Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'credential harvesting'

View all threats tagged with 'credential harvesting'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: credential harvesting

Threats Tagged 'credential harvesting'

Click on any threat for detailed analysis and mitigation recommendations

Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy
0

Cybercriminals are exploiting legitimate Google infrastructure in a sophisticated phishing operation that bypasses email security gateways and enterprise firewalls. The attack chains together six distinct Google properties including Meet, Search, DoubleClick, Custom Search, Tag Manager and Analytics to proxy malicious traffic through trusted domains. Victims' email addresses are encoded in URL fragments and stripped before server-side logging. Landing pages dynamically impersonate target organizations by pulling live logos from Clearbit, capturing real-time website screenshots, and validating domains via Google's DNS API. The operation includes multilingual support for 16 languages and dual execution tracks: credential harvesting with immediate Telegram exfiltration, or silent ScreenConnect remote access tool installation. Lures span document reviews, credential expiry notices, package delivery, payment notifications, government benefits and voicemail themes targeting manufacturing, government, finance and...

Join the discussion
Inside Knight Office, a New M365 AiTM Phishing Kit
0

Huntress researchers discovered Knight Office, a phishing kit utilizing Adversary-in-the-Middle techniques to steal Microsoft 365 session tokens. The attack chain begins with DocuSign-themed phishing emails containing redirects through Monday.com and compromised Joomla websites. Victims are directed to credential capture pages where session tokens are harvested and fed into the Knight Office console. These stolen tokens enable attackers to bypass multi-factor authentication entirely by using already-authenticated sessions. In one incident, attackers registered rogue devices in Microsoft Entra ID and bound Windows Hello for Business credentials for persistence. Analysis revealed nine phishing attacks linked to this kit over two weeks, with hundreds of related emails reported since April. The console, hosted at IP 104.37.188.94, manages at least 25 phishing domains using .vu top-level domains.

Join the discussion
19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads
0

Socket Threat Research team identified 19 malicious browser extensions (18 Chrome, 1 Edge) published in the last six months, delivering an extendable malware framework. These extensions establish WebSocket communication with command and control servers, strip Content Security Policy headers, and use XSS injection to execute malicious payloads. The primary focus is cryptocurrency wallet secret stealing and crypto draining. The threat actor employs two publishing approaches: creating malicious extensions from scratch or acquiring legitimate extensions with established user bases and weaponizing them. The most impactful case involves the 'Enable Right Click & Copy' extension, which had approximately 70,000 Chrome users and 10,000 Edge users when compromised. The campaign, tracked as 'Superior', has been active since February 2024, demonstrating sophisticated operational capabilities and persistent evolution of malicious modules targeting multiple cryptocurrency platforms, exchanges, and credential harvesting.

Join the discussion
AI-Powered PhaaS Supply Chain
0

AnonyMousKIT is an AI-powered Phishing-as-a-Service platform engineered to disable Apple's Activation Lock on stolen devices. Operating as a credit-metered system, it automates credential harvesting through email, SMS, WhatsApp, and AI-driven voice phishing calls. The investigation exposed a reseller supply chain spanning 506 domains and 168 storefront brands active since early 2024. The platform targets owners of stolen Apple devices using device-specific lures with internal model identifiers and real-time Find My statuses. Conversational AI agents impersonating Apple Support conduct vishing operations, with over 200 calls placed primarily to Brazil at minimal cost. Coding vulnerabilities exposed 120,242 lines of operational logs, revealing 689 distinct WhatsApp operator accounts and detailed attack infrastructure. The ecosystem operates through a decentralized enterprise structure with developers, resellers, and hundreds of subscriber-operators monetizing stolen iPhone hardware through industrialized soc...

Join the discussion
Inhospitable: Tracking Russian Cyber Espionage Infrastructure
0

This analysis examines infrastructure used by multiple Russian cyber espionage clusters targeting individuals in academia, think tanks, and organizations across Europe and the United States. The investigation expands on three threat clusters (UNC6293, UNC7005, and UNC5976) that employed OAuth phishing, Microsoft device code phishing, and WhatsApp targeting. UNC6293 utilized lure domains impersonating the Council on Foreign Relations and government portals, with possible Evilginx configurations. UNC7005 demonstrated lower sophistication with poor operational security, using domains like my-invite[.]org for phishing campaigns. UNC5976 employed Google Drive impersonation domains for OAuth phishing. The analysis leverages historical DNS data, CSS hash similarities, favicon analysis, registration patterns, and certificate information to identify additional infrastructure and tracking methods for discovering related malicious domains and IP addresses.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: credential harvesting
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses