<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>phishing &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/malicious-cyber-actors/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Wed, 15 Jul 2026 04:48:19 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.5</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>phishing &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Thousands of Phishing Domains Target Turkish Banks</title>
		<link>https://firsthackersnews.com/turkish-bank-phishing-campaign/</link>
					<comments>https://firsthackersnews.com/turkish-bank-phishing-campaign/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 04:47:55 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Banking]]></category>
		<category><![CDATA[Banking Security]]></category>
		<category><![CDATA[credential theft]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Online Banking]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Turkey]]></category>
		<category><![CDATA[Turkish Banks]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12024</guid>

					<description><![CDATA[<p>Cybercriminals are running a large-scale phishing campaign targeting Turkish banks through fake banking websites, fraudulent advertisements, and scam</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/turkish-bank-phishing-campaign/">Thousands of Phishing Domains Target Turkish Banks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Cybercriminals are running a large-scale phishing campaign targeting <strong>Turkish banks</strong> through fake banking websites, fraudulent advertisements, and scam loan offers. Researchers found more than <strong>8,400 phishing domains</strong> and over <strong>6,600 malicious advertisements</strong> on Facebook and Instagram designed to steal banking credentials and personal information.</p>



<p>The investigation also identified more than <strong>23,000 victim complaints</strong>, highlighting the scale of the operation and its impact on customers across Turkey.</p>



<h2 class="wp-block-heading"><strong>How the Campaign Works</strong></h2>



<p>Attackers use sponsored social media advertisements that impersonate legitimate banks and promote fake loan offers or financial services. Victims who click these ads are redirected to phishing websites that closely resemble official banking portals, where they are asked to enter login credentials, one-time passwords (OTPs), and other sensitive information.</p>



<p>Researchers found that the attackers frequently change their phishing infrastructure. Domains, advertisements, and hosting services are rotated regularly, sometimes within minutes, making it difficult for security teams to block the attacks before new ones appear.</p>



<p>The campaign also relies on a phishing toolkit sold through underground marketplaces. This toolkit allows cybercriminals to quickly create convincing phishing pages targeting multiple Turkish banks and government services, lowering the barrier for launching large-scale attacks.</p>



<h2 class="wp-block-heading"><strong>Recommendations for Banks and Customers</strong></h2>



<p>Financial institutions should strengthen their defenses by continuously monitoring for phishing domains, fake social media advertisements, cloned websites, and brand impersonation attempts.</p>



<p>Recommended security measures include:</p>



<ul class="wp-block-list">
<li>Monitor for newly registered phishing domains and fake banking websites.</li>



<li>Track fraudulent advertisements across social media platforms.</li>



<li>Detect and remove fake mobile apps and cloned banking portals.</li>



<li>Monitor suspicious account activity that may indicate money mule operations.</li>



<li>Accelerate takedown requests with domain registrars, hosting providers, and online platforms.</li>



<li>Educate customers about phishing and social engineering attacks.</li>
</ul>



<p>Customers can also reduce their risk by following these best practices:</p>



<ul class="wp-block-list">
<li>Access online banking only through official banking apps or trusted websites.</li>



<li>Avoid clicking banking links shared through advertisements, emails, or text messages.</li>



<li>Never share passwords, one-time passwords (OTPs), or banking credentials with anyone.</li>



<li>Verify loan offers and financial promotions directly with your bank before responding.</li>



<li>Report suspicious websites or advertisements to your bank immediately.</li>
</ul>



<p>This campaign demonstrates how cybercriminals are combining phishing websites, social media advertising, and financial fraud into highly organized operations. Staying vigilant, verifying banking communications, and maintaining strong security controls remain essential for protecting both financial institutions and their customers.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/turkish-bank-phishing-campaign/">Thousands of Phishing Domains Target Turkish Banks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/turkish-bank-phishing-campaign/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hackers Use GitHub Pages for Phishing Attacks</title>
		<link>https://firsthackersnews.com/github-pages-phishing/</link>
					<comments>https://firsthackersnews.com/github-pages-phishing/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 17 Jun 2026 21:51:09 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Banking Phishing]]></category>
		<category><![CDATA[credential theft]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[GitHub Pages]]></category>
		<category><![CDATA[Online Fraud]]></category>
		<category><![CDATA[Payment Card Theft]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[security research]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11877</guid>

					<description><![CDATA[<p>Researchers have uncovered a sophisticated phishing campaign targeting banking customers in Mexico through a highly scalable and resilient</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/github-pages-phishing/">Hackers Use GitHub Pages for Phishing Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Researchers have uncovered a sophisticated phishing campaign targeting banking customers in Mexico through a highly scalable and resilient attack infrastructure. The operation leverages GitHub Pages to host convincing phishing websites designed to steal login credentials, payment card information, and customer data.</p>



<p>Unlike traditional phishing operations that rely on a small number of malicious domains, this campaign uses a distributed network of GitHub Pages repositories. This approach allows attackers to quickly replace removed pages, maintain operational continuity, and reduce the effectiveness of takedown efforts.</p>



<p>Security researchers observed phishing pages impersonating multiple financial institutions, with customized interfaces optimized for both desktop and mobile users.</p>



<h2 class="wp-block-heading"><strong>Multi-Stage Infrastructure Designed for Scale</strong></h2>



<p>At the core of the campaign is a modular phishing kit that enables operators to generate institution-specific phishing pages with minimal effort. Victims are first directed to professionally crafted landing pages that closely mimic legitimate banking portals before being prompted to enter sensitive information.</p>



<p>The attack infrastructure uses client-side scripts to capture submitted data and transmit it to attacker-controlled platforms in real time. Rather than operating traditional command-and-control servers, the threat actors utilize third-party services to collect stolen information, reducing their infrastructure footprint and making detection more challenging.</p>



<p>Researchers also identified the use of obfuscated JavaScript loaded from external sources, allowing attackers to modify payloads and update functionality without altering the visible phishing pages. In some instances, stolen credentials were forwarded directly through Telegram, providing operators with immediate access to harvested data.</p>



<p>Evidence gathered from repository activity suggests the campaign has been actively maintained for more than a year, with continuous updates, infrastructure changes, and deployment improvements. The operation also utilizes automated deployment mechanisms and carefully crafted link previews to increase engagement across messaging and social media platforms.</p>



<h2 class="wp-block-heading"><strong>Abuse of Trusted Platforms Continues to Grow</strong></h2>



<p>The campaign highlights a growing trend in which threat actors abuse reputable cloud and hosting services to conduct phishing operations. By leveraging GitHub Pages, attackers benefit from trusted infrastructure, HTTPS encryption, and simplified deployment capabilities, making malicious pages appear more legitimate to potential victims.</p>



