Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 30 threats
Threat actors linked to ShinyHunters, Helix, and other extortion groups are conducting social engineering campaigns that abuse passkey and single sign-on registration flows to compromise corporate Microsoft 365 accounts. Stolen credentials and session data are used to exfiltrate sensitive organizational data for extortion purposes.
DoppelCart is a large-scale fraud operation leveraging over 119,000 fake e-commerce domains to trick consumers into entering payment card details on fraudulent storefronts. The scale of the infrastructure suggests automated domain generation and templated site deployment, enabling rapid scaling and takedown resilience. The primary impact is financial fraud and payment card data theft against consumers and, by extension, brands whose identities may be spoofed.
A threat cluster is targeting executives (directors, VPs, senior staff) at organizations using Microsoft 365 and other SaaS platforms through IT help desk vishing calls, adversary-in-the-middle (AitM) session token theft, and sign-ins routed through residential proxy networks to evade geolocation-based detection. Stolen credentials and session tokens are used for data exfiltration followed by extortion demands. The campaign leverages human trust in IT support workflows rather than software exploits, making it effective against organizations with strong technical controls but weaker identity-verification processes.
BigBear 2.0, a phishing-as-a-service (PhaaS) platform, has been used to compromise 258 organizations and steal over 5,000 Microsoft 365 credentials by bypassing multi-factor authentication via adversary-in-the-middle (AiTM) reverse-proxy techniques. The kit lowers the barrier to entry for large-scale credential phishing campaigns and has demonstrated broad reach across sectors relying on Microsoft 365 for identity and collaboration.
Threat actors are embedding invisible Unicode characters within phishing emails to conceal malicious lures and evade email security filters, a technique known as ASCII smuggling. This allows attackers to bypass keyword-based and pattern-matching detection systems while presenting deceptive content to human victims or automated parsers.
Microsoft identified a high-volume phishing campaign that embeds invisible Unicode tag characters within financial lure words (e.g., 'funding') to evade traditional email security filters. The technique splits keywords at the character level so pattern-matching and keyword-based detection engines fail to flag the malicious content, while the text still renders normally to human recipients.
This roundup aggregates multiple ongoing threat campaigns including CEO/executive impersonation phishing kits, a mass compromise affecting roughly 5,000 Dropbox accounts, and OAuth consent-phishing traps that trick users into granting malicious apps access via legitimate-looking 'Allow' prompts. The common thread is abuse of trust in normal workflows—IT calls, shared files, and trusted apps—rather than technical exploitation, making these attacks highly effective and hard to detect through traditional security controls.
Threat actors are abusing the legitimate Faronics Deploy endpoint-management platform, likely delivered via phishing, to gain remote administrative control over victim machines. Once access is obtained, attackers use the platform's legitimate deployment capabilities to install ScreenConnect, a remote support tool commonly repurposed by attackers for persistence and lateral movement.
A subscription-based adversary-in-the-middle phishing toolkit called NovaCookies is being used to abuse legitimate Docusign notification emails to lure victims into fraudulent Microsoft 365 login flows. The service acts as a reverse proxy that captures authenticated session cookies, allowing attackers to bypass MFA and hijack active Microsoft 365 sessions for $320/month.
Threat actors are abusing npm and its mirror services to host malicious HTML pages that impersonate Cloudflare CAPTCHA verification screens. Visitors who interact with these fake pages are redirected to attacker-controlled sites, likely for further phishing, malware delivery, or credential theft. The abuse leverages the inherent trust and reachability of npm's infrastructure to evade detection and blocklisting.
A new malware loader named SynkLoader is being distributed through Microsoft Teams phishing campaigns, using a fake lock screen overlay to harvest user credentials. The campaign leverages the trust employees place in Teams notifications and internal communication tools to deliver the loader and steal login credentials.
This is a vendor advisory (Kaseya via BleepingComputer) describing how AI is making phishing emails more personalized and convincing, allowing them to bypass traditional email filters. It recommends MSPs adopt layered monitoring across identity, email, and endpoint activity to catch attacks that reach user inboxes.
UNC6671 is a data extortion group conducting voice phishing attacks against financial services, private equity, and professional services firms. The group impersonates IT help desk staff and contacts employees via personal phones to coerce urgent 'security migration' actions that grant attackers access to SaaS environments and enterprise data.
Levi Strauss & Co. disclosed that attackers used social engineering tactics against three employees to gain unauthorized access to corporate data stored on their machines. The incident resulted in the theft of corporate information, though full scope of the compromised data has not been publicly detailed. This represents a targeted human-layer attack rather than a technical exploit of infrastructure.
Securonix Threat Labs identified an active, multi-wave social engineering campaign dubbed SMOKE#SCREEN that uses fake Adobe and Zoom update prompts, fraudulent document review notices, and system maintenance lures to trick victims into installing ConnectWise ScreenConnect. Once installed, the legitimate RMM tool grants attackers persistent, stealthy remote access to compromised endpoints, bypassing many traditional malware detection controls due to ScreenConnect's legitimate code signing.
The Greatness PhaaS platform has added device code phishing capabilities, allowing attackers to abuse the legitimate OAuth 2.0 Device Authorization Grant flow to bypass MFA and hijack user sessions via stolen tokens. Combined with its existing adversary-in-the-middle (AiTM) credential phishing, this significantly lowers the barrier for attackers to compromise MFA-protected accounts at scale.
The Greatness phishing-as-a-service platform has evolved from basic credential phishing to adversary-in-the-middle (AiTM) and device-code phishing techniques, now spoofing RingCentral notifications to target Microsoft 365 accounts. This expansion enables attackers to bypass MFA protections and steal session tokens, significantly increasing the risk of successful account takeovers across organizations using Microsoft 365.
CTM360 researchers identified a shift in insurance-sector phishing campaigns from traditional credential harvesting to real-time account hijacking, where stolen credentials and session tokens are used immediately to take over accounts before victims can react. This evolution suggests attackers are increasingly leveraging automated relay infrastructure or adversary-in-the-middle (AiTM) techniques to bypass MFA and act on stolen sessions within seconds of capture.
Threat actors are leveraging email addresses and personal data leaked by the ShinyHunters extortion group to send mass sextortion emails demanding $2,000 in Bitcoin. The scam uses previously breached data to add false credibility, threatening victims with fake claims of compromising webcam footage or browsing history unless payment is made.
BlueNoroff, a North Korean state-sponsored threat actor, is operating an active phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains and ClickFix-style social engineering lures. The campaign profiles victims' cryptocurrency wallets before delivering malware, combining compromised industry contacts and trust abuse to maximize infection success.