by sophisticated infostealer malware and AI-enhanced social engineering.

Runtime Rebel Intel
4 min read · Mar 18, 2026
7-Stage Phishing Chain Targets Outpost24 C-Suite via Redirects
MEDIUM
Threat Intel

7-Stage Phishing Chain Targets Outpost24 C-Suite via Redirects

Security researchers identify a sophisticated 7-stage phishing attack targeting Outpost24 executives using legitimate domains to evade email gateways.

Runtime Rebel Intel
4 min read · Mar 17, 2026
LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis
MEDIUM
Malware

LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis

LeakNet ransomware leverages ClickFix social engineering and Deno-based in-memory loaders to bypass traditional security controls and deploy payloads.

Runtime Rebel Intel
4 min read · Mar 17, 2026