<p>Researchers noted that the phishing pages were specifically designed for targeted distribution through channels such as SMS, WhatsApp, Telegram, and social media rather than search engine discovery. This targeted approach helps maximize victim engagement while reducing unwanted visibility.</p>



<p>The findings demonstrate that traditional domain-based blocking and blacklist approaches are becoming less effective against modern phishing operations. As attackers increasingly rely on legitimate platforms to host malicious content, organizations must adopt stronger behavioral detection strategies, continuously monitor for brand impersonation, and improve collaboration across the security community.</p>



<p>The campaign serves as a reminder that phishing remains one of the most effective cybercrime techniques, particularly when combined with trusted platforms and scalable infrastructure designed to withstand disruption.</p>



<h2 class="wp-block-heading" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IOCs)</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">#</th><th class="has-text-align-left" data-align="left">Hostname</th><th class="has-text-align-left" data-align="left">Count</th></tr></thead><tbody><tr><td class="has-text-align-left" data-align="left">1</td><td class="has-text-align-left" data-align="left">soporte-index25.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">2</td><td class="has-text-align-left" data-align="left">soporte-index09.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">3</td><td class="has-text-align-left" data-align="left">sntdr-soporte25.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">4</td><td class="has-text-align-left" data-align="left">sntdr-soporte25.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">5</td><td class="has-text-align-left" data-align="left">07-soporte.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">6</td><td class="has-text-align-left" data-align="left">soporte2507.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">7</td><td class="has-text-align-left" data-align="left">soporte160625.github[.]io</td><td class="has-text-align-left" data-align="left">3</td></tr><tr><td class="has-text-align-left" data-align="left">8</td><td class="has-text-align-left" data-align="left">soporte250324.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">9</td><td class="has-text-align-left" data-align="left">soporte74.github[.]io</td><td class="has-text-align-left" data-align="left">4</td></tr><tr><td class="has-text-align-left" data-align="left">10</td><td class="has-text-align-left" data-align="left">soporte-bm1.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">11</td><td class="has-text-align-left" data-align="left">soporte-r5.github[.]io</td><td class="has-text-align-left" data-align="left">3</td></tr><tr><td class="has-text-align-left" data-align="left">12</td><td class="has-text-align-left" data-align="left">api.sheetbest.com</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">13</td><td class="has-text-align-left" data-align="left">soporte0625.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">14</td><td class="has-text-align-left" data-align="left">soporte200525.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">15</td><td class="has-text-align-left" data-align="left">soporte2650.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">16</td><td class="has-text-align-left" data-align="left">soporte-bn1.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">17</td><td class="has-text-align-left" data-align="left">soporte-b2.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">18</td><td class="has-text-align-left" data-align="left">soporte-index.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">19</td><td class="has-text-align-left" data-align="left">soporte-c1.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">20</td><td class="has-text-align-left" data-align="left">soporte-b4.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">21</td><td class="has-text-align-left" data-align="left">sntndr25-soporte.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">22</td><td class="has-text-align-left" data-align="left">sntndr-soporte0825.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">23</td><td class="has-text-align-left" data-align="left">0825-soporte.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">24</td><td class="has-text-align-left" data-align="left">soporte-07-25.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">25</td><td class="has-text-align-left" data-align="left">soporte-0725.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">26</td><td class="has-text-align-left" data-align="left">0725soporte.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">27</td><td class="has-text-align-left" data-align="left">soporte0725-3.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">28</td><td class="has-text-align-left" data-align="left">soporte0725.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">29</td><td class="has-text-align-left" data-align="left">soporteyatencionf.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">30</td><td class="has-text-align-left" data-align="left">0725-soporte.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">31</td><td class="has-text-align-left" data-align="left">soporte-y-atencion.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">32</td><td class="has-text-align-left" data-align="left">soporter03.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">33</td><td class="has-text-align-left" data-align="left">respaldo94.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">34</td><td class="has-text-align-left" data-align="left">soporte-index05.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">35</td><td class="has-text-align-left" data-align="left">soporte-b1.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr><tr><td class="has-text-align-left" data-align="left">36</td><td class="has-text-align-left" data-align="left">soporte0625.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">37</td><td class="has-text-align-left" data-align="left">soporte250324.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">38</td><td class="has-text-align-left" data-align="left">fldsmdfr-94.github[.]io</td><td class="has-text-align-left" data-align="left">2</td></tr><tr><td class="has-text-align-left" data-align="left">39</td><td class="has-text-align-left" data-align="left">support-vh.github[.]io</td><td class="has-text-align-left" data-align="left">1</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/github-pages-phishing/">Hackers Use GitHub Pages for Phishing Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/github-pages-phishing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>New Sniper Dz Scam Operation Exploits MENA Users with Fraudulent Facebook Offers</title>
		<link>https://firsthackersnews.com/sniper-dz-mena-facebook-scam/</link>
					<comments>https://firsthackersnews.com/sniper-dz-mena-facebook-scam/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 15 Jun 2026 10:04:46 +0000</pubDate>
				<category><![CDATA[Bug Bounty]]></category>
		<category><![CDATA[Email servers]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Browser Alerts]]></category>
		<category><![CDATA[Digital Fraud]]></category>
		<category><![CDATA[Fake Facebook Offers]]></category>
		<category><![CDATA[MENA Region]]></category>
		<category><![CDATA[Notification Spam]]></category>
		<category><![CDATA[User Awareness]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11828</guid>

					<description><![CDATA[<p>A new Sniper Dz scam campaign is targeting users across the Middle East and North Africa (MENA) through fraudulent Facebook offers and deceptive browser alerts. Researchers warn that the operation uses social engineering tactics to lure victims into financial scams, credential theft, and other online fraud activities.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/sniper-dz-mena-facebook-scam/">New Sniper Dz Scam Operation Exploits MENA Users with Fraudulent Facebook Offers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Cybersecurity researchers have uncovered a sophisticated scam campaign known as <strong>Sniper Dz</strong>, which primarily targets users across the <strong>Middle East and North Africa (MENA)</strong> region. The operation leverages <strong>fake Facebook promotions</strong>, deceptive social media content, and browser notification abuse to lure victims into fraudulent schemes.</p>



<p>Unlike traditional phishing attacks that immediately request credentials, Sniper Dz employs a multi-stage social engineering process designed to gradually build trust before redirecting users into malicious advertising and scam ecosystems. The campaign demonstrates how threat actors are increasingly combining social media platforms, legitimate web services, and browser features to maximize victim engagement.</p>



<h2 class="wp-block-heading">Technical Analysis of the Campaign</h2>



<p>Researchers found that the operation relies heavily on social engineering techniques rather than malware deployment. Victims are initially exposed to attractive Facebook advertisements promising prizes, discounts, giveaways, or exclusive offers.</p>



