Výsledky hledání

téma: podvod× v celém archivu zrušit filtry

92 karet z 92 položek · strana 1 z 2 CZ · EN/orig

3

New Android malware uses AI to steal bank logins and PINs

Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process. What’s new is that RatHat gives a live AI assistant the keys to the accessibility tree of the infected device and uses it to determine where to tap or scroll, rather than following a hardcoded script. The variable attack path makes it harder for signature- and rule-based mobile security tools to detect this Trojan. It also abuses Android Debug Bridge (ADB), a legitimate tool…

Google finance US

tg: rozbor tg: propagace tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · New Android malware uses AI to steal bank logins and PINs

Fake parcel delivery messages steal your card and bank details

Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands. The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial…

doprava US

tg: varování tg: rozbor tg: propagace tp: phishing tp: podvod

· Malwarebytes Labs · Fake parcel delivery messages steal your card and bank details

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.

US

tg: varování tg: zranitelnost tp: phishing tp: podvod tp: špionáž

· The Record · North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

3

Revolut phishing texts appear days after data breach

Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain. Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of…

Revolut finance US

tg: incident tg: varování tg: propagace tp: phishing tp: podvod tp: únik dat

· Malwarebytes Labs · Revolut phishing texts appear days after data breach

T-Mobile rewards points expiry texts are a phishing scam

Since early May 2026, we’ve been monitoring a large phishing campaign based on T-Mobile rewards points. The messages falsely warn that a customer’s rewards points are about to expire. They aren’t legitimate account notices: They use urgency, invented point balances, and phishing links to push recipients into acting before they can verify the claim. A typical message says that a T-Mobile Rewards account holds 18,400 points, gives an imminent expiry date, and states that unused points will be…

T-Mobile telekomunikace US

tg: varování tg: rozbor tg: propagace tp: phishing tp: podvod

· Malwarebytes Labs · T-Mobile rewards points expiry texts are a phishing scam

5

House passes bill to equip local law enforcement with scam-fighting tools

The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investigate them.

veřejná správa US

tg: vymáhání práva tg: regulace tp: podvod

· The Record · House passes bill to equip local law enforcement with scam-fighting tools

Ukraine moves to crack down on scam call centers after corruption scandal

Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.

veřejná správa US

tg: vymáhání práva tg: regulace tp: podvod tp: soukromí

· The Record · Ukraine moves to crack down on scam call centers after corruption scandal

AI helps scammers build convincing antivirus renewal pages

Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are taken to a fake page designed to collect your contact details. The renewal charge never existed. Receiving a message that names the antivirus software you use does not necessarily mean the sender has access to your device or account. Scammers impersonate popular brands and send the same message to large numbers of people, knowing…

Avast US

tg: rozbor tg: propagace tp: phishing tp: podvod tp: AI

· Malwarebytes Labs · AI helps scammers build convincing antivirus renewal pages

2

Search results are sending people to fake Bitrefill checkouts

Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and mobile top-ups. You can pay on their website for all of these with cryptocurrency. The scam is designed to catch people searching for Bitrefill or something it sells, like a gift card. Victims see a search result that appears to lead to Bitrefill but actually points to a lookalike domain. The fake site then takes them through what…

Bitrefill obchod US

tg: varování tg: rozbor tp: phishing tp: podvod

· Malwarebytes Labs · Search results are sending people to fake Bitrefill checkouts

7

Revolut gave customer IDs and financial data to a government impostor

Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain, according to TechCrunch. Revolut is a London-based banking and financial platform with more than 80 million customers globally, according to the company. Revolut describes this as an external impersonation scam, not an intrusion into its systems. It also says customer funds…

Revolut finance US

tg: incident tp: podvod tp: únik dat

· Malwarebytes Labs · Revolut gave customer IDs and financial data to a government impostor

Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

A deep technical analysis of the Smishing Triad’s JWR phishing kit and Outsider operator cluster, revealing its real-time victim control, encrypted WebSocket communications, multi-stage credential theft, AES-256-CTR implementation, infrastructure, and actionable indicators for defenders.

