FBI shares massive list of 42,000 LabHost phishing domains

FBI shares massive list of 42,000 LabHost phishing domains

The FBI has shared 42,000 phishing domains tied to the LabHost cybercrime platform, one of the largest global phishing-as-a-service (PhaaS) platforms that was dismantled in April 2024. The published domains were registered between November 2021 and April 2024, the time of its seizure, and are being shared to increase awareness and provide indicators of compromise. … Read more

This Google phishing email is so convincing, even Gmail didn’t flag it

This Google phishing email is so convincing, even Gmail didn’t flag it

Phishing attacks aren’t new. But every now and then, one shows up that makes you do a double-take. That’s what happened this week when developer Nick Johnson shared a Google phishing email that somehow slipped past Gmail’s usual warnings. The email came from [email protected] and was actually signed by accounts.google.com. In other words, it looked … Read more

Don’t Fall for This New Gmail Phishing Scheme

Don’t Fall for This New Gmail Phishing Scheme

If you receive an email from Google that appears to be a legitimate security alert, do not proceed. Scammers are taking advantage of vulnerabilities in Google’s authentication protocols to send phishing messages that appear convincing enough to steal unsuspecting users’ account credentials. Here’s how to protect yourself. How this new Google phishing scam works As … Read more

Windows NTLM hash leak flaw exploited in phishing attacks on governments

Windows NTLM hash leak flaw exploited in phishing attacks on governments

A Windows vulnerability that exposes NTLM hashes using .library-ms files is now actively exploited by hackers in phishing campaigns targeting government entities and private companies. The flaw tracked as CVE-2025-24054 was fixed in Microsoft’s March 2025 Patch Tuesday. Initially, it was not marked as actively exploited and was assessed as ‘less likely’ to be. However, … Read more

Midnight Blizzard deploys new GrapeLoader malware in embassy phishing

Midnight Blizzard deploys new GrapeLoader malware in embassy phishing

Russian state-sponsored espionage group Midnight Blizzard is behind a new spear-phishing campaign targeting diplomatic entities in Europe, including embassies. Midnight Blizzard, aka ‘Cozy Bear’ or ‘APT29,’ is a state-sponsored cyberespionage group linked to Russia’s Foreign Intelligence Service (SVR). According to Check Point Research, the new campaign introduces a previously unseen malware loader called ‘GrapeLoader,’ and a … Read more

Tycoon2FA phishing kit targets Microsoft 365 with new tricks

Tycoon2FA phishing kit targets Microsoft 365 with new tricks

Phishing-as-a-service (PhaaS) platform Tycoon2FA, known for bypassing multi-factor authentication on Microsoft 365 and Gmail accounts, has received updates that improve its stealth and evasion capabilities. Tycoon2FA was discovered in October 2023 by Sekoia researchers, who later reported significant updates on the phishing kit that increased its sophistication and effectiveness. Trustwave now reports that the Tycoon 2FA … Read more

E-ZPass toll payment texts return in massive phishing wave

E-ZPass toll payment texts return in massive phishing wave

An ongoing phishing campaign impersonating E-ZPass and other toll agencies has surged recently, with recipients receiving multiple iMessage and SMS texts to steal personal and credit card information. The messages embed links that, if clicked, take the victim to a phishing site impersonating E-ZPass, The Toll Roads, FasTrak, Florida Turnpike, or another toll authority that attempts to … Read more

PoisonSeed phishing campaign behind emails with wallet seed phrases

PoisonSeed phishing campaign behind emails with wallet seed phrases

A large-scale phishing campaign dubbed ‘PoisonSeed’ compromises corporate email marketing accounts to distribute emails containing crypto seed phrases used to drain cryptocurrency wallets. According to SilentPush, the campaign targets Coinbase and Ledger using compromised accounts at Mailchimp, SendGrid, HubSpot, Mailgun, and Zoho. The researchers link the campaign to recent incidents, such as the case of Troy Hunt’s … Read more

zkLend hacker loses 2,930 ETH to Tornado Cash phishing scam

zkLend hacker loses 2,930 ETH to Tornado Cash phishing scam

The zkLend exploiter lost all 2,930 ETH in a phishing scam while trying to launder the stolen money using what they thought was Tornado Cash. According to a Mar. 31 post on X by Consensys-backed De.Fi Antivirus Web3, the attacker mistakenly deposited the stolen funds into a fake Tornado Cash website, resulting in an immediate … Read more

zkLend hacker claims losing stolen ETH to Tornado Cash phishing site

zkLend hacker claims losing stolen ETH to Tornado Cash phishing site

The hacker behind the $9.6 million exploit of the decentralized money-lending protocol zkLend in February claims they’ve just fallen victim to a phishing website impersonating Tornado Cash, resulting in the loss of a significant portion of the stolen funds. In a message sent to zkLend through Etherscan on March 31, the hacker claimed to have … Read more