<p>The campaign then guides users through a series of seemingly legitimate web pages before ultimately triggering browser notification permissions and redirecting users into fraudulent content networks. By abusing trusted platforms and legitimate web services, the attackers are able to reduce suspicion and improve campaign effectiveness.</p>



<h2 class="wp-block-heading">Sniper Dz Attack Flow</h2>



<p>The attack follows a structured victim funnel designed to maximize conversion rates while minimizing detection.</p>



<h3 class="wp-block-heading">Phase 1 – Social Media Lures</h3>



<p>Attackers publish fraudulent advertisements and impersonation posts across social media platforms.</p>



<ul class="wp-block-list">
<li>Free gift offers </li>



<li>Discount promotions </li>



<li>Prize giveaways </li>



<li>Mobile device rewards</li>
</ul>



<h3 class="wp-block-heading">Phase 2 – Legitimate-Looking Bridge Pages</h3>



<p>Instead of immediately redirecting victims to malicious content, the campaign utilizes intermediary pages hosted on legitimate services.</p>



<ul class="wp-block-list">
<li>Link aggregation platforms </li>



<li>Landing page builders </li>



<li>Redirect services </li>



<li>Social media profile pages</li>
</ul>



<p>These bridge pages help bypass security filters and increase the perceived legitimacy of the campaign.</p>



<figure class="wp-block-image aligncenter size-large is-resized"><img fetchpriority="high" decoding="async" width="1024" height="683" src="https://firsthackersnews.com/wp-content/uploads/2026/06/Sniper-Dz-victim-funnel-1-1024x683.png" alt="" class="wp-image-11831" style="width:636px;height:auto" srcset="https://firsthackersnews.com/wp-content/uploads/2026/06/Sniper-Dz-victim-funnel-1-300x200.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/06/Sniper-Dz-victim-funnel-1-768x512.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/06/Sniper-Dz-victim-funnel-1-1024x683.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/06/Sniper-Dz-victim-funnel-1.png 1536w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="has-text-align-center">Simplified representation of the Sniper Dz victim funnel showing how users are guided from social media lures through trusted bridge pages before being exposed to browser notification abuse and scam content.</p>



<h3 class="wp-block-heading">Phase 3 – Browser Notification Abuse</h3>



<p>Once users reach the final stage, they are encouraged to allow browser notifications through deceptive prompts.</p>



<ul class="wp-block-list">
<li>Fake CAPTCHA pages </li>



<li>&#8220;Click Allow to Continue&#8221;</li>



<li>&#8220;Verify You&#8217;re Human&#8221;</li>
</ul>



<p>After notification permissions are granted, attackers gain a persistent channel to deliver scam advertisements and fraudulent alerts directly to the victim&#8217;s browser.</p>



<h2 class="wp-block-heading">Potential Risks to Users</h2>



<ul class="wp-block-list">
<li>Financial Fraud</li>



<li>Privacy Exposure</li>



<li>Continuous Scam Exposure</li>



<li>Credential Theft</li>
</ul>



<h2 class="wp-block-heading">Why Social Engineering Remains Effective</h2>



<p>Modern scam campaigns increasingly rely on psychological manipulation rather than technical exploitation. By leveraging trusted platforms such as Facebook and legitimate web services, attackers can make fraudulent content appear authentic.</p>



<p>The use of multiple redirection stages also helps threat actors evade automated detection systems while increasing the likelihood that victims will complete the entire attack flow.</p>



<p>As users become more aware of traditional phishing techniques, attackers continue to evolve their tactics by combining social media abuse, browser notification exploitation, and deceptive marketing strategies.</p>



<h2 class="wp-block-heading">Security Recommendations</h2>



<ul class="wp-block-list">
<li>Verify Promotional Offers</li>



<li>Review Browser Notifications</li>



<li>Exercise Caution with Redirects</li>



<li>Implement Security Awareness Training</li>
</ul>



<p>The <strong>Sniper Dz</strong> campaign demonstrates how modern threat actors are leveraging <strong>social media impersonation</strong>, <strong>trusted bridge pages</strong>, and <strong>browser notification abuse</strong> to target users across the MENA region. Rather than relying on malware, the operation exploits user trust and social engineering tactics to drive victims toward fraudulent content, making awareness and browser security practices critical defenses against these evolving threats.</p>



<p></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/sniper-dz-mena-facebook-scam/">New Sniper Dz Scam Operation Exploits MENA Users with Fraudulent Facebook Offers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/sniper-dz-mena-facebook-scam/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Gamaredon Phishing Attacks Use GammaDrop Malware</title>
		<link>https://firsthackersnews.com/gamaredon-phishing-attacks/</link>
					<comments>https://firsthackersnews.com/gamaredon-phishing-attacks/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 18 May 2026 14:13:00 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[#CloudSecurity]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#CyberEspionage]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#DigitalRisk]]></category>
		<category><![CDATA[#EthicalHacking]]></category>
		<category><![CDATA[#gamaredon]]></category>
		<category><![CDATA[#gammadrop]]></category>
		<category><![CDATA[#gammaload]]></category>
		<category><![CDATA[#governmentsecurity]]></category>
		<category><![CDATA[#Hacking]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#ITSecurity]]></category>
		<category><![CDATA[#Malware]]></category>
		<category><![CDATA[#malwareloader]]></category>
		<category><![CDATA[#phishingattacks]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#spearphishing]]></category>
		<category><![CDATA[#ThreatHunting]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#vbscriptmalware]]></category>
		<category><![CDATA[#winrarvulnerability]]></category>
		<category><![CDATA[#ZeroTrust]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11713</guid>

					<description><![CDATA[<p>A sustained cyber-espionage campaign linked to the Gamaredon threat group is actively targeting Ukrainian government organizations through large-scale</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gamaredon-phishing-attacks/">Gamaredon Phishing Attacks Use GammaDrop Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A sustained cyber-espionage campaign linked to the Gamaredon threat group is actively targeting Ukrainian government organizations through large-scale phishing attacks and multi-stage malware delivery chains. The operation combines social engineering, abuse of trusted infrastructure, and custom malware loaders to maintain long-term access to compromised systems.</p>



<p>Also tracked as UAC-0010 or Shuckworm, Gamaredon continues to exploit CVE-2025-8088, a directory traversal vulnerability in WinRAR that allows malicious files to be written outside the intended extraction directory. Although the flaw has been widely abused since 2025, researchers noted that Gamaredon’s campaigns stand out due to their persistence, rapid infrastructure rotation, and repeated targeting of Ukrainian government entities.</p>