SG

tg: rozbor tp: phishing tp: podvod tp: identita

· Group-IB · Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators' Ethereum transactions cluster during São Paulo working hours. Over 15 months and seven campaigns, they built a malicious browser extension that installs…

Google Microsoft finance US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

5

Crypto customers targeted by scammers after email marketing provider breach

An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields. The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms. Brevo initially said an attacker had gained access to 120 customer accounts, some of which were used to send phishing emails to the…

Brevo Trezor CoinTracking BitBox finance US

tg: incident tg: varování tg: zneužíváno tp: phishing tp: podvod tp: únik dat tp: dodavatelský řetězec

· Malwarebytes Labs · Crypto customers targeted by scammers after email marketing provider breach

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal…

US

tg: rozbor tp: podvod tp: identita

· Rapid7 · The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Android malware creates a hidden copy of your banking app

Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device. To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of…

finance US

tg: rozbor tg: propagace tp: malware tp: phishing tp: podvod

· Malwarebytes Labs · Android malware creates a hidden copy of your banking app

5

Protecting organizations from AI-assisted executive impersonation and invoice fraud

In this article Attack chain overviewEmail DeliveryDomain registrationGenerative AI usageMitigation and protection guidanceMicrosoft Defender detectionsMicrosoft Security CopilotThreat intelligence reportsMITRE ATT&CK Techniques observedIndicators of compromise (IOC)Learn More Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive…

ServiceNow US

tg: varování tg: rozbor tp: phishing tp: podvod tp: AI

· Microsoft Security Blog · Protecting organizations from AI-assisted executive impersonation and invoice fraud

Detect and disrupt AI-themed attacks with Microsoft Defender

Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious advertising that uses online ads to lure users to harmful sites, downloads, or redirect…

Microsoft US

tg: varování tg: rozbor tg: propagace tp: malware tp: phishing tp: podvod tp: identita

· Microsoft Security Blog · Detect and disrupt AI-themed attacks with Microsoft Defender

Copyright scammers get Instagram accounts suspended and demand payment

Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC. Criminals file fake copyright complaints with Instagram, claiming that an account is using material it doesn’t own. Repeated complaints can trigger a temporary account suspension from the platform, locking out the victim even though they haven’t done anything wrong. The criminal then moves the conversation to another platform, such as Telegram, and…

Meta Instagram US

tg: varování tg: návod tg: propagace tp: podvod

· Malwarebytes Labs · Copyright scammers get Instagram accounts suspended and demand payment

6

More than 100,000 fake stores are out to steal your card details

Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores. The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined. The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even…

obchod US

tg: varování tg: rozbor tp: phishing tp: podvod

· Malwarebytes Labs · More than 100,000 fake stores are out to steal your card details

7

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery…

Google Cloudflare NetSupport veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Cisco Talos · ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the…

Google Tampermonkey US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Cisco Talos · ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

3

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

This week on the Lock and Code podcast… Crooks are taking a holiday. They’re counting on you to fund it. For decades, cybercriminals have stolen roughly the same types of data. Biographical and personal details—like Social Security numbers, birthdates, addresses, and phone numbers—can be stolen to commit identity fraud. Credit card numbers, expiration dates, and CVC codes can be stolen to make fraudulent purchases. Usernames and passwords can, in the wrong hands, let a cybercriminal impersonate…

US

tg: rozbor tg: propagace tg: přehled tp: podvod tp: identita

· Malwarebytes Labs · Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

Upozorenje: WhatsApp prijevara “Glasajte za moje dijete”

Nacionalni CERT zaprimio je prijave o phishing (smishing) prijevari putem preuzetog WhatsApp računa te je prijavio prijevare izvorima incidenta i nadležnim CERT timovima. Primjer WhatsApp poruke: Sadržaj lažnih WhatsApp poruka je: “Glasajte za … dijete na natjecanju”Možete primiti poruku od poznate osobe s poveznicom za glasovanje na natjecanju. Nakon klika traži se unos broja mobitela te kôda – time prevarantu nesvjesno dajete pristup svom WhatsApp računu i omogućavate širenje lažnih poruka…

