Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
TerminalFix is a new ClickFix campaign that tricks users into running PowerShell commands and turns infected Windows PCs into network pivots.
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into ...
PavinLoader uses fake CAPTCHAs, game installers, and software downloads to deliver malware and steal passwords, browser data, ...
SOCRadar details E4del and PINHOLE RAT campaigns using FTP banners as dead drop resolvers to fetch commands and C2 details.
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other ...
SynkLoader malware is spreading through Microsoft Teams phishing, using a fake Windows lock screen to steal credentials and enable remote access.
Cybersecurity researchers have identified an unusual malware campaign in which attackers are abusing FTP server banners to hide commands used to deliver two previously undocumented Windows remote ...
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal ...
Microsoft has released new PowerShell scripts that give IT administrators an easier way to view, export, and delete Windows ...