<h2 class="wp-block-heading">Phishing Campaign Delivers GammaDrop Malware</h2>



<p>The attacks begin with carefully crafted spearphishing emails sent either from compromised Ukrainian government accounts or spoofed domains designed to appear legitimate. Many of these emails mimic official court summons, legal notices, or government-related communications to increase the likelihood of user interaction.</p>



<p>The phishing attachments typically contain malicious RAR or ARJ archives disguised as regular documents. Inside the archive, researchers identified:</p>



<ul class="wp-block-list">
<li>A decoy PDF document used to distract the victim</li>



<li>A hidden VBScript payload stored using NTFS Alternate Data Streams (ADS)</li>
</ul>



<p>When the archive is extracted, the WinRAR vulnerability is abused to silently place the malicious VBScript into the Windows Startup folder. This ensures persistence on the infected machine without requiring additional user interaction.</p>



<p>The first-stage payload, known as GammaDrop, functions as a downloader responsible for retrieving additional malware from attacker-controlled infrastructure. Researchers observed that the script is heavily obfuscated using randomized variables, junk code, and automated generation techniques commonly associated with Gamaredon operations.</p>



<h2 class="wp-block-heading">GammaLoad Expands Persistence and Reconnaissance</h2>



<p>After execution, GammaDrop downloads a second-stage malware component called GammaLoad from infrastructure hosted through Cloudflare Workers. The payload is delivered as an HTA file and launched using mshta.exe in a hidden window to avoid drawing attention.</p>



<p>GammaLoad acts as both a persistence mechanism and a reconnaissance tool. It creates RunOnce registry entries and continuously communicates with command-and-control servers to receive instructions and additional payloads.</p>



<p>The malware collects system-level information including:</p>



<ul class="wp-block-list">
<li>Computer name</li>



<li>System drive details</li>



<li>Volume serial numbers</li>



<li>Victim identification data</li>
</ul>



<p>This information is embedded into beaconing traffic, allowing attackers to uniquely track infected systems and selectively deliver follow-up malware.</p>



<p>Researchers also observed that Gamaredon frequently rotates its infrastructure using fast-flux DNS, dynamic DNS services, and short-lived domains to evade detection. Communication traffic is disguised using legitimate browser user-agent strings, while some newer variants imitate automated services such as Bingbot to blend malicious traffic with normal network activity.</p>



<p>The Security Service of Ukraine (SSU), along with regional government and law enforcement organizations, remains one of the primary targets of these campaigns. Researchers believe the operation’s success is also supported by weak email authentication practices across some targeted domains, where missing or poorly configured SPF, DKIM, and DMARC policies allow attackers to spoof trusted senders more effectively.</p>



<p>Although the malware itself is not considered highly advanced, Gamaredon continues to maintain a strong operational presence through continuous adaptation, large-scale phishing activity, and aggressive infrastructure management.</p>



<p><strong>Security teams are advised to patch vulnerable WinRAR installations immediately, strengthen email authentication controls, monitor suspicious archive-based phishing activity, and block known malicious infrastructure associated with the campaign.</strong></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gamaredon-phishing-attacks/">Gamaredon Phishing Attacks Use GammaDrop Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/gamaredon-phishing-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Facebook Phishing Campaign Targets Business Accounts</title>
		<link>https://firsthackersnews.com/facebook-phishing-campaign/</link>
					<comments>https://firsthackersnews.com/facebook-phishing-campaign/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Sun, 03 May 2026 20:54:12 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[#AppSheet]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberThreats]]></category>
		<category><![CDATA[#DataBreach]]></category>
		<category><![CDATA[#DigitalSecurity]]></category>
		<category><![CDATA[#FacebookPhishing]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#MalwareAnalysis]]></category>
		<category><![CDATA[#Netlify]]></category>
		<category><![CDATA[#OnlineSafety]]></category>
		<category><![CDATA[#PhishingAttack]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SocialEngineering]]></category>
		<category><![CDATA[#Telegram]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11680</guid>

					<description><![CDATA[<p>Researchers at Guardio Labs have uncovered a large and highly organized phishing operation known as AccountDumpling, which has</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/facebook-phishing-campaign/">Facebook Phishing Campaign Targets Business Accounts</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Researchers at Guardio Labs have uncovered a large and highly organized phishing operation known as <strong>AccountDumpling</strong>, which has already compromised more than 30,000 Facebook accounts worldwide. What makes this campaign stand out is not just its scale, but the way it abuses legitimate platforms to make phishing emails appear completely authentic.</p>



<p>Instead of relying on fake domains or compromised mail servers, attackers use Google AppSheet to send emails through Google’s own infrastructure. These messages are generated as part of automated workflows, meaning they pass authentication checks like SPF, DKIM, and DMARC without raising suspicion. </p>



<p>As a result, security tools and spam filters see them as trusted communications, allowing phishing messages to land directly in inboxes of targeted users—often business account owners managing Facebook pages.</p>



<h2 class="wp-block-heading">Multi-Layered Attack Strategy</h2>



<p>The campaign is not a single phishing page but a structured, multi-stage system designed to increase success rates. Victims are first directed to pages hosted on Netlify, where attackers replicate the Facebook Help Center with high accuracy. These pages are customized per victim using unique subdomains, making them difficult to block using traditional security measures.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1024" height="766" src="https://firsthackersnews.com/wp-content/uploads/2026/05/image.png" alt="" class="wp-image-11681" srcset="https://firsthackersnews.com/wp-content/uploads/2026/05/image-300x224.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/05/image-768x575.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/05/image.png 1024w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Email phishing (Source: Guard Labs)</figcaption></figure>



<p>From there, users are guided through a series of steps that collect not only login credentials but also deeper identity information such as date of birth and even government-issued ID images. In some cases, the attackers shift tactics by offering fake incentives, like verification badges, hosted on platforms such as Vercel. These pages are designed to look dynamic and legitimate, while quietly bypassing detection systems using techniques like hidden Unicode characters.</p>



<p>The operation becomes more advanced in later stages. Attackers host phishing documents on Google Drive, presenting them as official Meta notifications. These documents, often designed using Canva, contain embedded links that redirect victims into interactive phishing environments. These environments are powered by real-time communication frameworks, allowing attackers to actively engage with victims during the login process.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1024" height="809" src="https://firsthackersnews.com/wp-content/uploads/2026/05/image-1.png" alt="" class="wp-image-11682" srcset="https://firsthackersnews.com/wp-content/uploads/2026/05/image-1-300x237.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/05/image-1-768x607.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/05/image-1.png 1024w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Account Dumpling (Source: Guard Labs)</figcaption></figure>



<p>This live interaction is a critical aspect of the campaign. Instead of passively collecting credentials, attackers can request one-time passwords, monitor user actions, and even capture browser sessions as they happen. This significantly increases the likelihood of successful account takeover, even when multi-factor authentication is enabled.</p>



