๐จ New โComplaint Stealerโ Malware Escalates, Targeting Cryptocurrency Wallets & Hospitality Sector๐จ
@CofenseIntel has seen an increase in the last few days in the newly christened #ComplaintStealer malware. Here's what we know so far ๐
https://t.co/M93kFW34Hg
"Human intuition is often much better at recognizing these differences, so training employees to be vigilant against phishing threats is a critical element of good cyber defense."
Another great discovery from @CofenseIntel. Written by @wirelesswench.
https://t.co/Ij8klhNmOh
โ๐๐ฅ๐๐๐๐๐ก๐ ๐ก๐๐ช๐ฆโ#Emotet has resumed activity this morning, sending emails with attached .zip files that are not password protected.
Learn more below โฌ๏ธ
https://t.co/kbXBKNGzan
Emotet Update: Loader DLLs for #Emotet botnet- (Epochs 4 and 5) have recently been updated, and #malicious#email dissemination may not be far behind! We're anticipating email activity will resume in the next couple of weeks, if not days. Stay vigilant.
#Emotet is back, and reaching inboxes! #Malicious XLS files are attached to emails, sometimes zipped. #Email subjects appear to be taken from email reply-chains. Cofense #Phishing Defense Center has seen multiple instances of Emotet in corporate inboxes this morning. Example:
๐จNEW: Scammers Are Targeting Hurricane Relief Funds From FEMA๐จ
@iHeartMalware has evidence that shows scammers are actively sharing tutorials and documents with criminal networks on how to steal relief funds from @fema.
Here's what we know โฌ๏ธ https://t.co/Inag9cvVfh
Reply-Chain #phishing email found by our Phishing Defense Center (PDC) after it was missed by #Proofpoint.
Reply-chain tactic โ using an existing email threat to tack on the #phishing email โ gaining trust from the recipient to increase the likelihood of them interacting. (1/4)
Ever wonder how a threat actor might selectively target government contractors without even knowing whether the recipient of a #phishing#email is one?
We've got details on a long-standing activity set with convincing lures and #spoofed gov websites โก๏ธ https://t.co/OotoQDEjTK
Uber hack updates from @iHeartMalware ๐
VPN credentials compromised via social engineering and hard-coded credentials in scripts led to the compromise of Uber's infrastructure.
Also, make sure you use MFA on your VPN and train your users not to leak VPN credentials. #cybersec
New insights from the team on a unique attack using customer feedback systems that were utilized to launch #phishing attacks. These emails were found by our Phishing Defense Center in environments protected by Microsoft.
Unusual Microsoft 365 Phishing Campaign Spoofs eFax Via Compromised Dynamics Voice Account https://t.co/47HX6A7Psx by Elizabeth Monalbano #365 #phishing
The #phishers know we're all thinking it's about time for #vacation, and they are taking advantage. Don't fall for #summer vacation #phish! Example below. Make sure your employees are aware of phish like this. However, we don't recommend running simulations with this theme.
A well-crafted credential #phishing campaign is specifically targeting the food manufacturing industry, spoofing @USDA. Images below are of the original phish and subsequent landing/harvesting pages. @CofenseIntel customers can find details in Cofense ThreatHQ.
Flash Alert! Dozens of C-level executives (mostly CFOs) have been directly targeted in an ongoing #phishing campaign #spoofing Docusign. Cofense Intelligence customers can read the full alert in our ThreatHQ portal, but here's a closeup look at an actual email from the campaign.
Q2 2022 is in the books! We've distilled some of the most important takeaways for you to catch up on between meetings today, but if you want the full picture of today's #Phishing Threat Landscape, there's also a link to download the complete report here: https://t.co/4lvYa99WBa
Check out our recently released Business Email Compromise (BEC) study. Cofense Intelligence & @CofenseLabs teams phished hundreds of scammers and gained some amazing insights into their techniques and mindset!
https://t.co/53RIQCHSmV