Threats Tagged 'mobile targeting'
View all threats tagged with 'mobile targeting'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mobile targeting'
Click on any threat for detailed analysis and mitigation recommendations
Threat actors are exploiting anticipation for the FIFA World Cup 2026 through sophisticated phishing campaigns targeting fans seeking tickets, hospitality packages, and tournament information. Attackers have deployed FIFA-themed domains and mobile-optimized phishing infrastructure resolving to specific IP addresses, designed to harvest credentials and payment information. The campaigns feature convincing fake ticketing portals that mimic official FIFA services, collecting personal details including names, emails, phone numbers, and payment card data. Some variants redirect victims to online gambling platforms after credential theft. The infrastructure leverages third-party payment services like KOIpay and EBpay, with JavaScript redirecting users to external payment gateways. Victims face risks including fraudulent account creation, credential stuffing attacks, email account takeover, and unauthorized financial access. This operation represents part of a larger fraud ecosystem targeting the tournament. Join the discussion | AlienVault OTX General | 06/25/2026, 14:07:33 UTC Added: 06/25/2026, 16:16:01 UTC |
A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes. Join the discussion | AlienVault OTX General | 06/03/2026, 13:18:23 UTC Added: 06/04/2026, 09:03:35 UTC |
Showing 1 to 2 of 2 results