Skip to main content

Threats Tagged 'token theft'

View all threats tagged with 'token theft'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: token theft

Threats Tagged 'token theft'

Click on any threat for detailed analysis and mitigation recommendations

A large-scale phishing operation has deployed 70 fraudulent websites impersonating legitimate cryptocurrency projects including xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis, and Firelight. The fake sites closely replicate authentic platforms and lure visitors with offers to vote on rewards distribution dates in exchange for a 1.25x boost. Upon clicking the vote button, users encounter a wallet connection prompt that ultimately leads to malicious authorization requests designed to drain cryptocurrency tokens. The targeted projects were strategically selected based on recent token launches, airdrops, or active rewards programs, making the phishing attempts appear credible to community members. All malicious domains follow the pattern 'sitemu' followed by random characters on the .xyz domain, suggesting a coordinated campaign using shared infrastructure and phishing kits.

Join the discussion

Cybercriminals are operating fraudulent cryptocurrency wallet-checking websites that impersonate legitimate anti-money laundering (AML) services. These fake sites mimic authentic platforms like AMLBot and trick users into connecting their wallets and approving transactions or token permissions. The scam uses fake progress bars, compliance messages, and error notifications to appear legitimate and request small fees. Once users approve these requests, attackers can drain their cryptocurrency holdings. This is a social engineering scam exploiting user trust and security awareness rather than a software vulnerability.

Join the discussion

A significant expansion of the Kali365 phishing-as-a-service operation has been observed, now targeting multiple platforms beyond Microsoft 365. The operator abuses OAuth 2.0 device authorization flows to bypass MFA and steal authentication tokens. Key discoveries include a live command-and-control panel infrastructure, a phishing campaign impersonating MAX Messenger (Russia's state-backed messaging platform with 110 million users) through fake prize-claim flows, and a cluster of 126 malicious hosts impersonating services including Microsoft Outlook, Okta SSO, Xerox DocuShare, Mail.ru, Yandex Disk, and Odnoklassniki. The operation demonstrates a deliberate focus on Russian consumer platforms alongside Western enterprise targets, utilizing Telegram bots for credential exfiltration and employing a multi-tenant phishing platform distributed through Telegram channels.

Join the discussion

In early April 2026, a large-scale device code phishing campaign targeted organizations across multiple sectors and regions, exploiting OAuth 2.0 Device Authorization Grant. Threat actors leveraged the Kali365 phishing-as-a-service platform, originating primarily from IP address 216.203.20[.]95. The campaign used high-fidelity lures directing victims to Microsoft's legitimate device login flow, where users unknowingly authorized threat actor-controlled sessions. Captured OAuth tokens enabled immediate mailbox access and post-compromise activities. In some cases, attackers established malicious inbox rules to suppress security notifications, extending dwell time. The Kali365 platform operates as a multi-tenant PhaaS ecosystem supporting both device code abuse and adversary-in-the-middle session capture, featuring rapid lure generation across multiple languages and file types, Cloudflare Worker-hosted pages, and token sharing capabilities between affiliates.

Join the discussion
0

Microsoft Incident Response researchers identified Storm-2755, a financially motivated threat actor conducting payroll pirate attacks against Canadian users. The campaign uses malvertising and SEO poisoning on generic search terms like "Office 365" to lure victims to a fraudulent sign-in page. Through adversary-in-the-middle techniques, the actor captures authentication tokens and session cookies, bypassing MFA protections. Storm-2755 maintains persistence using Axios HTTP client to replay stolen tokens, then conducts discovery for payroll and HR contacts. The actor impersonates compromised users to socially engineer HR staff or directly manipulates payroll systems like Workday. Malicious inbox rules hide correspondence from victims. Attacks resulted in direct financial losses through redirected salary payments to attacker-controlled bank accounts.

Join the discussion

A week-long automated attack campaign targeted CI/CD pipelines across major open source repositories, achieving remote code execution in multiple targets. The attacker, an autonomous bot called hackerbot-claw, used five different exploitation techniques and successfully exfiltrated a GitHub token with write permissions from one of the most popular repositories on GitHub. The campaign targeted repositories belonging to Microsoft, DataDog, CNCF, and other popular open source projects. The attacks included token theft via poisoned Go scripts, direct script injection, branch name injection, filename injection, and AI prompt injection. The most severe attack resulted in a full repository compromise of Aqua Security's Trivy project. The campaign highlights the growing threat of AI-powered bots targeting software supply chains and the need for automated security controls in CI/CD pipelines.

Join the discussion

A sophisticated ClickFix campaign has been uncovered, compromising legitimate websites to deliver a multi-stage malware chain. The attack culminates in MIMICRAT, a custom remote access trojan with advanced capabilities. The campaign uses compromised sites across industries and geographies for delivery, employing a five-stage PowerShell chain that bypasses security measures before deploying a Lua-scripted shellcode loader. MIMICRAT, the final payload, is a native C++ RAT featuring malleable C2 profiles, Windows token theft, and SOCKS5 proxy functionality. The attack chain involves multiple compromised websites, obfuscated scripts, and sophisticated evasion techniques, demonstrating a high level of operational sophistication.

Join the discussion

A new Python-based Remote Access Trojan (RAT) named 'Nursultan Client' targets gamers by masquerading as a legitimate Minecraft client. It uses the Telegram Bot API for command and control, enabling attackers to capture screenshots, access webcams, steal Discord authentication tokens, open URLs, and perform system reconnaissance on Windows machines. Although it attempts persistence, its implementation has flaws. The malware's focus on Discord tokens and gaming users suggests a Malware-as-a-Service model, likely sold to other threat actors. No known exploits in the wild have been reported yet. The threat poses a medium severity risk but could escalate if customized versions improve persistence or evasion. European organizations with gaming communities or employees using Discord and Minecraft are at risk, especially in countries with high gaming engagement and Discord usage. Mitigation requires targeted detection of the fake client, monitoring Telegram API usage, and securing Discord tokens. Countries like Germany, France, the UK, and the Netherlands are most likely affected due to their large gaming populations and technology adoption. The threat is medium severity given its impact on confidentiality and moderate ease of exploitation without user interaction beyond initial infection.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: token theft
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses