Cybersecurity Hacking News

Phishing & social engineering evolution: quishing, ClickFix, Graph API abuse & MFA bypass

Phishing & social engineering evolution: quishing, ClickFix, Graph API abuse & MFA bypass

Key Questions

What new macOS malware impersonates Apple crash reports?

CrashStealer uses a signed installer and notarization to bypass Gatekeeper while stealing passwords and crypto wallets.

How are attackers abusing Microsoft Device Code flow?

Campaigns achieve 3-second account hijacks by abusing the Device Code authentication flow in phishing and hotel Wi-Fi DNS hijacks.

What is the Helpdesk Hijackers campaign?

It combines Teams vishing, Quick Assist, and the GoGRPC backdoor, tracked since January 2026 and likely linked to ransomware initial access brokers.

Which crypter is used by China-linked groups?

Cruciferra employs BYOVD and Process Ghosting to hide malware, delivered via income tax-themed phishing lures targeting Indian taxpayers.

How do malvertising campaigns build malware in-browser?

SourTrade and similar campaigns use JavaScript and Bun runtime to assemble executables directly in the browser via fake TradingView and Solana pages.

What phishing kit profiles crypto wallets before delivery?

BlueNoroff's Zoom phishing kit uses AI-generated faces and self-propagating techniques to profile targets before deploying malware.

Which new campaign targets Web3 wallets with compliance lures?

Attackers use fake DocuSign pages and compliance themes to phish Keystone and OneKey wallet users through malicious sites.

How is Operation BlueDash delivering remote access tools?

It deploys Level RMM, ScreenConnect, and Tactical RMM via fake Microsoft Teams updates from a Nigerian threat actor.

Evolving phishing tactics. ARToken device code phishing, OS-aware kits, 2026 World Cup campaign (35K+ fake sites), deepfake vishing surging. Cyrillic homoglyphs in display names. Hotel Wi-Fi phishing (Midnight Blizzard) via CaptiveCrunch DNS poisoning. Storm-2945 using fake MFA pages. AI social engineering defenses emerging. AI-native security awareness platforms gaining traction. VanishID previews AI Exploitability Management for measuring weaponization of public data for deepfakes and spear phishing. New: BEC attack from legitimate tenant bypasses DMARC/SPF/DKIM; pretexting highlighted as key threat. New: Bank of America impersonators use ScreenConnect with SDDL ACL evasion to hide service. macOS ClickFix campaigns evolve to server-side fingerprinting with per-request content decisions. Larva-24009 phishing campaign deploys QuasarRAT via Telegram C2.

Sources (31)
Updated Aug 6, 2026