<h2 class="wp-block-heading">Real-Time Data Exfiltration and Attribution</h2>



<p>Once credentials are captured, they are immediately transmitted through a centralized system built around Telegram bots. This allows operators to monitor incoming data in real time and quickly take control of compromised accounts before victims notice suspicious activity.</p>



<p>Analysis of the infrastructure shows a strong operational scale, with thousands of records flowing into attacker-controlled channels. Most victims are concentrated in regions like the United States and Europe, indicating a focus on high-value targets such as businesses and influencers.</p>



<p>Investigators were also able to trace elements of the campaign back to Vietnamese actors. This attribution is supported by metadata found in phishing documents and developer comments embedded within the malicious code, providing insight into the origin of the operation.</p>



<h2 class="wp-block-heading">A Shift Toward Industrialized Phishing</h2>



<p>AccountDumpling reflects a broader shift in cybercrime, where phishing is no longer a simple tactic but part of a larger, industrialized ecosystem. Attackers are combining trusted services, automation, and real-time interaction to create highly effective campaigns that are difficult to detect and disrupt.</p>



<p>Compromised accounts are rarely the end goal. They are often reused for further scams, advertising fraud, or additional phishing attacks, creating a cycle that sustains and expands the operation. This approach shows how modern threat actors are leveraging legitimate platforms at scale, turning them into tools for widespread abuse while staying under the radar.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/facebook-phishing-campaign/">Facebook Phishing Campaign Targets Business Accounts</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/facebook-phishing-campaign/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>W3LL Phishing Kit Takedown Disrupts MFA Bypass Campaign</title>
		<link>https://firsthackersnews.com/w3ll-phishing-kit/</link>
					<comments>https://firsthackersnews.com/w3ll-phishing-kit/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 14 Apr 2026 10:25:18 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[#AccountTakeover]]></category>
		<category><![CDATA[#CredentialTheft]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#Cybercrime]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#FBI]]></category>
		<category><![CDATA[#FraudPrevention]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#MFABypass]]></category>
		<category><![CDATA[#phishing]]></category>
		<category><![CDATA[#PhishingToolkit]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityBreach]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#W3LL]]></category>
		<category><![CDATA[#W3LLPhishingKit]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11592</guid>

					<description><![CDATA[<p>The FBI Atlanta Field Office, in collaboration with Indonesian law enforcement, has taken down a large-scale global phishing</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/w3ll-phishing-kit/">W3LL Phishing Kit Takedown Disrupts MFA Bypass Campaign</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The FBI Atlanta Field Office, in collaboration with Indonesian law enforcement, has taken down a large-scale global phishing operation linked to the W3LL toolkit. This joint effort marks a major milestone, as it is the first coordinated action between the United States and Indonesia targeting a phishing kit developer.</p>



<p>The operation focused on the W3LL phishing kit, a tool widely used by cybercriminals to steal credentials and bypass multi-factor authentication. Attackers used this kit to carry out large-scale fraud attempts, with losses estimated to exceed $20 million.</p>



<h2 class="wp-block-heading">How the W3LL Phishing Kit Worked</h2>



<p>The W3LL toolkit was designed to make cybercrime easier, even for low-skilled attackers. It was sold as a service, allowing buyers to quickly launch phishing campaigns using ready-made fake login pages that closely mimicked legitimate websites.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<p>What made this tool especially dangerous was its ability to go beyond simple credential theft. Instead of just capturing usernames and passwords, it also collected session data and authentication tokens. This allowed attackers to bypass MFA protections and gain ongoing access to accounts without raising immediate alerts.</p>



<p>The ecosystem also included an underground marketplace called W3LLSTORE. This platform enabled criminals to buy and sell stolen credentials, corporate access, and remote connections, creating a full cybercrime supply chain.</p>



<ul class="wp-block-list">
<li>Over 25,000 compromised accounts were sold between 2019 and 2023</li>



<li>More than 17,000 victims were targeted globally in recent campaigns</li>



<li>Fraud attempts exceeded $20 million</li>



<li>Stolen access was often resold multiple times for profit</li>
</ul>



<h2 class="wp-block-heading">Law Enforcement Action and Impact</h2>



<p>Even after the original marketplace shut down, the operation continued through private channels. Investigators tracked its evolution and identified the key individuals behind it.</p>



<p>With support from U.S. authorities, the FBI seized critical infrastructure used to run the phishing service. At the same time, Indonesian police arrested the suspected developer and took control of domains linked to the operation.</p>



<p>Officials described the platform as more than just a phishing kit—it functioned as a complete cybercrime service. By shutting it down, authorities have disrupted a major tool that attackers relied on to breach organizations.</p>



<p>This takedown highlights how modern phishing has evolved into organized, scalable operations—and why international cooperation is essential to combat today’s cyber threats.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/w3ll-phishing-kit/">W3LL Phishing Kit Takedown Disrupts MFA Bypass Campaign</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/w3ll-phishing-kit/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Fake LastPass Support Scam Targets Password Vaults</title>
		<link>https://firsthackersnews.com/lastpass-support-phishing-attack/</link>
					<comments>https://firsthackersnews.com/lastpass-support-phishing-attack/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 05 Mar 2026 06:05:07 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[#AccountSecurity]]></category>
		<category><![CDATA[#CredentialTheft]]></category>
		<category><![CDATA[#CyberDefense]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberSecurityNews]]></category>
		<category><![CDATA[#CyberThreats]]></category>
		<category><![CDATA[#DataProtection]]></category>
		<category><![CDATA[#DigitalSecurity]]></category>
		<category><![CDATA[#EmailSecurity]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#LastPass]]></category>
		<category><![CDATA[#LastPassPhishing]]></category>
		<category><![CDATA[#PasswordManager]]></category>
		<category><![CDATA[#PhishingAttack]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11335</guid>

					<description><![CDATA[<p>A new phishing campaign is pretending to be LastPass support emails to trick users into revealing their vault</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/lastpass-support-phishing-attack/">Fake LastPass Support Scam Targets Password Vaults</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p></p>



<p>A new phishing campaign is pretending to be <strong>LastPass support emails</strong> to trick users into revealing their vault passwords and account credentials.</p>



<p>Attackers send emails that look like internal support conversations about suspicious activity on a user’s account.</p>



<p>These messages claim that someone is attempting actions such as:</p>



<ul class="wp-block-list">
<li>Exporting vault data</li>



<li>Recovering the account</li>



<li>Registering a new trusted device</li>
</ul>



<p>The goal is to scare users into reacting quickly.</p>



<h2 class="wp-block-heading">How the Phishing Attack Works</h2>



<p>Hackers use a method called <strong>display name spoofing</strong>. The sender name appears as <em>LastPass Support</em>, but the actual email address comes from a different domain.</p>



