Phishing

Credential-theft campaigns, phishing-as-a-service kits, OAuth consent phishing, and adversary-in-the-middle techniques that bypass MFA.

Other conventional threat types

Showing 1–20 of 24 threats, newest first

phishingoauth-abusecredential-theftsocial-engineeringaccount-takeoversupply-chainagent-relevant

This roundup aggregates multiple ongoing threat campaigns including CEO/executive impersonation phishing kits, a mass compromise affecting roughly 5,000 Dropbox accounts, and OAuth consent-phishing traps that trick users into granting malicious apps access via legitimate-looking 'Allow' prompts. The common thread is abuse of trust in normal workflows—IT calls, shared files, and trusted apps—rather than technical exploitation, making these attacks highly effective and hard to detect through traditional security controls.

Updated Sep 4, 2026

phishingremote-access-toolliving-off-the-landinitial-accessscreenconnectendpoint-management-abuseagent-relevant

Threat actors are abusing the legitimate Faronics Deploy endpoint-management platform, likely delivered via phishing, to gain remote administrative control over victim machines. Once access is obtained, attackers use the platform's legitimate deployment capabilities to install ScreenConnect, a remote support tool commonly repurposed by attackers for persistence and lateral movement.

Updated Sep 2, 2026

AitMphishing-as-a-servicesession-hijackingMicrosoft365Docusign-abusecredential-theftagent-relevant

A subscription-based adversary-in-the-middle phishing toolkit called NovaCookies is being used to abuse legitimate Docusign notification emails to lure victims into fraudulent Microsoft 365 login flows. The service acts as a reverse proxy that captures authenticated session cookies, allowing attackers to bypass MFA and hijack active Microsoft 365 sessions for $320/month.

Updated Aug 27, 2026

npmphishingsupply-chainfake-captchacloudflare-impersonationagent-relevant

Threat actors are abusing npm and its mirror services to host malicious HTML pages that impersonate Cloudflare CAPTCHA verification screens. Visitors who interact with these fake pages are redirected to attacker-controlled sites, likely for further phishing, malware delivery, or credential theft. The abuse leverages the inherent trust and reachability of npm's infrastructure to evade detection and blocklisting.

Updated Aug 26, 2026

malwarephishingcredential-theftmicrosoft-teamsloadersocial-engineering

A new malware loader named SynkLoader is being distributed through Microsoft Teams phishing campaigns, using a fake lock screen overlay to harvest user credentials. The campaign leverages the trust employees place in Teams notifications and internal communication tools to deliver the loader and steal login credentials.

Updated Aug 22, 2026

phishingai-generated-contentmspemail-securityidentity-securitysocial-engineering

This is a vendor advisory (Kaseya via BleepingComputer) describing how AI is making phishing emails more personalized and convincing, allowing them to bypass traditional email filters. It recommends MSPs adopt layered monitoring across identity, email, and endpoint activity to catch attacks that reach user inboxes.

Updated Aug 21, 2026

vishingsocial-engineeringsaasdata-extortioncredential-thefthelp-desk-impersonationagent-relevant

UNC6671 is a data extortion group conducting voice phishing attacks against financial services, private equity, and professional services firms. The group impersonates IT help desk staff and contacts employees via personal phones to coerce urgent 'security migration' actions that grant attackers access to SaaS environments and enterprise data.

Updated Aug 8, 2026

social-engineeringdata-breachcorporate-espionageemployee-targetingcredential-theft

Levi Strauss & Co. disclosed that attackers used social engineering tactics against three employees to gain unauthorized access to corporate data stored on their machines. The incident resulted in the theft of corporate information, though full scope of the compromised data has not been publicly detailed. This represents a targeted human-layer attack rather than a technical exploit of infrastructure.

Updated Aug 8, 2026

social-engineeringrmm-abusescreenconnectfake-updatesinitial-accessagent-relevant

Securonix Threat Labs identified an active, multi-wave social engineering campaign dubbed SMOKE#SCREEN that uses fake Adobe and Zoom update prompts, fraudulent document review notices, and system maintenance lures to trick victims into installing ConnectWise ScreenConnect. Once installed, the legitimate RMM tool grants attackers persistent, stealthy remote access to compromised endpoints, bypassing many traditional malware detection controls due to ScreenConnect's legitimate code signing.

Updated Aug 5, 2026

phishing-as-a-serviceMFA-bypassdevice-code-phishingOAuth-abuseAiTMtoken-theftcredential-theftagent-relevant

The Greatness PhaaS platform has added device code phishing capabilities, allowing attackers to abuse the legitimate OAuth 2.0 Device Authorization Grant flow to bypass MFA and hijack user sessions via stolen tokens. Combined with its existing adversary-in-the-middle (AiTM) credential phishing, this significantly lowers the barrier for attackers to compromise MFA-protected accounts at scale.

