#phishing-as-a-service

[ follow ]
Information security
fromThe Hacker News
6 days ago

Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar

Sneaky 2FA PhaaS now uses Browser-in-the-Browser (BitB) to present fake Microsoft login pop-ups, enabling large-scale credential theft and account takeover.
#phishing
fromAxios
1 week ago
Information security

Google targets China-based scam operators sending Americans' toll fraud texts

fromThe Verge
1 week ago
Information security

Google is trying to take down a group sending you all those spammy texts

fromAxios
1 week ago
Information security

Google targets China-based scam operators sending Americans' toll fraud texts

fromThe Verge
1 week ago
Information security

Google is trying to take down a group sending you all those spammy texts

fromTheregister
1 week ago

Google sues 25 China-based scammers behind phishing kit

Lighthouse is a phishing software service described in the lawsuit [PDF] as a "phishing for dummies" kit. Criminals pay a monthly subscription fee for access to hundreds of templates for fake websites, domain set-up tools for those phony sites, and other features designed to dupe victims into believing they are visiting a legitimate website. The crims use these sites to trick victims into entering their financial info and other sensitive details, which the crooks then steal.
Information security
#smishing
Information security
fromIT Pro
1 month ago

Hackers are using a new phishing kit to steal Microsoft 365 credentials and MFA tokens - Whisper 2FA is evolving rapidly and has been used in nearly one million attacks since July

Whisper 2FA is a PhaaS tool that steals credentials and MFA tokens from Microsoft 365 accounts while evading detection through advanced obfuscation.
#raccoono365
Information security
fromSecurityWeek
2 months ago

RaccoonO365 Phishing Service Disrupted, Leader Identified

Microsoft and Cloudflare disrupted RaccoonO365, a phishing-as-a-service that stole thousands of Microsoft 365 credentials and targeted healthcare, prompting legal and technical takedowns.
fromTheregister
2 months ago

Google, Microsoft account takeover made easy via VoidProxy

The phishes target any Google and Microsoft accounts, from small businesses to large enterprises, we're told. And while Okta didn't have a confirmed victim count, "we have observed high-confidence account takeovers in multiple entities," the threat intel team told us. "By extension, we expect Microsoft and Google will have observed a larger number of ATO events, given that VoidProxy proxies non-federated users directly with Microsoft and Google servers."
Information security
Information security
fromThe Hacker News
2 months ago

Watch Out for Salty2FA: New Phishing Kit Targeting US and EU Enterprises

Salty2FA is a PhaaS phishing kit that bypasses push, SMS, and voice 2FA to intercept credentials and codes, enabling high-impact account takeovers across industries.
#cybersecurity
fromTechzine Global
6 months ago
Privacy technologies

Cybercriminals are circumventing multi-factor authentication

MFA is becoming less effective against sophisticated attacks, requiring a reassessment of organizational security strategies.
fromITProUK
7 months ago
Privacy professionals

'Phishing kits are a force multiplier': Cheap cyber crime kits can be bought on the dark web for less than $25 - and experts warn it's lowering the barrier of entry for amateur hackers

The cost of launching phishing attacks is decreasing, making it easier for criminals with minimal skills to execute cyber crimes.
Privacy professionals
fromITProUK
7 months ago

'Phishing kits are a force multiplier': Cheap cyber crime kits can be bought on the dark web for less than $25 - and experts warn it's lowering the barrier of entry for amateur hackers

The cost of launching phishing attacks is decreasing, making it easier for criminals with minimal skills to execute cyber crimes.
[ Load more ]