Advertisement
Spring Ring Voice Phishing Targets Microsoft Teams Users
Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.
ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO
ReliaQuest confirms a social engineering attack by ShinyHunters targeting an employee's Okta SSO, blocked from accessing applications or customer data.
UNC6671 Targets Financial Sector via Vishing and AiTM Phishing
UNC6671, linked to BlackFile, exploits vishing and AiTM phishing against financial firms for cloud data theft and extortion.
Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk
A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.
Silent Ransom Group Targets US Law Firms via Vishing and Intrusions
Silent Ransom Group (Luna Moth) targets US law firms using vishing and physical intrusions for data extortion. Technical analysis and mitigation strategies.
UNC3753: Vishing and Physical Intrusions Fuel U.S. Data Extortion
Mandiant identifies UNC3753 targeting U.S. legal and financial sectors through sophisticated vishing and physical breaches to execute data theft extortion.
Advertisement
UNC3753 Targets US Law Firms with Vishing & Physical Intrusions
UNC3753 (Luna Moth) leverages vishing and physical office intrusions to steal sensitive data from US law firms and professional services, leading to swift extortion.
Google Android Scam Detection: Real-Time AI Defense Against Fraud
Google introduces AI-powered Scam Detection for Android, utilizing on-device Gemini Nano to identify fraud patterns and protect users from voice-based phishing.
BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion
Examines UNC6671's BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 & Okta. Actionable mitigations included.
Cordial Spider and Snarky Spider: Rapid SaaS Extortion via Vishing
Researchers identify Cordial Spider and Snarky Spider using vishing and SSO abuse to execute high-speed data theft within corporate SaaS environments.
Fake IT Support Campaigns Deploy Customized Havoc C2 Payloads
Huntress identifies a new campaign using fake IT support lures and vishing to deploy Havoc C2 for data exfiltration and ransomware delivery.
SLH Recruits Women for $1,000 IT Help Desk Vishing Attacks
Scattered LAPSUS$ Hunters (SLH) are offering financial incentives to recruit women for vishing campaigns targeting corporate IT help desks and IAM systems.