WhatsApp HR

tg: varování tp: phishing tp: podvod tp: identita

· CERT.hr · Upozorenje: WhatsApp prijevara “Glasajte za moje dijete”

Flirty OnlyFans promoters on X may be using AI to appear human

In a recent post, we looked at reports of League of Legends players receiving suspicious friend requests shortly after matches. The accounts quickly steered the conversation toward Discord, where they promoted paid adult-content pages. At the time, one unanswered question was how much of those conversations was automated. Were people working from scripts behind the accounts? Were they conventional, rules-based chatbots following a limited decision tree? Or were they using generative AI to…

X OnlyFans US

tg: varování tg: rozbor tp: podvod tp: AI

· Malwarebytes Labs · Flirty OnlyFans promoters on X may be using AI to appear human

2

1

StreamRat Android malware spreads through Meta and TikTok ads

A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok. The available data shows the ads’ reach, not the number of downloads or infections, but…

Meta TikTok US

tg: varování tg: rozbor tp: malware tp: podvod

· Malwarebytes Labs · StreamRat Android malware spreads through Meta and TikTok ads

4

Tech support scams look different now. Here’s what to watch for

In a tech support scam, criminals pretend to work for a trusted technology or security company. They claim there is a problem with your device, software, subscription, or account, then try to persuade you to pay them, share personal information, or give them remote access to your computer. These scams used to rely mainly on browser locks and fake virus warnings. Now, scammers use many more ways to reach people, including websites and platforms they trust. How tech support scams reach you As…

Malwarebytes US

tg: varování tg: návod tg: propagace tp: phishing tp: podvod

· Malwarebytes Labs · Tech support scams look different now. Here’s what to watch for

Scammers are getting smarter about where they target you 

Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media. That’s no coincidence. Rather than blasting the same message everywhere, criminals are tailoring different scams to the platforms where they’re most likely to succeed. This finding comes from Malwarebytes’ own threat research systems and…

Google Microsoft Apple Amazon US

tg: rozbor tg: návod tg: propagace tp: phishing tp: podvod

· Malwarebytes Labs · Scammers are getting smarter about where they target you 

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Research by: Amit Yardeni Key Points A Chinese-speaking actor is now targeting Brazil. Check Point Research has uncovered a sustained campaign against Brazilian organizations, primarily government and educational institutions since mid-2025. We dubbed this group Gambling Goblin: a Chinese-speaking cybercrime cluster connected to a previously documented group, Earth Berberoka, that targeted gambling sites across Asia. It marks a shift from Brazil’s usual home-grown banking-trojan threats to a…

Apache veřejná správa školství IL

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Check Point Research · Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

REVSTEALER ramps up: analysis of up-and-coming infostealer

Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months, with higher distribution volume, and has emerged as a formidable threat, featuring a comprehensive credential harvester, an embedded sandbox scoring system, and a Polygon blockchain-based dead drop for resilience. Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on…

US

tg: varování tg: rozbor tp: malware tp: podvod tp: identita

· Elastic Security · REVSTEALER ramps up: analysis of up-and-coming infostealer

4

Fake GTA 6 leaked copy drains your crypto wallet

We’ve seen scam sites built around Grand Theft Auto VI (GTA 6) targeting visitors in three different ways this year. In June, we looked at sites selling GTA 6 “early access” for hundreds of dollars in cryptocurrency. You paid, got nothing, and could not reverse the payment. In August, we found fake Extended Look and demo sites delivering an infostealer instead of a game. The site we examined this week looks like a GTA 6 fan countdown site but offers to sell a leaked copy of the game. It loads a…

US

tg: varování tg: rozbor tp: malware tp: podvod

· Malwarebytes Labs · Fake GTA 6 leaked copy drains your crypto wallet

Infostealers are hijacking Claude accounts at users’ expense

Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the…

Anthropic US

tg: incident tg: varování tg: zranitelnost tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · Infostealers are hijacking Claude accounts at users’ expense

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In…

finance obchod US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod tp: AI

· Mandiant / Google TI · Financially Motivated Threat Actor BREEZE COMET Targets Brazil

3