Updated Aug 5, 2026

phishingPhaaSMicrosoft 365adversary-in-the-middledevice-code phishingcredential theftbusiness-email-compromiseagent-relevant

The Greatness phishing-as-a-service platform has evolved from basic credential phishing to adversary-in-the-middle (AiTM) and device-code phishing techniques, now spoofing RingCentral notifications to target Microsoft 365 accounts. This expansion enables attackers to bypass MFA protections and steal session tokens, significantly increasing the risk of successful account takeovers across organizations using Microsoft 365.

Updated Aug 5, 2026

phishingcredential-theftreal-time-hijackingsession-hijackinginsurance-sectorfinancial-fraudsocial-engineeringadversary-in-the-middle

CTM360 researchers identified a shift in insurance-sector phishing campaigns from traditional credential harvesting to real-time account hijacking, where stolen credentials and session tokens are used immediately to take over accounts before victims can react. This evolution suggests attackers are increasingly leveraging automated relay infrastructure or adversary-in-the-middle (AiTM) techniques to bypass MFA and act on stolen sessions within seconds of capture.

Updated Jul 27, 2026

sextortiondata-breachextortionemail-scamShinyHunterssocial-engineering

Threat actors are leveraging email addresses and personal data leaked by the ShinyHunters extortion group to send mass sextortion emails demanding $2,000 in Bitcoin. The scam uses previously breached data to add false credibility, threatening victims with fake claims of compromising webcam footage or browsing history unless payment is made.

Updated Jul 26, 2026

BlueNoroffNorth-KoreaAPTClickFixcrypto-theftsocial-engineeringtyposquattingwallet-draineragent-relevant

BlueNoroff, a North Korean state-sponsored threat actor, is operating an active phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains and ClickFix-style social engineering lures. The campaign profiles victims' cryptocurrency wallets before delivering malware, combining compromised industry contacts and trust abuse to maximize infection success.

Updated Jul 25, 2026

DNS hijackingcredential theftMicrosoft 365phishinghospitalitytravel-securitycaptive-portal-abuseagent-relevant

Threat actors are compromising DNS settings on hotel and conference center Wi-Fi routers/gateways to silently redirect guests to convincing fake Microsoft 365 login pages. Victims who enter credentials on these spoofed portals have their Microsoft 365 accounts stolen, potentially exposing corporate email, files, and connected services. The campaign leverages trust in hotel network infrastructure and captive portal flows to bypass user suspicion.

Updated Jul 25, 2026

phishing-as-a-servicelaw-enforcement-takedowncredential-theftPhaaSinfrastructure-disruption

German and U.S. authorities dismantled the central infrastructure of Kratos, a phishing-as-a-service platform used globally to conduct credential-theft campaigns, and arrested its developer in Indonesia. This disrupts a major toolkit used by lower-skilled threat actors to launch large-scale phishing operations against individuals and organizations.

Updated Jul 22, 2026

phishinginfostealerwebdavmalware-deliveryoperational-security-failureai-assisted-contentmexicowindows

Rapid7 researchers discovered an exposed, misconfigured delivery server belonging to a malware operator, revealing over 1,000 files including phishing lure templates, filename-spoofing tests, droppers, and builder notes. The toolkit was actively used in a campaign targeting Windows users in Mexico via a fake government ID-lookup site, delivering an infostealer through WebDAV. The exposure suggests use of AI-generated content in crafting lures, lowering the barrier for producing convincing localized phishing pages.

Updated Jul 21, 2026

BECbusiness-email-compromiseinvestment-fraudmoney-launderinglaw-enforcement-actionfinancial-crime

Spanish National Police dismantled a cybercrime and money-laundering network responsible for approximately €140 million ($160 million) in losses through investment fraud and business email compromise (BEC) schemes. Four suspects were arrested in connection with the operation, which targeted victims through social engineering and fraudulent financial transactions.

Updated Jul 15, 2026

vishingvoice-phishingdevice-code-phishingMFA-abuseSharePointdata-extortionidentity-attacksocial-engineeringcloud-securityagent-relevant

A newly identified data-extortion group called Helix is targeting organizations' SharePoint environments using identity-focused attack techniques, including voice phishing (vishing), device code phishing, and MFA abuse. The group's approach bypasses traditional malware-based detection by exploiting human trust and authentication weaknesses to gain access and exfiltrate sensitive data for extortion purposes.

Updated Jul 10, 2026

device-code-phishingmicrosoft-365oauth-abusecredential-theftbusiness-email-compromisesocial-engineeringagent-relevant

A phishing campaign dubbed DEBULL abuses Microsoft's legitimate device-code authentication flow to hijack Microsoft 365 accounts, using collaboration-themed lures rather than fake login pages. Because the attack leverages the real Microsoft login experience and obtains valid OAuth tokens, it bypasses many traditional phishing detections and can persist beyond password resets. The campaign was active between late June and early July 2026, as reported by ZeroBEC.

Updated Jul 8, 2026