North Korean Zoom Phishing Kit Profiles Crypto Wallets
A North Korean group uses a Zoom phishing kit to profile crypto wallets before delivering malware, targeting high‑value victims via compromised Telegram accounts.
A North Korean group uses a Zoom phishing kit to profile crypto wallets before delivering malware, targeting high‑value victims via compromised Telegram accounts.
German and U.S. authorities seized over 200 servers, shutting down the Kratos phishing-as-a-service platform and arresting its developer in Indonesia.
Researchers dissect a 1,048‑file AI‑assisted phishing toolkit, revealing a WebDAV hijack targeting Mexican users and LLM‑driven development.
Kaspersky uncovers OkoBot’s SeedHunter module stealing recovery phrases from Ledger and Trezor apps, affecting hundreds across 25+ countries.
The FBI and CISA update their warning as Russian intelligence groups coax victims into handing over Signal Backup Recovery Keys, exposing private chats and groups.
Security researchers warn that over 4,300 fake FIFA domains and a 300‑site phishing kit are already scamming fans, with losses potentially reaching billions.
Researchers uncover ChatGPhish, a flaw that lets malicious web pages inject phishing links into ChatGPT summaries, exposing a new attack surface.
Over 80 organizations hit as attackers abuse legitimate RMM tools to bypass security. The campaign leverages trusted software for undetected access. Details from May 05, 2026.
Over 1,600 phishing messages from China-linked Silver Fox APT targeted India and Russia in tax-themed attacks delivering new malware. Details emerged May 04, 2026.
OpenAI rolls out Advanced Account Security on May 01, 2026, targeting developers and high-risk users concerned about phishing. Measures include mandatory MFA and login alerts. Details from Wired.