Phishing

Cybersecurity
Jalisco and OmegaLord PhaaS Kits Beat M365 MFA Using OAuth Tricks
ReliaQuest disclosed Jalisco, which regenerates OAuth tokens in real time to beat Microsoft's 15-minute window, and OmegaLord, which harvests MFA phone numbers.
Cybersecurity
Open Server Exposes Three Concurrent Evilginx M365 Operations
French security firm Lexfo discovered three Evilginx M365 phishing campaigns after attackers left a Python HTTP server with directory listing exposed.
Cybersecurity
SCMBANKER Targets Mexican Banking With AI-Written PowerShell
Elastic Security Labs found REF6045 deploying SCMBANKER, an AI-written PowerShell toolkit that lets operators control Mexican banking sessions live and hijack transfers.
Cybersecurity
Helix Group Uses Vishing and Device Code Flow to Steal SharePoint Data
New threat group Helix chains vishing with Microsoft's OAuth Device Code Flow to harvest M365 tokens and exfiltrate SharePoint data for corporate extortion.
Cybersecurity
Forg365 PhaaS Combines AiTM and Device Code Flow to Target M365
Forg365 is a new phishing-as-a-service platform combining AiTM session hijacking and Device Code Flow abuse with AI-generated lures for mass targeting.
Cybersecurity
Operation DragonReturn: DcRAT Targets India Tax Professionals
China-nexus Operation DragonReturn deploys DcRAT via a cloned Indian tax utility, targeting tax professionals and accountants during India's filing season.
Cybersecurity
Unit 42 Exposes EtherRAT: Teams Calls Deliver Blockchain-Backed RAT
Unit 42 exposed an active campaign using fake Microsoft Teams IT support calls to install EtherRAT, a Node.js RAT whose C2 runs on Ethereum smart ...
Application Security
UNK_MassTraction Exploits Roundcube XSS to Hit US Physics Departments
Proofpoint named UNK_MassTraction, a China-aligned group using Roundcube CVE-2024-42009 to steal credentials and 2FA tokens from university physics departments.
Cybersecurity
Fake Job Interview Phishing Hits Marketing Pros Across 30 Brand Lures
Attackers posing as 30-plus major brand recruiters use fake job interviews to steal Google credentials from marketing professionals who manage ad platforms.
Cybersecurity
90-Domain SEO Campaign Abuses ScreenConnect to Deploy AsyncRAT
Kaspersky exposed a 90-domain SEO poisoning campaign that installs AsyncRAT on Windows via a fake ScreenConnect installer, targeting users across 10 languages.