Hacker News with Generative AI: Phishing

Windows infected with backdoored Linux VMs in new phishing attacks (bleepingcomputer.com)
A new phishing campaign dubbed 'CRON#TRAP' infects Windows with a Linux virtual machine that contains a built-in backdoor to give stealthy access to corporate networks.
Russian spies use remote desktop protocol files in unusual mass phishing drive (theregister.com)
Microsoft says a mass phishing campaign by Russia's foreign intelligence services (SVR) is now in its second week, and the spies are using a novel info-gathering technique.
Microsoft creates fake Azure tenants to pull phishers into honeypots (bleepingcomputer.com)
Microsoft is using deceptive tactics against phishing actors by spawning realistic-looking honeypot tenants with access to Azure and lure cybercriminals in to collect intelligence about them.
Microsoft creates fake Azure tenants to pull phishers into honeypots (bleepingcomputer.com)
Microsoft is using deceptive tactics against phishing actors by spawning realistic-looking honeypot tenants with access to Azure and lure cybercriminals in to collect intelligence about them.
DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (theregister.com)
The US Department of Justice and Microsoft have seized 107 websites used by Russian cyberspies in a phishing campaign to steal sensitive information from US government agencies, think tanks, and other victims.
Windows PowerShell Phish Has Scary Potential (krebsonsecurity.com)
Many GitHub users this week received a novel phishing email warning of critical security holes in their code. Those who clicked the link for details were asked to distinguish themselves from bots by pressing a combination of keyboard keys that causes Microsoft Windows to download password-stealing malware. While it’s unlikely that many programmers fell for this scam, it’s notable because less targeted versions of it are likely to be far more successful against the average Windows user.
Using Security Engineering to Prevent Phishing – Doyensec (doyensec.com)
Recently Doyensec was hired by a client offering a “Communication Platform as a Service”. This platform allows their clients to craft a customer service experience and to communicate with their own customers via a plethora of channels: email, web chats, social media and more.
FBI recommends using an ad blocker (2022) (ic3.gov)
The FBI is warning the public that cyber criminals are using search engine advertisement services to impersonate brands and direct users to malicious sites that host ransomware and steal login credentials and other financial information.
Hacker trap: Fake OnlyFans tool backstabs cybercriminals, steals passwords (bleepingcomputer.com)
When Get-Out-the-Vote Efforts Look Like Phishing (krebsonsecurity.com)
New Phishing Technique Bypasses Security on iOS and Android to Steal Bank Creds (securityweek.com)
Apple Intelligence beta flagged a phishing email as "Priority" (panic.com)
The golden age of scammers: AI-powered phishing (mailgun.com)
Nigerian faces up to 102 years in the slammer for $1.5M phishing scam (theregister.com)
Progressive Web Apps (PWAs) Phishing (mrd0x.com)
AI Will Increase the Quantity–and Quality–of Phishing Scams (schneier.com)
You receive a call on your phone. The caller says they're from your bank (mastodon.social)
US Post Office phishing sites get as much traffic as the real one (bleepingcomputer.com)
Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself (akamai.com)