Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process. What’s new is that RatHat gives a live AI assistant the keys to the accessibility tree of the infected device and uses it to determine where to tap or scroll, rather than following a hardcoded script. The variable attack path makes it harder for signature- and rule-based mobile security tools to detect this Trojan. It also abuses Android Debug Bridge (ADB), a legitimate tool…
Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands. The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial…
Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain. Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of…
Since early May 2026, we’ve been monitoring a large phishing campaign based on T-Mobile rewards points. The messages falsely warn that a customer’s rewards points are about to expire. They aren’t legitimate account notices: They use urgency, invented point balances, and phishing links to push recipients into acting before they can verify the claim. A typical message says that a T-Mobile Rewards account holds 18,400 points, gives an imminent expiry date, and states that unused points will be…
Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separates them.
Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are taken to a fake page designed to collect your contact details. The renewal charge never existed. Receiving a message that names the antivirus software you use does not necessarily mean the sender has access to your device or account. Scammers impersonate popular brands and send the same message to large numbers of people, knowing…
Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device. To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of…
Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious advertising that uses online ads to lure users to harmful sites, downloads, or redirect…
Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC. Criminals file fake copyright complaints with Instagram, claiming that an account is using material it doesn’t own. Repeated complaints can trigger a temporary account suspension from the platform, locking out the victim even though they haven’t done anything wrong. The criminal then moves the conversation to another platform, such as Telegram, and…
This week on the Lock and Code podcast… Crooks are taking a holiday. They’re counting on you to fund it. For decades, cybercriminals have stolen roughly the same types of data. Biographical and personal details—like Social Security numbers, birthdates, addresses, and phone numbers—can be stolen to commit identity fraud. Credit card numbers, expiration dates, and CVC codes can be stolen to make fraudulent purchases. Usernames and passwords can, in the wrong hands, let a cybercriminal impersonate…
In a tech support scam, criminals pretend to work for a trusted technology or security company. They claim there is a problem with your device, software, subscription, or account, then try to persuade you to pay them, share personal information, or give them remote access to your computer. These scams used to rely mainly on browser locks and fake virus warnings. Now, scammers use many more ways to reach people, including websites and platforms they trust. How tech support scams reach you As…
Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media. That’s no coincidence. Rather than blasting the same message everywhere, criminals are tailoring different scams to the platforms where they’re most likely to succeed. This finding comes from Malwarebytes’ own threat research systems and…
Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging automation. Together, those functions can help operators turn a compromised phone into a platform for account…
Key Takeaways Two real-world cloud attacks reached meaningful impact in less than ten minutes despite pursuing entirely different objectives. Both attackers treated the environment as a connected system, using existing permissions and relationships to expand their reach. Reconnaissance increasingly focuses on understanding access and capability rather than discovering vulnerable assets. AI is compressing the gap between discovery, decision-making, and execution for cloud attackers. The interval…
Most business email compromise (BEC) attacks start with stolen credentials, not a malicious email. Group-IB uses threat intelligence to detect compromised accounts before attackers log in — predicting BEC before it starts.
Meet Huntress Reseller Sales Manager Cody Browning. Learn how his grandmother's vishing scam inspired his career and fuels our mission to bring human-led cybersecurity to all businesses.
Huntress’ AI-Centric SOC recently stopped a MacSync infostealer attack on a macOS device. The malware attempted to scrape credentials, browser cookies, and crypto wallets, but Huntress contained the threat before any data was sent to the attacker. Learn how we did it.