<p>Many email apps, especially on mobile devices, show only the sender name. Because of this, users may not notice the fake address.</p>



<p>The email then asks users to secure or verify their account by clicking a link.</p>



<p>However, the link leads to a malicious website such as:</p>



<p>verify-lastpass[.]com</p>



<p>This site hosts a fake <strong>LastPass login page</strong> designed to look identical to the official one. If users enter their credentials, attackers can capture their master password and access their stored vault data.</p>



<h2 class="wp-block-heading">Common Phishing Email Signs</h2>



<p>The phishing emails often include LastPass branding and fake message threads to appear legitimate.</p>



<p>Some of the subject lines used include:</p>



<ul class="wp-block-list">
<li>“Account recovery verification request”</li>



<li>“Unauthorized vault export attempt detected”</li>



<li>“New trusted device registered to your account”</li>
</ul>



<p>These messages create urgency so users click before verifying the source.</p>



<h2 class="wp-block-heading">Security Advice for LastPass Users</h2>



<p>LastPass has warned that it will <strong>never ask for a user’s master password</strong> through email.</p>



<p>Users should take the following precautions:</p>



<ul class="wp-block-list">
<li>Check the full sender email address carefully</li>



<li>Avoid clicking links inside emails</li>



<li>Access LastPass directly through the official website or app</li>



<li>Enable multi-factor authentication (MFA)</li>



<li>Report suspicious emails to <strong><a>abuse@lastpass.com</a></strong></li>
</ul>



<h2 class="wp-block-heading">Why This Attack Matters</h2>



<p>Phishing attacks are becoming more realistic and harder to detect.</p>



<p>Since password managers store sensitive data, they are a high-value target for cybercriminals. Users should always verify security alerts and avoid rushing to click links, even when the message appears legitimate.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/lastpass-support-phishing-attack/">Fake LastPass Support Scam Targets Password Vaults</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/lastpass-support-phishing-attack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OAuth Phishing Campaign Targets Entra ID and Google Workspace</title>
		<link>https://firsthackersnews.com/oauth-phishing-campaign-targets-entra-id-and-google-workspace/</link>
					<comments>https://firsthackersnews.com/oauth-phishing-campaign-targets-entra-id-and-google-workspace/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 04 Mar 2026 12:23:09 +0000</pubDate>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[#AccountTakeover]]></category>
		<category><![CDATA[#CloudSecurity]]></category>
		<category><![CDATA[#CyberDefense]]></category>
		<category><![CDATA[#CyberRisk]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberSecurityNews]]></category>
		<category><![CDATA[#CyberThreats]]></category>
		<category><![CDATA[#DigitalSecurity]]></category>
		<category><![CDATA[#EmailSecurity]]></category>
		<category><![CDATA[#EnterpriseSecurity]]></category>
		<category><![CDATA[#EntraID]]></category>
		<category><![CDATA[#GoogleWorkspace]]></category>
		<category><![CDATA[#IdentitySecurity]]></category>
		<category><![CDATA[#IdentityThreats]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#InfosecCommunity]]></category>
		<category><![CDATA[#MicrosoftEntraID]]></category>
		<category><![CDATA[#OAuth]]></category>
		<category><![CDATA[#OAuthAttack]]></category>
		<category><![CDATA[#OAuthPhishing]]></category>
		<category><![CDATA[#PhishingAttack]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityOperations]]></category>
		<category><![CDATA[#ThreatDetection]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11327</guid>

					<description><![CDATA[<p>Microsoft has discovered advanced phishing campaigns that misuse the normal behavior of the OAuth 2.0 authentication process. Instead</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/oauth-phishing-campaign-targets-entra-id-and-google-workspace/">OAuth Phishing Campaign Targets Entra ID and Google Workspace</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Microsoft has discovered advanced phishing campaigns that misuse the normal behavior of the OAuth 2.0 authentication process.</p>



<p>Instead of exploiting software bugs or directly stealing passwords, attackers abuse trusted login flows used by platforms like Microsoft Entra ID and Google Workspace. This tactic allows them to bypass traditional email security systems and quietly redirect victims to malicious sites.</p>



<h2 class="wp-block-heading"><strong>How the Attack Starts</strong></h2>



<p>The attack begins when threat actors create a malicious application inside their own cloud tenant. They configure the application&#8217;s redirect link to point to a domain controlled by the attackers.</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="759" height="881" src="https://firsthackersnews.com/wp-content/uploads/2026/03/image-3.png" alt="" class="wp-image-11328" style="width:705px;height:auto" srcset="https://firsthackersnews.com/wp-content/uploads/2026/03/image-3-258x300.png 258w, https://firsthackersnews.com/wp-content/uploads/2026/03/image-3.png 759w" sizes="auto, (max-width: 759px) 100vw, 759px" /><figcaption class="wp-element-caption">attack chain(Source: Microsoft)<br></figcaption></figure>



<p>To lure victims, attackers send phishing emails that appear legitimate. These messages often look like normal workplace requests.</p>



<p>Common phishing lures include:</p>



<ul class="wp-block-list">
<li>Fake e-signature requests</li>



<li>Microsoft Teams meeting invitations</li>



<li>Password reset alerts</li>



<li>Account verification messages</li>
</ul>



<p>When a victim clicks the link, a hidden OAuth authorization process begins.</p>



<h2 class="wp-block-heading"><strong>How Attackers Bypass Detection</strong></h2>



<p>Attackers modify certain parameters in the OAuth request to trigger a silent authentication process.</p>



<p>Two parameters are commonly abused:</p>



<ul class="wp-block-list">
<li><strong>prompt=none</strong> – forces the system to check the session without user interaction</li>



<li><strong>scope=invalid</strong> – intentionally triggers an authentication error</li>
</ul>



<p>This forces the identity provider to redirect the user automatically. Because the redirection happens through a trusted identity provider, the link looks legitimate to users and security tools.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong> <a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<h2 class="wp-block-heading"><strong>Using the “State” Parameter for Deception</strong></h2>



<p>To make the attack look even more convincing, attackers abuse the OAuth <strong>state</strong> parameter.</p>



<p>Normally, this parameter is used to match authentication requests and responses. However, attackers encode the victim’s email address inside it.</p>



<p>Encoding methods used include:</p>



<ul class="wp-block-list">
<li>Base64</li>



<li>Hex encoding</li>



<li>Custom decoding schemes</li>
</ul>



<p>When the victim lands on the phishing page, their email address is already filled in automatically, making the login page appear legitimate.</p>



