Phishing

Other conventional threat types

Showing 21–24 of 24 threats, newest first

vishingteams-abusesocial-engineeringinitial-accessratremote-access-trojanhelp-desk-impersonationagent-relevant

Threat actors are impersonating corporate IT support staff over Microsoft Teams voice calls to socially engineer employees into installing the EtherRAT remote access trojan. Once installed, the malware grants attackers initial access to corporate networks, potentially enabling lateral movement, credential theft, and further compromise. This campaign leverages trust in internal communication tools rather than exploiting a software vulnerability.

Updated Jul 7, 2026

phishingcredential-theftbrand-impersonationgoogle-accountssocial-engineeringrecruitment-scam

A large-scale phishing campaign impersonates over 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, using fake job interview lures to steal Google account credentials from marketing professionals. The attackers leverage trusted brand names and recruitment pretexts to bypass victim skepticism and harvest credentials likely for account takeover, further phishing, or resale.

Updated Jul 7, 2026

phishing-as-a-serviceMicrosoft 365credential-theftsession-token-theftAiTMagent-relevant

ARToken is a newly identified phishing-as-a-service (PhaaS) platform operating as an affiliate of the EvilTokens phishing ecosystem, offering attackers a turnkey toolkit to compromise Microsoft 365 accounts. The platform enables adversary-in-the-middle (AiTM) style credential and session token theft at scale, lowering the barrier to entry for large-scale enterprise account compromise.

Updated Jul 5, 2026

Social EngineeringIdentityMFA Bypass

English-speaking group using SIM-swapping and MFA fatigue attacks to compromise enterprise identity providers via IT help desk impersonation calls.

Updated Jul 3, 2026