Silent Ransom Group's Multi-Channel Tactics Escalate Beyond Email
Silent Ransom Group demonstrates how spear-phishing has evolved into coordinated multi-channel attacks that bypass traditional email defenses.
-...

Created by Oscar Lankford Jr
Technical research on spear‑phishing attacks and defenses for high‑value financial institutions
Explore the latest content tracked by Financial Spear Phishing Digest
Silent Ransom Group demonstrates how spear-phishing has evolved into coordinated multi-channel attacks that bypass traditional email defenses.
-...
No significant updates today.
No significant updates today.
Chinese-language PhaaS platforms now deliver mature, AI-enhanced services historically dominated by Russian-speaking groups.
Kali365 PhaaS deploys AiTM phishing pages that capture live authentication tokens, session cookies, and credentials from Microsoft 365 logins,...
Deepfake technology has matured into a viable spear-phishing vector for BEC and vishing attacks, producing real financial losses through convincing...
Token-capture phishing kits like Kali365 and EvilTokens enable even novice attackers to bypass MFA in Microsoft 365 environments by stealing OAuth...
Candescent's integration of Memcyco enables pre-login detection of cloned sites and impersonation attempts by feeding fake credentials to attackers...
frank_fbi delivers a 5-layer pipeline tailored for dissecting spear-phishing emails aimed at financial targets.
Ocean's stealth-to-$28M exit reflects strong investor backing for AI agents that probe every email for hidden malicious intent via sender context,...
Kali365, a subscription PhaaS platform observed April 2026, equips attackers with AI-generated lures, automated templates, real-time tracking...
Phishing has shifted from a technical issue to a cognitive problem of manipulation and disinformation, with attackers leveraging LLMs to evade dynamic...
CVE-2026-42897 is an XSS flaw in on-premises Exchange OWA that executes attacker-controlled JavaScript from crafted emails under preview or specific...
Phishing reclaimed the top initial access vector in Q1 2026, but IPBan-style network-layer controls catch what email filters and MFA miss: the...
Device code phishing is giving way to new Azure AD attack vectors that start with unauthenticated enumeration of vulnerable users and progress to...