<h2 class="wp-block-heading"><strong>What Happens After Redirection</strong></h2>



<p>Once redirected, victims are sent to attacker-controlled infrastructure.</p>



<p>Two main outcomes have been observed:</p>



<h3 class="wp-block-heading"><strong>Credential Theft</strong></h3>



<p>Victims are redirected to phishing frameworks such as EvilProxy that capture login credentials and session cookies.</p>



<h3 class="wp-block-heading"><strong>Malware Delivery</strong></h3>



<p>In some campaigns, the redirect automatically downloads a ZIP file. This archive contains a malicious shortcut that launches a PowerShell script.</p>



<p>The script performs several actions:</p>



<ul class="wp-block-list">
<li>Collects system information</li>



<li>Extracts a legitimate executable file (steam_monitor.exe)</li>



<li>Loads a malicious DLL (crashhandler.dll)</li>
</ul>



<p>This technique allows attackers to run malicious code while appearing as legitimate software, ultimately connecting the infected system to an external command-and-control server.</p>



<h2 class="wp-block-heading"><strong>Mitigation and Threat Indicators</strong></h2>



<p>This attack shows how threat actors can misuse normal OAuth authentication behavior instead of exploiting software bugs. Because the activity follows standard protocol rules, it can be harder for traditional security tools to detect.</p>



<p><strong>Key Mitigation Steps</strong></p>



<ul class="wp-block-list">
<li>Restrict user consent for third-party OAuth applications</li>



<li>Regularly audit apps with excessive permissions</li>



<li>Implement Conditional Access policies</li>



<li>Enable strong identity protection controls</li>



<li>Use XDR to monitor identity, email, and endpoint activity</li>



<li>Monitor OAuth URL clicks with invalid <strong>scope</strong> parameters</li>



<li>Watch for unusual downloads triggered after OAuth redirects</li>



<li>Investigate suspicious <strong>PowerShell executions</strong></li>



<li>Detect unexpected <strong>DLL side-loading activit</strong></li>
</ul>



<h2 class="wp-block-heading"><strong>IOCs</strong></h2>



<figure class="wp-block-table"><table><thead><tr><th>Detection Type</th><th>Indicator / Component Details</th><th>Context</th></tr></thead><tbody><tr><td><strong>URL Parameters</strong></td><td><code>prompt=none</code>,&nbsp;<code>scope=invalid</code>&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/"></a>​</td><td>Used to trigger silent authentication errors&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/"></a>​.</td></tr><tr><td><strong>File Artifacts</strong></td><td><code>steam_monitor.exe</code>,&nbsp;<code>crashhandler.dll</code>,&nbsp;<code>crashlog.dat</code>&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/"></a>​</td><td>Components used for malicious DLL side-loading&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/"></a>​.</td></tr><tr><td><strong>Defender Antivirus</strong></td><td>Trojan:Win32/Malgent, Trojan:Win32/Znyonm, Trojan:Win32/WinLNK&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/"></a>​</td><td>Defender signatures for the associated malware payloads&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/"></a>​.</td></tr><tr><td><strong>Error Codes</strong></td><td>Error 65001,&nbsp;<code>error=interaction_required</code>&nbsp;<a rel="noreferrer noopener" target="_blank" href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/"></a>​</td><td>Indicates failed silent SSO and successful redirect&nbsp;<a href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/" target="_blank" rel="noreferrer noopener"></a>​.</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/oauth-phishing-campaign-targets-entra-id-and-google-workspace/">OAuth Phishing Campaign Targets Entra ID and Google Workspace</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/oauth-phishing-campaign-targets-entra-id-and-google-workspace/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>GTFire Phishing Attack Hides Behind Google Services</title>
		<link>https://firsthackersnews.com/gtfire-google-phishing-campaign/</link>
					<comments>https://firsthackersnews.com/gtfire-google-phishing-campaign/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 02 Mar 2026 21:45:10 +0000</pubDate>
				<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[#BrandImpersonation]]></category>
		<category><![CDATA[#CloudSecurity]]></category>
		<category><![CDATA[#CredentialTheft]]></category>
		<category><![CDATA[#CyberDefense]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#DigitalRisk]]></category>
		<category><![CDATA[#EmailSecurity]]></category>
		<category><![CDATA[#EnterpriseSecurity]]></category>
		<category><![CDATA[#GoogleAbuse]]></category>
		<category><![CDATA[#GTFire]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#PhishingCampaign]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SocialEngineering]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11311</guid>

					<description><![CDATA[<p>GTFire is a newly identified phishing campaign that misuses trusted Google services, including Firebase and Google Translate, to</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gtfire-google-phishing-campaign/">GTFire Phishing Attack Hides Behind Google Services</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>GTFire is a newly identified phishing campaign that misuses trusted Google services, including Firebase and Google Translate, to steal user credentials.</p>



<p>By hosting phishing content on legitimate Google-owned domains, the attackers are able to bypass many email security filters and web gateways. Because the links appear trustworthy, they are less likely to raise suspicion.</p>



<p>Victims are redirected to realistic login pages that imitate well-known brands. After entering their credentials, they are quietly sent to the real website, making the attack difficult to detect.</p>



<h2 class="wp-block-heading"><strong>Global Impact and Scale</strong></h2>



<p>The campaign is widespread. Investigators uncovered attacker-controlled servers containing thousands of stolen credentials linked to more than 1,000 organizations across 100+ countries and over 200 industries.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="608" src="https://firsthackersnews.com/wp-content/uploads/2026/03/image-1-1024x608.png" alt="" class="wp-image-11312" srcset="https://firsthackersnews.com/wp-content/uploads/2026/03/image-1-300x178.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/03/image-1-768x456.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/03/image-1-1024x608.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/03/image-1-1536x912.png 1536w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">GTFire phishing campaign (Source: Group-IB)<br></figcaption></figure>



<p>Mexico has the highest number of confirmed victims, particularly in manufacturing, education, and government sectors. The United States, Spain, India, and Argentina are also significantly affected.</p>



<p>The use of trusted cloud services makes this campaign especially effective and harder to block using traditional security controls.</p>



<p>Group-IB researchers describe GTFire as a structured, large-scale credential theft operation.</p>



<p>Attackers reuse the same phishing templates across multiple brands and store stolen data on centralized servers, organized by date, language, and targeted servic</p>



<p>More than 120 phishing domains were discovered, using similar naming patterns to quickly rotate infrastructure and avoid detection.</p>



<p>Attackers customize each fake login page to closely match real brands. After victims enter their credentials, they are redirected to the legitimate website, delaying suspicion.</p>



<p>Because the campaign uses trusted Google domains, traditional URL filtering and blocklists struggle to detect it — showing how easily legitimate infrastructure can be misused for phishing.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>The attack starts with a phishing email that contains a Google Translate link. This link quietly routes the victim through Google’s translation service before redirecting them to a fake login page hosted on Firebase.</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="624" height="571" src="https://firsthackersnews.com/wp-content/uploads/2026/03/image-2.png" alt="" class="wp-image-11313" style="width:931px;height:auto" srcset="https://firsthackersnews.com/wp-content/uploads/2026/03/image-2-300x275.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/03/image-2.png 624w" sizes="auto, (max-width: 624px) 100vw, 624px" /><figcaption class="wp-element-caption">Phishing pages display fake login error messages (Source: Group-IB)<br><br></figcaption></figure>



<p>Because the link uses a Google domain, many email filters and web gateways do not block it.</p>



<p>Attackers create many random *.web.app subdomains to host phishing pages and rotate them frequently to avoid detection. Each page is designed to look like a real brand login portal.</p>



<p>When victims enter their credentials, they are shown a fake “wrong password” message and asked to try again. Both login attempts are secretly captured and sent to attacker-controlled servers, along with basic details like location and browser language.</p>



<p>The stolen data is collected using simple, ready-made backend tools, making the campaign easy to scale.</p>



<h2 class="wp-block-heading"><strong>Mitigation Measures</strong></h2>



<p>Organizations should:</p>



<ul class="wp-block-list">
<li>Enforce phishing-resistant multi-factor authentication (MFA)</li>



<li>Train employees to recognize suspicious Google-based links</li>



<li>Monitor for unusual use of translate.goog and *.web.app domains</li>



<li>Watch for brand impersonation hosted on trusted cloud platforms</li>



<li>Share indicators of compromise with security communities and CERT teams</li>
</ul>



<p>Trusted services can be misused, so detection strategies must go beyond basic domain reputation check</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gtfire-google-phishing-campaign/">GTFire Phishing Attack Hides Behind Google Services</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/gtfire-google-phishing-campaign/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI-Driven Phishing Kit Targets Microsoft Accounts</title>
		<link>https://firsthackersnews.com/ai-driven-phishing-kit/</link>
					<comments>https://firsthackersnews.com/ai-driven-phishing-kit/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 30 Dec 2025 07:03:04 +0000</pubDate>
				<category><![CDATA[AI Malware]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email servers]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[OpenAI]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[account takeover]]></category>
		<category><![CDATA[ai phishing]]></category>
		<category><![CDATA[credential theft]]></category>
		<category><![CDATA[email security]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[outlook phishing]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Phishing Kit]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=10878</guid>

					<description><![CDATA[<p>Since March 2025, attackers running a Spanish-language phishing campaign have been going after Microsoft Outlook accounts. The phishing</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/ai-driven-phishing-kit/">AI-Driven Phishing Kit Targets Microsoft Accounts</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Since March 2025, attackers running a Spanish-language phishing campaign have been going after Microsoft Outlook accounts. The phishing tool they use appears advanced and likely built with help from AI.</p>



<h2 class="wp-block-heading"><strong>AI-Driven Phishing Kit </strong></h2>



<p>Researchers track the activity using a small but unusual clue: four mushroom emojis hidden inside the text “OUTL.” So far, this marker has been linked to more than 75 separate attack setups.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1020" height="1024" src="https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-1020x1024.png" alt="" class="wp-image-10879" srcset="https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-66x66.png 66w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-150x150.png 150w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-200x201.png 200w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-300x300.png 300w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-400x402.png 400w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-600x602.png 600w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-768x771.png 768w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-800x803.png 800w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-1020x1024.png 1020w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12-1200x1205.png 1200w, https://firsthackersnews.com/wp-content/uploads/2025/12/image-12.png 1280w" sizes="auto, (max-width: 1020px) 100vw, 1020px" /><figcaption class="wp-element-caption"><em>Source – The Sage Hollow</em></figcaption></figure>



<p>The attackers collect stolen email usernames and passwords, along with the victim’s IP address and location. This information is then sent to the attackers using Telegram and Discord.</p>



<p>To trick users, the phishing page copies the Outlook login screen and displays prompts in Spanish, making it look legitimate to victims.</p>



<p>After a victim enters their login details, the phishing tool quickly adds extra context to the stolen data. It checks the user’s IP address using api.ipify.org and pulls location details from ipapi.co.</p>



<p>This data collection happens instantly, before the stolen credentials are sent to the attackers.</p>



<p>The campaign shows careful planning. Even though the attackers change how the code is hidden, the way the operation runs stays mostly the same.</p>



<p>Sage Hollow researchers first spotted the activity by noticing the repeated mushroom emoji marker, which helped them trace more related attacks.</p>



<p>Over time, the phishing kit has appeared in multiple versions. Some use heavy obfuscation and anti-analysis tricks, while others are left completely open and resemble AI-generated code. The latest version, <strong>disBLOCK.js</strong>, uses clean formatting, clear function names, and Spanish comments explaining each step — signs that the code was likely generated with AI rather than written fully by hand.</p>



<h2 class="wp-block-heading"><strong>How the Phishing Kit Works</strong></h2>



<p>The phishing tool is designed with separate pieces, keeping its settings away from the main logic. In earlier versions, a file called <em>xjsx.js</em> was used to store Telegram bot details with only basic hiding techniques.</p>



<p>When someone enters their login details on the fake page, the tool runs through a set process. It checks whether the email address is valid, then reaches out to external services to collect IP and location information.</p>



<p>All stolen data is bundled into a standard message format and sent over regular HTTPS connections. The attackers use either Telegram bots or Discord webhooks to receive this information.</p>



<p>Newer samples rely more on Discord webhooks because they work as one-way channels. Even if the link is discovered, past data cannot be viewed.</p>



<p>This setup points to a shared phishing platform, where multiple attackers reuse the same toolkit across different campaigns.</p>



<h2 class="wp-block-heading"><strong>Security Recommendations</strong></h2>



<ul class="wp-block-list">
<li>Organizations should enable phishing-resistant MFA on Microsoft accounts to reduce the impact of stolen passwords.</li>



<li>Email gateways should be tuned to detect look-alike Outlook login pages and block messages that redirect users to external authentication sites.</li>



<li>Security teams should monitor outbound traffic for suspicious connections to Telegram bot APIs and Discord webhooks, especially from user workstations.</li>



<li>User awareness remains critical. Employees should be reminded to verify login pages and avoid entering credentials through email links.</li>



<li>Incident response teams should reset affected credentials immediately and review sign-in logs for abnormal locations and IP addresses.</li>
</ul>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/ai-driven-phishing-kit/">AI-Driven Phishing Kit Targets Microsoft Accounts</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/ai-driven-phishing-kit/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
